Accessing Neo4j using Kubernetes Ingress
The Helm chart neo4j/neo4j-reverse-proxy provides allows you to use a Kubernetes Ingress to access Neo4j on port :80 or :443.
For more information about Kubernetes Ingress, see the Kubernetes official documentation → Ingress.
The Helm chart creates a reverse proxy that is configured to route traffic to the Neo4j service URL using the serviceName, namespace, and domain values.
For example, if the serviceName is standalone-admin, the namespace is default, and the domain is cluster.local, then the Neo4j service URL is standalone-admin.default.svc.cluster.local.
For Neo4j clusters, the Neo4j headless service can be used to route the traffic to the cluster instances.
For more information and a detailed example of how to install the neo4j/neo4j-cluster-headless-service Helm chart, see Access the Neo4j cluster using headless service.
The Reverse proxy Helm chart creates an HTTP server, which routes requests to either the Bolt reverse proxy or HTTP reverse proxy based on the request headers.
Upon receiving a response, the Bolt reverse proxy updates the response to replace the Bolt port with either :80 or :443.
The Reverse proxy Helm chart supports defining privilege and access control settings for a Container. Make sure that you do not run Neo4j as a root user.
Configuration options
To see all configurable options, run the following command:
helm show values neo4j/neo4j-reverse-proxy
# Default values for neo4j reverse proxy helm chart
## @param nameOverride String to partially override common.names.fullname
nameOverride: ""
## @param fullnameOverride String to fully override common.names.fullname
fullnameOverride: ""
# Parameters for reverse proxy
reverseProxy:
image: "neo4j/helm-charts-reverse-proxy:5.26.0"
# Name of the kubernetes service. This service should have the ports 7474 and 7687 open.
# This could be the admin service ex: "standalone-admin" or the loadbalancer service ex: "standalone" created via the neo4j helm chart
# serviceName , namespace , domain together will form the complete k8s service url. Ex: standalone-admin.default.svc.cluster.local
# When used against a cluster ensure the service being used is pointing to all the cluster instances.
# This could be the loadbalancer from neo4j helm chart or the headless service installed via neo4j-headless-service helm chart
serviceName: ""
# default is set to cluster.local
domain: "cluster.local"
# securityContext defines privilege and access control settings for a Container. Making sure that we dont run Neo4j as root user.
containerSecurityContext:
allowPrivilegeEscalation: false
runAsNonRoot: true
runAsUser: 7474
runAsGroup: 7474
capabilities:
drop: [ "ALL" ]
podSecurityContext:
runAsNonRoot: true
runAsUser: 7474
runAsGroup: 7474
fsGroup: 7474
fsGroupChangePolicy: "Always"
# This assumes ingress-nginx controller or haproxy-ingress-controller is already installed in your kubernetes cluster.
# You can install ingress-nginx by following instructions on this link https://github.com/kubernetes/ingress-nginx/blob/main/docs/deploy/index.md#quick-start
# You can install haproxy-ingress by following instructions on this link https://haproxy-ingress.github.io/docs/getting-started/
ingress:
enabled: true
#default value is nginx. It can be either nginx or haproxy
className: nginx
annotations: {}
# "demo": "value"
# "demo2": "value2"
host: ""
tls:
enabled: false
config: []
# - secretName: "demo2"
# hosts:
# - localhost
The following steps assume that you have a Kubernetes cluster running and a standalone Neo4j Helm chart installed.
The standalone Neo4j has a Neo4j service with the name standalone-admin, and it has :7474 an :7687 opened.
To verify that, run:
kubectl get all, pvc, pv, configmaps, secrets
You also need to have an Ingress controller for the Kubernetes Ingress to work. The following steps use the Nginx Ingress Controller. See Ingress-Nginx Controller official documentation for more information.
If you do not have one, you can use the following command to install it:
helm upgrade --install ingress-nginx ingress-nginx \
--repo https://kubernetes.github.io/ingress-nginx \
--namespace ingress-nginx --create-namespace
helm upgrade --install ingress-nginx ingress-nginx \
--repo https://kubernetes.github.io/ingress-nginx \
--namespace ingress-nginx --create-namespace --set controller.service.externalTrafficPolicy=Local
Configure the Kubernetes Ingress
Configure the ingress-values.yaml file that you will use to install the Reverse proxy Helm chart.
Configure the ingress-values.yaml file to access Neo4j on port :443
The following example shows how to configure the ingress-values.yaml file to access Neo4j on port :443:
-
Create a Kubernetes secret containing the Ingress self-signed certificates and then create the ingress-values.yaml file.
-
Create a directory for the Ingress self-signed certificates:
mkdir certs cd certs -
Create Ingress self-signed certificates:
openssl req -x509 -nodes -days 365 -newkey rsa:2048 -keyout ingress.key -out ingress.cert -subj "/CN=localhost/O=neo4j" -addext "subjectAltName = DNS:localhost" -
Create Kubernetes secret using the Ingress self-signed certificates:
kubectl create secret tls ingress-cert --key /path/to/your/certs/ingress.key --cert /path/to/your/certs/ingress.cert
-
-
Configure the ingress-values.yaml file with the correct values for the
serviceNameandsecretName. Ensure that thesecretNameis the same as the one created in the previous step. Enable TLS by settingtls.enabledtotrue.reverseProxy: image: neo4j/helm-charts-reverse-proxy:5.26.0 serviceName: "standalone-admin" ingress: enabled: true tls: enabled: true config: - secretName: ingress-cert hosts: - localhost
Configure the ingress-values.yaml file to access Neo4j on port :80
Alternatively, if you want to access Neo4j on port :80, leave tls.enabled with its default value false, and create the ingress-values.yaml file with the following content:
reverseProxy:
#Use image only when need a specific version or using your internal artifactory.
#Otherwise let it default to what is in the values.yaml
#image: neo4j/helm-charts-reverse-proxy:5.26.0
serviceName: "standalone-admin"
ingress:
enabled: true
tls:
enabled: false
Install the Reverse proxy Helm chart
Install the Reverse proxy Helm chart using the ingress-values.yaml file that you have created:
helm install rp neo4j/neo4j-reverse-proxy -f /path/to/your/ingress-values.yaml
Access your data via Neo4j Browser
-
Get the Ingress LoadBalancer IP:
kubectl get ingress/rp-reverseproxy-ingress -n default -o jsonpath='{.status.loadBalancer.ingress[0].ip}' -
Open Neo4j Browser on https://INGRESS_IP:443 or http://INGRESS_IP:80 and log in with your credentials.
Access your data via Cypher Shell
Alternatively, if you want to use Cypher Shell to access your data via Nginx Ingress Controller only, you need to create a configmap, because Cypher Shell expects a TCP connection and Ingress is an HTTP connection.
For more information about exposing TCP/UDP services, see Ingress-Nginx Controller official documentation → Exposing TCP and UDP services.
-
Create a
configmapwith the following content:apiVersion: v1 kind: ConfigMap metadata: name: tcp-services namespace: ingress-nginx data: 9000: "default/standalone-admin:7687" -
Apply the
configmap:kubectl apply -f /path/to/your/nginx-tcp.yaml -
Update the Ingress controller LoadBalancer service to use the port :9000:
-
Get the IP address of the Ingress controller:
kubectl get svc -n ingress-nginx -
Open the Ingress controller service for editing:
kubectl edit svc ingress-nginx-controller -n ingress-nginx -o yaml -
Add the following lines to the
spec.portssection:- name: proxied-tcp-9000 port: 9000 protocol: TCP targetPort: 9000 -
Save the changes and exit the editor.
-
-
Update the Ingress controller deployment to use the
configmap:-
Open the Ingress controller deployment for editing:
kubectl edit deployment ingress-nginx-controller -n ingress-nginx -
Add the following lines to the
spec.template.spec.containers.argssection:- --tcp-services-configmap=ingress-nginx/tcp-services -
Save the changes and exit the editor.
-
Verify that the changes are applied by running
kubectl get all -n ingress-nginx. You should see the new port :9000 in the Ingress controller deployment.
-
-
Get the IP address of the Ingress controller:
kubectl get ingressNAME CLASS HOSTS ADDRESS PORTS AGE rp-reverseproxy-igress nginx * 34.89.91.112 80 2m
-
Connect to the Neo4j database using Cypher Shell:
cypher-shell -a neo4j://34.89.91.112:9000 -u neo4j -p <password>
Glossary
- allocator
-
A component in the cluster that allocates databases to servers according to the topology constraints specified and an allocation strategy.
- asynchronous replication
-
Asynchronous replication is used by secondary copies to poll for new transactions, which means they cannot be guaranteed to have received the most recent transactions. This enables efficient scale-out of read-performance.
- Aura instance
-
A fully-managed DBMS represented by a single instance ID, that is running in the Neo4j Aura cloud.
- auto-commit transaction
-
An automatically committed transaction that contains a single query.
- Bolt protocol
-
Bolt is a protocol used for interaction between Neo4j instances and drivers.
- bookmark
-
A marker the client can request from the cluster to ensure that it is able to read its own writes so that the application’s state is consistent and only databases that have a copy of the bookmark are permitted to respond.
- category (Bloom)
-
A category is based on a node label and is defined in a Perspective as a way of visually distinguishing nodes with the same label(s).
- causal consistency
-
All servers in a cluster agree on the order in which transactions take place. The position of a server on the causal chain can be guaranteed using a bookmark.
- cluster
-
A Neo4j DBMS that spans multiple servers working together to increase fault tolerance and/or read scalability. Databases on a cluster may be configured to replicate across servers in the cluster thus achieving read scalability or high availability.
- client application
-
Software that interacts with a Neo4j server.
- commit
-
A commit is the successful completion of a transaction, which ensures durability of any changes made. For more details, visit Operations Manual → Transaction management.
- composite database
-
Composite databases are the means to access partitioned graph data with a single Cypher query.
- constraint
-
Constraints are sets of data modeling rules that ensure the data is consistent and reliable.
- Cypher®
-
Neo4j’s graph query language.
- data model
-
A data model defines how information is organized in a database. A good data model will make querying and understanding your data easier. In Neo4j, the data models have a graph structure.
- database
-
A database is a container used by the DBMS to manage and store graph data. The physical structure of data is controlled by the database.
- database vs graph
-
Databases are the physical containers of graph data. Graphs are the logical structure of data in Neo4j.
- Database Management System
-
Database Management System, or DBMS, capable of managing multiple databases. A DBMS may run on a single server, or span several servers configured as a cluster.
- database schema
-
The prescribed property existence and datatypes for nodes and relationships.
- deallocate
-
An act of removing a database from a server or a server from a cluster without loss of data or reduced fault tolerance.
- degree (of a node)
-
The number of relationships of a specific node; loops are counted twice.
- disaster recovery
-
A manual intervention to restore availability of a cluster, or databases within a cluster.
- driver
-
A software library that provides access to Neo4j from a particular programming language.
- election
-
In the event that the Raft leader becomes unresponsive, followers automatically trigger an election and vote for a new leader.
- entity
-
A node or a relationship.
- expression (Cypher)
-
A component of a Cypher query which produces values. It may be used in projections, as a predicate, or when setting properties on graph elements.
- fabric
-
Fabric is the architectural design of a unified system that provides a single access point to local or distributed graph data.
- fault tolerance
-
A guarantee that a cluster can maintain a database’s persistence and availability in the event of one or more servers failing.
- follower
-
A primary copy of a database acting as a follower, receives and acknowledges synchronous writes from the leader.
- Generative AI (GenAI)
-
A type of artificial intelligence (AI) system that generates text, images, or other media in response to prompts.
- graph
-
A logical representation of a set of nodes where some pairs are connected by relationships.
- index
-
Data structure that improves read performance of a database.
- knowledge graph
-
A specific type of graph that has an organizing principle so that a user (or a computer system) can reason about the underlying data. The organizing principle provides an additional layer of structure that adds context to support knowledge discovery.
- label
-
Marks a node as a member of a named and indexed subset. A node may be assigned zero or more labels.
- leader
-
A single primary copy of a database is designated as the leader. It receives all write transactions from clients and replicates writes synchronously to followers and asynchronously to secondary copies of the database.
- main database
-
In terms of Neo4j Enterprise Studio, the database(s) containing the user’s data. Can exist in the same Neo4j deployment as the tool asset database.
- motif
-
A description of a specific pattern within a graph.
- node
-
A node represents an entity or discrete object in your graph data model. Nodes can be connected by relationships, hold data in properties, and are classified by labels.
- operator
-
A symbol representing a mathematical or logical operation.
- parameter
-
Named value provided when running a Cypher statement.
- path
-
A sequence of nodes and the relationships connecting them, that does not contain duplicate relationships. Several paths can match a pattern.
- pattern
-
A specific arrangement of nodes and relationships that can be matched in a graph. A pattern follows a motif.
- perspective (Bloom)
-
A Perspective defines a certain business view or domain that can be found in the target Neo4j graph. A single Neo4j graph can be viewed through different Perspectives, each tailored for a different business purpose.
- primary
-
A copy of the database that is able to process write transactions and is eligible to be elected as a leader. It participates in fault tolerant writes as it is part of the majority required to acknowledge and commit write transactions.
- primary vs secondary
-
In a cluster, databases can operate in either primary or secondary mode. Primary databases are able to process write and read transactions, ensuring fault tolerance. Secondary databases are replicated asynchronously from primaries, and their main purpose is to provide read scaling within the cluster.
- project (Aura)
-
An isolated environment in the unified Aura console that contains its own database instances, configurations, and resources. Preceded by tenant in the classic Aura console.
- property
-
Properties are key-value pairs that are used for storing data on nodes and relationships.
- query (Cypher)
-
A statement that retrieves or writes information to a database.
- Raft group
-
A group of servers that are participating in hosting a particular database in primary mode.
- Raft group member
-
A server that is participating in a Raft group. A server can be a member of one or more groups.
- Raft log
-
A shared log between all Raft group members that is guaranteed to be consistently updated and viewed by those members. The log contains both database data and operational state of the Raft group.
- Raft protocol
-
The networking mechanism that enables a database to replicate its data across multiple servers to give high availability for accessing the data and high durability to the data stored.
- read scaling
-
Distributing query load by creating additional database copies hosted in secondary mode (read-only).
- relationship
-
A relationship represents a connection between nodes in your graph data model. Relationships connect a source node to a target node, hold data in properties, and are classified by type.
- secondary
-
An asynchronously replicated copy of the database that provides read scaling within the cluster.
- seed
-
A seed is a database dump or a full backup used to create a database on a cluster. This is sometimes called seeding.
- server
-
A physical machine, a virtual machine, or a container running an instance of Neo4j. Servers can be standalone or part of a cluster.
- session
-
A causally linked sequence of transactions.
- session consistency
-
An alternative name for Neo4j’s causal consistency.
- standalone
-
A single server running Neo4j and not part of a cluster.
- synchronous replication
-
Synchronous replication requires the leader primary to replicate a transaction and block the commit until a quorum of the follower primaries acknowledges that the transaction is successfully replicated. Once the transaction is replicated, the commit is allowed to proceed. This ensures data durability and consistency within the cluster.
- system database
-
A database used by Neo4j to store system information.
- tenant (Aura)
-
An isolated environment in the classic Aura console that contains its own database instances, configurations, and resources. Replaced by project in the unified Aura console.
- tool asset database
-
In terms of Neo4j Enterprise Studio, the database where tools' assets are stored. This can be in the same Neo4j deployment as the main database(s) or in a separate deployment.
- topology
-
A configuration that describes how the copies of a database should be spread across the servers in a cluster, see primary mode and secondary mode.
- transaction
-
A transaction comprises a unit of work performed against a database. It is treated in a coherent and reliable way, independent of other transactions. Transactions comply with the ACID consistency model (atomic, consistent, isolated, and durable).