---
title: Charmhub | Deploy Temporal Server using Charmhub - The Open Operator Collection
description: Deploy the latest version of Temporal Server as a Kubernetes Operator
  on any cloud.
url: https://charmhub.io/temporal-k8s/docs/h-deploy-ingress
---

# Temporal Server

[Workflows Charmers](https://charmhub.io/publisher/workflows-charmers "View all packages from Workflows Charmers")

* [Workflows Charmers](https://charmhub.io/publisher/workflows-charmers "View all packages from Workflows Charmers")

Platform:

1.23/stable 60

```
juju deploy temporal-k8s --channel 1.23/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Homepage](https://github.com/canonical/temporal-k8s-operator)

---

#### Contacts

##### Maintainers

+ [Commercial Systems](mailto:jaas-crew@lists.canonical.com)

* [Submit a bug](https://github.com/canonical/temporal-k8s-operator/issues)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

# Configure ingress with Nginx Ingress Integrator

Charmed Temporal components can be exposed through an ingress solution to make them available to clients outside the cluster and to handle TLS termination.
In the Charming ecosystem, the [Nginx Ingress Integrator](https://charmhub.io/nginx-ingress-integrator)
operator allows different applications to request `Ingress` resources from an underlying ingress controller.

## [Enable ingress](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-enable-ingress)

### [Requirements](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-requirements)

To follow this guide, consider having a Kubernetes cluster with the following configured:

* Ingress controller: If using any Kubernetes (K8s), the [nginx ingress controller](https://docs.nginx.com/nginx-ingress-controller/installation/installing-nic/installation-with-manifests) can be installed; if using MicroK8s, the `ingress` addon should suffice.
* LoadBalancer: If using K8s, the [default LoadBalancer](https://documentation.ubuntu.com/canonical-kubernetes/latest/snap/howto/networking/default-loadbalancer/) works; on MicroK8s, the `metallb` addon should suffice.
* [Temporal Command Line Interface (CLI) snap](https://snapcraft.io/temporal).

The `nginx-ingress-integrator` only allows one integration per `ingress` and `nginx-route` integration.
Charmed Temporal is not designed to share the same integrator instance, and thus, an integrator
charm per application must be deployed.

See [Support multiple relations](https://charmhub.io/nginx-ingress-integrator/docs/support-multiple-relations) for more details.

### [Expose the Temporal Server](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-expose-the-temporal-server)

1. Deploy the integrator charm:

```
juju deploy nginx-ingress-integrator temporal-server-ingress --trust
```

1. Check your cluster’s `IngressClass`:

```
kubectl get ingressclass

NAME             CONTROLLER                  PARAMETERS   AGE
nginx            k8s.io/ingress-nginx        <none>       12d
```

1. Configure the integrator’s `ingress-class` using the name from the previous step:

```
juju config temporal-server-ingress ingress-class nginx
```

1. Configure `backend-protocol`. Temporal server, specifically its frontend, is a `gRPC` server:

```
juju config temporal-server-ingress backend-protocol GRPC
```

1. Integrate and configure:

```
juju config temporal-k8s tls-secret-name=""
juju integrate temporal-k8s temporal-server-ingress
```

1. Connect with clients. Assuming a `LoadBalancer` is enabled, and because the Temporal Server works with
   host-based routing, DNS resolution must be set up. For example:

```
cat /etc/hosts/
[...]
<LOADBALANCER-IP> temporal-k8s

temporal operator namespace list --address temporal-k8s:80
[...]
```

### [Expose Temporal UI](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-expose-temporal-ui)

1. Deploy the integrator charm:

```
juju deploy nginx-ingress-integrator temporal-ui-ingress --trust
```

1. Check your cluster’s `IngressClass`:

```
kubectl get ingressclass

NAME             CONTROLLER                  PARAMETERS   AGE
nginx            k8s.io/ingress-nginx        <none>       12d
```

1. Configure the integrator’s `ingress-class` using the name from the previous step:

```
juju config temporal-server-ingress ingress-class nginx
```

1. Configure the integrator’s `backend-protocol`:

```
juju config temporal-ui-ingress backend-protocol HTTP
```

1. Integrate:

```
juju config temporal-ui-k8s tls-secret-name=""
juju integrate temporal-ui-k8s temporal-ui-ingress
```

1. Access the Temporal UI on a web browser. Assuming a `LoadBalancer` is enabled, and because of Temporal’s
   host-based routing, DNS resolution must be set up. For example:

```
cat /etc/hosts/
[...]
<LOADBALANCER-IP> temporal-ui-k8s

http://temporal-ui-k8s:80/
```

## [Enable TLS termination at ingress](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-enable-tls-termination-at-ingress)

The integrator charm provides a way to perform TLS termination at ingress in conjunction with the ecosystem’s TLS providers.
Please refer to [Security with X.509 certificates](https://charmhub.io/topics/security-with-x-509-certificates) to understand
the different certificate use cases and choose the solution that best fits each one.

### [Temporal Server](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-temporal-server)

1. Reconfigure the integrator charm for a secured backend:

```
juju config temporal-server-ingress backend-protocol GRPCS
```

1. Integrate the integrator charm with a TLS certificate provider:

```
juju integrate temporal-server-ingress <tls-certificate-provider>
```

1. Get the Certificate Authority (CA) certificate from the TLS certificate provider charm and use it in further requests. For example,
   using the temporal CLI snap:

```
temporal operator namespace list --address temporal-k8s:443 --tls-ca-path <path to CA cert>
```

### [Temporal UI](https://charmhub.io/temporal-k8s/docs/h-deploy-ingress#p-27504-temporal-ui)

1. Reconfigure the integrator charm for a secured backend:

```
juju config temporal-ui-ingress backend-protocol HTTPS
```

1. Integrate the integrator charm with a TLS certificate provider:

```
juju integrate temporal-ui-ingress <tls-certificate-provider>
```

1. Use `https` when browsing, and configure certificate trust settings as needed.

---
