# Ingress basic http for multiple users and passwords

**URL:** <https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585>\
**Category:** SUSE Rancher Prime\
**Created:** [February 14, 2020, 11:26pm UTC](https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585 "2020-02-14T23:26:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Austin-Earl](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/austin-earl/32/4916_2.png) [@Austin-Earl](https://forums.suse.com/u/Austin-Earl)\
**Post date:** [February 14, 2020, 11:26pm UTC](https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585/1 "2020-02-14T23:26:23Z")

</div>

Im trying to get our project to have some basic http authentication. I can get one user to work but I need multiple users to have their own logins.  
I have a secret called auth with the this data:  
user1 = password\_hash  
user2 = password\_hash2

I also have these annotations on the ingress pod:  
[nginx.ingress.kubernetes.io/auth-secret](http://nginx.ingress.kubernetes.io/auth-secret) = auth  
[nginx.ingress.kubernetes.io/auth-secret-type](http://nginx.ingress.kubernetes.io/auth-secret-type) = auth-map  
[nginx.ingress.kubernetes.io/auth-type](http://nginx.ingress.kubernetes.io/auth-type) = basic

I have done this command to see the logs of the pod:  
kubectl logs nginx-ingress-controller-8lrhh -n ingress-nginx  
This is the return:

> I0214 23:21:47.056041 6 store.go:449] secret default/auth was updated and it is used in ingress annotations. Parsing…  
> E0214 23:21:47.056585 6 annotations.go:197] error reading BasicDigestAuth annotation in Ingress default/backend: the secret auth does not contain a key with value auth  
> W0214 23:21:47.056883 6 backend\_ssl.go:46] Error obtaining X.509 certificate: secret “default/auth” contains no keypair or CA certificate  
> I0214 23:21:47.057941 6 controller.go:133] Configuration changes detected, backend reload required.  
> I0214 23:21:47.333999 6 controller.go:149] Backend successfully reloaded.

It says that i need a key with auth. Does that mean I need to put the user:hash into the key auth?  
Thanks for the help in advance!

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [February 14, 2020, 11:49pm UTC](https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585/2 "2020-02-14T23:49:59Z")

</div>

Yes, `...auth-secret-type: auth-map` was [added](https://github.com/kubernetes/ingress-nginx/pull/4560) in ingress-nginx 0.26, which is (one) newer than we currently package. You can use the `auth-file` format for the secret (which was the only format at that time).

---

<div class="post-metadata">

**Author:** ![Austin-Earl](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/austin-earl/32/4916_2.png) [@Austin-Earl](https://forums.suse.com/u/Austin-Earl)\
**Post date:** [February 14, 2020, 11:53pm UTC](https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585/3 "2020-02-14T23:53:58Z")

</div>

Yo thanks for the fast response!  
That makes sense why I couldn’t get it to work lol!  
Okay so I’ll just do with what we got for now and use auth-file.

By chance do you happen to know when this will be available?

---

<div class="post-metadata">

**Author:** ![MarkHooijkaas](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/markhooijkaas/32/7578_2.png) [@MarkHooijkaas](https://forums.suse.com/u/MarkHooijkaas)\
**Post date:** [May 18, 2021, 7:28am UTC](https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585/4 "2021-05-18T07:28:27Z")

</div>

Is the auth-map feature available in availabe in v2.5.7? If so, what is the correct way to crypt/hash the passwords?

---

<div class="post-metadata">

**Author:** ![vincent](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/vincent/32/7156_2.png) [@vincent](https://forums.suse.com/u/vincent)\
**Post date:** [May 18, 2021, 3:12pm UTC](https://forums.suse.com/t/ingress-basic-http-for-multiple-users-and-passwords/16585/5 "2021-05-18T15:12:33Z")

</div>

Yes recent versions are newer than that. The value is a hash from `htpasswd` or `openssl passwd` (And then base64-encoded if you’re writing the raw yaml and using `data` vs ` stringData`).
