🎯 Lesson Objective_
Understand Gateway API v1.4 is the new standard replacing traditional Ingress, how to use GatewayClass, Gateway, HTTPRoute to route traffic, traffic splitting for canary deployment, TLS termination, and popular implementations.
1. Problem with Traditional Ingress
Ingress API exists since K8s 1.1 and has many limitations:
- Annotation hell: each controller (nginx, traefik, haproxy) uses different annotations → vendor lock-in
- Limited expressiveness: no built-in traffic splitting, header modification
- Single resource: no separation of infrastructure vs application teams roles
- TLS limitations: no natively TLS backend
Ingress-NGINX: entering maintenance mode (March 2026). New features are not added.
2. Gateway API v1.4 GA — October 2025
Gateway API is a Kubernetes SIG-Network project, standardizing traffic management with:
- Role-oriented design: clearly separate the roles of infrastructure provider, cluster operator, application developer
- Expressive: traffic splitting, header matching, URL rewriting is first-class citizens
- Portable: same manifest works with any Gateway API implementation
- Extensible: TLSRoute, GRPCRoute, TCPRoute, custom extensions
3. Resource Hierarchy
Infrastructure Provider
└── GatewayClass (định nghĩa loại gateway: cilium, envoy-gateway...)
│
Cluster Operator
└── Gateway (instance của gateway, lắng nghe trên port/protocol)
│
Application Developer
└── HTTPRoute / GRPCRoute (route traffic từ gateway đến services)
3.1 GatewayClass
apiVersion: gateway.networking.k8s.io/v1
kind: GatewayClass
metadata:
name: cilium
spec:
controllerName: io.cilium/gateway-controller
3.2 Gateway
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: main-gateway
namespace: infra
spec:
gatewayClassName: cilium
listeners:
- name: http
protocol: HTTP
port: 80
- name: https
protocol: HTTPS
port: 443
tls:
mode: Terminate
certificateRefs:
- name: tls-cert
namespace: infra
3.3 HTTPRoute — Path-based Routing
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: app-routes
namespace: production
spec:
parentRefs:
- name: main-gateway
namespace: infra
hostnames:
- "api.example.com"
rules:
# Route /api/v1 → backend-v1
- matches:
- path:
type: PathPrefix
value: /api/v1
backendRefs:
- name: backend-v1
port: 8080
# Route /api/v2 → backend-v2
- matches:
- path:
type: PathPrefix
value: /api/v2
backendRefs:
- name: backend-v2
port: 8080
# Route mọi thứ còn lại → frontend
- backendRefs:
- name: frontend
port: 3000
4. Traffic Splitting — Canary Deployment
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: canary-route
namespace: production
spec:
parentRefs:
- name: main-gateway
namespace: infra
hostnames:
- "myapp.example.com"
rules:
- backendRefs:
- name: myapp-stable # 90% traffic
port: 80
weight: 90
- name: myapp-canary # 10% traffic
port: 80
weight: 10
5. Header Matching and URL Rewriting__HTMLTAG_130___
rules:
# Route dựa trên header
- matches:
- headers:
- name: "X-Version"
value: "beta"
backendRefs:
- name: backend-beta
port: 8080
URL rewrite: /old-path/* → /new-path/*
- matches:
- path:
type: PathPrefix
value: /old-path
filters:
- type: URLRewrite
urlRewrite:
path:
type: ReplacePrefixMatch
replacePrefixMatch: /new-path
backendRefs:
- name: backend
port: 8080
Redirect HTTP → HTTPS
matches:
- path:
type: PathPrefix
value: /
filters:
type: RequestRedirect
requestRedirect:
scheme: https
statusCode: 301
rules:
# Route dựa trên header
- matches:
- headers:
- name: "X-Version"
value: "beta"
backendRefs:
- name: backend-beta
port: 8080
URL rewrite: /old-path/* → /new-path/*
- matches:
- path:
type: PathPrefix
value: /old-path
filters:
- type: URLRewrite
urlRewrite:
path:
type: ReplacePrefixMatch
replacePrefixMatch: /new-path
backendRefs:
- name: backend
port: 8080
Redirect HTTP → HTTPS
matches:
- path: type: PathPrefix value: / filters:
type: RequestRedirect requestRedirect: scheme: https statusCode: 301
6. BackendTLSPolicy — TLS to Backend (v1.4)
apiVersion: gateway.networking.k8s.io/v1alpha3
kind: BackendTLSPolicy
metadata:
name: backend-tls
spec:
targetRefs:
- group: ""
kind: Service
name: secure-backend
validation:
caCertificateRefs:
- group: ""
kind: Secret
name: backend-ca-cert
hostname: secure-backend.production.svc.cluster.local
7. Cross-namespace Routing with ReferenceGrant
# Cho phép HTTPRoute trong namespace "production" dùng Gateway trong namespace "infra"
apiVersion: gateway.networking.k8s.io/v1beta1
kind: ReferenceGrant
metadata:
name: allow-production
namespace: infra
spec:
from:
- group: gateway.networking.k8s.io
kind: HTTPRoute
namespace: production
to:
- group: gateway.networking.k8s.io
kind: Gateway
name: main-gateway
8. GRPCRoute
apiVersion: gateway.networking.k8s.io/v1
kind: GRPCRoute
metadata:
name: grpc-route
spec:
parentRefs:
- name: main-gateway
namespace: infra
hostnames:
- "grpc.example.com"
rules:
- matches:
- method:
service: mypackage.MyService
method: GetUser
backendRefs:
- name: user-service
port: 9090
9. Implementations Gateway API
- Cilium Gateway API: eBPF-based, native integration with Cilium CNI, most effective
- Envoy Gateway: Envoy-based, feature-rich, CNCF project
- nginx-gateway-fabric: nginx-based, stable
- Istio: integration with service mesh Istio
- Traefik: supports Gateway API v1 from v3.0
10. Migration from Ingress to Gateway API
# Ingress cũ apiVersion: networking.k8s.io/v1 kind: Ingress metadata: annotations: nginx.ingress.kubernetes.io/rewrite-target: / spec: rules: - host: example.com http: paths: - path: /api pathType: Prefix backend: service: name: api-service port: number: 8080Tương đương Gateway API (không cần annotations!)
HTTPRoute như ví dụ ở phần 3.3
Summary
- Gateway API v1.4 GA (October 2025) = new standard replacing Ingress
- Role-oriented: GatewayClass (infra) → Gateway (cluster ops) → HTTPRoute (app dev)
- Traffic splitting, header matching, URL rewrite is first-class
- BackendTLSPolicy: TLS to backend (v1.4)
- Cilium Gateway API: eBPF-based, recommended with Cilium CNI
- Ingress-NGINX: maintenance mode March 2026 — should migrate to Gateway API