Chuyển đến nội dung chính

LESSON 15: GATEWAY API — NEW STANDARDS TO REPLACE INGRESS

Gateway API v1.4 GA (October 2025) is the new standard replacing Ingress controller. GatewayClass, Gateway, HTTPRoute, GRPCRoute. Traffic splitting, TLS, header matching. Implementations: Cilium, Envoy Gateway, nginx-gateway-fabric.

🔒 DevSecOps — Lesson 15 LESSON 15: GATEWAY API — NEW STANDARDS REPLACEMENT INGRESS

KUBERNETES: FROM BASIC TO ADVANCED

Module 4: Networking

xdev.asia

🎯 Lesson Objective_

Understand Gateway API v1.4 is the new standard replacing traditional Ingress, how to use GatewayClass, Gateway, HTTPRoute to route traffic, traffic splitting for canary deployment, TLS termination, and popular implementations.

1. Problem with Traditional Ingress

Ingress API exists since K8s 1.1 and has many limitations:

  • Annotation hell: each controller (nginx, traefik, haproxy) uses different annotations → vendor lock-in
  • Limited expressiveness: no built-in traffic splitting, header modification
  • Single resource: no separation of infrastructure vs application teams roles
  • TLS limitations: no natively TLS backend

Ingress-NGINX: entering maintenance mode (March 2026). New features are not added.

2. Gateway API v1.4 GA — October 2025

Gateway API is a Kubernetes SIG-Network project, standardizing traffic management with:

  • Role-oriented design: clearly separate the roles of infrastructure provider, cluster operator, application developer
  • Expressive: traffic splitting, header matching, URL rewriting is first-class citizens
  • Portable: same manifest works with any Gateway API implementation
  • Extensible: TLSRoute, GRPCRoute, TCPRoute, custom extensions

3. Resource Hierarchy

Infrastructure Provider
    └── GatewayClass (định nghĩa loại gateway: cilium, envoy-gateway...)
           │
Cluster Operator
    └── Gateway (instance của gateway, lắng nghe trên port/protocol)
           │
Application Developer
    └── HTTPRoute / GRPCRoute (route traffic từ gateway đến services)

3.1 GatewayClass

apiVersion: gateway.networking.k8s.io/v1
kind: GatewayClass
metadata:
  name: cilium
spec:
  controllerName: io.cilium/gateway-controller

3.2 Gateway

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: main-gateway
  namespace: infra
spec:
  gatewayClassName: cilium
  listeners:
  - name: http
    protocol: HTTP
    port: 80
  - name: https
    protocol: HTTPS
    port: 443
    tls:
      mode: Terminate
      certificateRefs:
      - name: tls-cert
        namespace: infra

3.3 HTTPRoute — Path-based Routing

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: app-routes
  namespace: production
spec:
  parentRefs:
  - name: main-gateway
    namespace: infra
  hostnames:
  - "api.example.com"
  rules:
  # Route /api/v1 → backend-v1
  - matches:
    - path:
        type: PathPrefix
        value: /api/v1
    backendRefs:
    - name: backend-v1
      port: 8080
  # Route /api/v2 → backend-v2
  - matches:
    - path:
        type: PathPrefix
        value: /api/v2
    backendRefs:
    - name: backend-v2
      port: 8080
  # Route mọi thứ còn lại → frontend
  - backendRefs:
    - name: frontend
      port: 3000

4. Traffic Splitting — Canary Deployment

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: canary-route
  namespace: production
spec:
  parentRefs:
  - name: main-gateway
    namespace: infra
  hostnames:
  - "myapp.example.com"
  rules:
  - backendRefs:
    - name: myapp-stable    # 90% traffic
      port: 80
      weight: 90
    - name: myapp-canary    # 10% traffic
      port: 80
      weight: 10

5. Header Matching and URL Rewriting__HTMLTAG_130___
rules:
# Route dựa trên header
- matches:
  - headers:
    - name: "X-Version"
      value: "beta"
  backendRefs:
  - name: backend-beta
    port: 8080

URL rewrite: /old-path/* → /new-path/*

  • matches:
    • path: type: PathPrefix value: /old-path filters:
    • type: URLRewrite urlRewrite: path: type: ReplacePrefixMatch replacePrefixMatch: /new-path backendRefs:
    • name: backend port: 8080

Redirect HTTP → HTTPS

  • matches:
    • path: type: PathPrefix value: / filters:
    • type: RequestRedirect requestRedirect: scheme: https statusCode: 301

6. BackendTLSPolicy — TLS to Backend (v1.4)

apiVersion: gateway.networking.k8s.io/v1alpha3
kind: BackendTLSPolicy
metadata:
  name: backend-tls
spec:
  targetRefs:
  - group: ""
    kind: Service
    name: secure-backend
  validation:
    caCertificateRefs:
    - group: ""
      kind: Secret
      name: backend-ca-cert
    hostname: secure-backend.production.svc.cluster.local

7. Cross-namespace Routing with ReferenceGrant

# Cho phép HTTPRoute trong namespace "production" dùng Gateway trong namespace "infra"
apiVersion: gateway.networking.k8s.io/v1beta1
kind: ReferenceGrant
metadata:
  name: allow-production
  namespace: infra
spec:
  from:
  - group: gateway.networking.k8s.io
    kind: HTTPRoute
    namespace: production
  to:
  - group: gateway.networking.k8s.io
    kind: Gateway
    name: main-gateway

8. GRPCRoute

apiVersion: gateway.networking.k8s.io/v1
kind: GRPCRoute
metadata:
  name: grpc-route
spec:
  parentRefs:
  - name: main-gateway
    namespace: infra
  hostnames:
  - "grpc.example.com"
  rules:
  - matches:
    - method:
        service: mypackage.MyService
        method: GetUser
    backendRefs:
    - name: user-service
      port: 9090

9. Implementations Gateway API

  • Cilium Gateway API: eBPF-based, native integration with Cilium CNI, most effective
  • Envoy Gateway: Envoy-based, feature-rich, CNCF project
  • nginx-gateway-fabric: nginx-based, stable
  • Istio: integration with service mesh Istio
  • Traefik: supports Gateway API v1 from v3.0

10. Migration from Ingress to Gateway API

# Ingress cũ
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  rules:
  - host: example.com
    http:
      paths:
      - path: /api
        pathType: Prefix
        backend:
          service:
            name: api-service
            port:
              number: 8080

Tương đương Gateway API (không cần annotations!)

HTTPRoute như ví dụ ở phần 3.3

Summary

  • Gateway API v1.4 GA (October 2025) = new standard replacing Ingress
  • Role-oriented: GatewayClass (infra) → Gateway (cluster ops) → HTTPRoute (app dev)
  • Traffic splitting, header matching, URL rewrite is first-class
  • BackendTLSPolicy: TLS to backend (v1.4)
  • Cilium Gateway API: eBPF-based, recommended with Cilium CNI
  • Ingress-NGINX: maintenance mode March 2026 — should migrate to Gateway API