Lesson 9 / 25

Ingress and the Gateway API

HTTP routing from outside the cluster.

Hosts, paths, TLS

To expose HTTP services, an Ingress routes requests by host and path to Services and terminates TLS, implemented by an ingress controller you install (NGINX-based, Traefik, cloud controllers). The newer Gateway API separates infrastructure (Gateway) from application routes (HTTPRoute), supports richer traffic management (header matching, weighted splits) and is the direction the community is moving. Use cert-manager or your provider for certificates.

An HTTPRoute splitting traffic (Gateway API)

Not applied to a live cluster in this course; check field names against the API reference for your version.

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: shop
spec:
  parentRefs: [{name: public-gateway}]
  hostnames: ["shop.example.com"]
  rules:
  - matches: [{path: {type: PathPrefix, value: /}}]
    backendRefs:
    - {name: web-stable, port: 80, weight: 90}
    - {name: web-canary, port: 80, weight: 10}

Prefer the Gateway API for new setups

Check whether your platform supports it; it handles canaries and team ownership more cleanly than Ingress annotations.

Quick check: What must be installed for an Ingress resource to do anything?

  • A database
  • A second cluster
  • An ingress controller
  • Nothing, it works by itself
Answer

An ingress controller — Ingress is a spec; a controller implements it.