docs/docs/deploy/azure/aks.mdx
:::tip This page contains details in addition to the base Kubernetes documentation for deploying OPA. Please see that page for details on how to deploy OPA on K8s and return here for more AKS specific notes. :::
If running OPA as a cluster service, you might be interested in exposing the service to the internet or other, internal, off-cluster PEPs. Generally, OPA is invoked by other PEP applications rather than clients, and so a public IP is generally not required.
apiVersion: v1
kind: Service
metadata:
name: opa
annotations:
// highlight-next-line
service.beta.kubernetes.io/azure-load-balancer-internal: "true"
spec:
selector:
app: opa
ports:
- protocol: TCP
port: 8181
targetPort: 8181
type: LoadBalancer
:::warning If you are exposing an OPA service to the public internet, you are advised to make use of OPA's built in authentication and authorization features if not running OPA behind another service that provides these functions. :::
apiVersion: v1
kind: Service
metadata:
name: opa
annotations:
// highlight-next-line
service.beta.kubernetes.io/azure-load-balancer-internal: "false"
spec:
selector:
app: opa
ports:
- protocol: TCP
port: 8181
targetPort: 8181
type: LoadBalancer
For more information, please see the AKS documentation on load balancers: