Chuyển đến nội dung chính

BÀI 15: GATEWAY API — CHUẨN MỚI THAY THẾ INGRESS

Gateway API v1.4 GA (10/2025) là chuẩn mới thay thế Ingress controller. GatewayClass, Gateway, HTTPRoute, GRPCRoute. Traffic splitting, TLS, header matching. Implementations: Cilium, Envoy Gateway, nginx-gateway-fabric.

🔒 DevSecOps — Bài 15 BÀI 15: GATEWAY API — CHUẨN MỚI THAY THẾ INGRESS

KUBERNETES: TỪ CƠ BẢN ĐẾN NÂNG CAO

Module 4: Networking

xdev.asia

🎯 Mục tiêu bài học

Hiểu Gateway API v1.4 là chuẩn mới thay thế Ingress truyền thống, cách dùng GatewayClass, Gateway, HTTPRoute để route traffic, traffic splitting cho canary deployment, TLS termination, và các implementations phổ biến.

1. Vấn đề với Ingress Truyền thống

Ingress API tồn tại từ K8s 1.1 và có nhiều hạn chế:

  • Annotation hell: mỗi controller (nginx, traefik, haproxy) dùng annotations khác nhau → vendor lock-in
  • Limited expressiveness: không có built-in traffic splitting, header modification
  • Single resource: không phân tách vai trò infrastructure vs application teams
  • TLS limitations: không có backend TLS natively

Ingress-NGINX: đang vào maintenance mode (tháng 3/2026). Các tính năng mới không được thêm vào.

2. Gateway API v1.4 GA — Tháng 10/2025

Gateway API là Kubernetes SIG-Network project, chuẩn hoá traffic management với:

  • Role-oriented design: phân tách rõ ràng vai trò infrastructure provider, cluster operator, application developer
  • Expressive: traffic splitting, header matching, URL rewriting là first-class citizens
  • Portable: cùng manifest hoạt động với mọi Gateway API implementation
  • Extensible: TLSRoute, GRPCRoute, TCPRoute, custom extensions

3. Resource Hierarchy

Infrastructure Provider
    └── GatewayClass (định nghĩa loại gateway: cilium, envoy-gateway...)
           │
Cluster Operator
    └── Gateway (instance của gateway, lắng nghe trên port/protocol)
           │
Application Developer
    └── HTTPRoute / GRPCRoute (route traffic từ gateway đến services)

3.1 GatewayClass

apiVersion: gateway.networking.k8s.io/v1
kind: GatewayClass
metadata:
  name: cilium
spec:
  controllerName: io.cilium/gateway-controller

3.2 Gateway

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: main-gateway
  namespace: infra
spec:
  gatewayClassName: cilium
  listeners:
  - name: http
    protocol: HTTP
    port: 80
  - name: https
    protocol: HTTPS
    port: 443
    tls:
      mode: Terminate
      certificateRefs:
      - name: tls-cert
        namespace: infra

3.3 HTTPRoute — Path-based Routing

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: app-routes
  namespace: production
spec:
  parentRefs:
  - name: main-gateway
    namespace: infra
  hostnames:
  - "api.example.com"
  rules:
  # Route /api/v1 → backend-v1
  - matches:
    - path:
        type: PathPrefix
        value: /api/v1
    backendRefs:
    - name: backend-v1
      port: 8080
  # Route /api/v2 → backend-v2
  - matches:
    - path:
        type: PathPrefix
        value: /api/v2
    backendRefs:
    - name: backend-v2
      port: 8080
  # Route mọi thứ còn lại → frontend
  - backendRefs:
    - name: frontend
      port: 3000

4. Traffic Splitting — Canary Deployment

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: canary-route
  namespace: production
spec:
  parentRefs:
  - name: main-gateway
    namespace: infra
  hostnames:
  - "myapp.example.com"
  rules:
  - backendRefs:
    - name: myapp-stable    # 90% traffic
      port: 80
      weight: 90
    - name: myapp-canary    # 10% traffic
      port: 80
      weight: 10

5. Header Matching và URL Rewriting

rules:
# Route dựa trên header
- matches:
  - headers:
    - name: "X-Version"
      value: "beta"
  backendRefs:
  - name: backend-beta
    port: 8080

URL rewrite: /old-path/* → /new-path/*

  • matches:
    • path: type: PathPrefix value: /old-path filters:
    • type: URLRewrite urlRewrite: path: type: ReplacePrefixMatch replacePrefixMatch: /new-path backendRefs:
    • name: backend port: 8080

Redirect HTTP → HTTPS

  • matches:
    • path: type: PathPrefix value: / filters:
    • type: RequestRedirect requestRedirect: scheme: https statusCode: 301

6. BackendTLSPolicy — TLS đến Backend (v1.4)

apiVersion: gateway.networking.k8s.io/v1alpha3
kind: BackendTLSPolicy
metadata:
  name: backend-tls
spec:
  targetRefs:
  - group: ""
    kind: Service
    name: secure-backend
  validation:
    caCertificateRefs:
    - group: ""
      kind: Secret
      name: backend-ca-cert
    hostname: secure-backend.production.svc.cluster.local

7. Cross-namespace Routing với ReferenceGrant

# Cho phép HTTPRoute trong namespace "production" dùng Gateway trong namespace "infra"
apiVersion: gateway.networking.k8s.io/v1beta1
kind: ReferenceGrant
metadata:
  name: allow-production
  namespace: infra
spec:
  from:
  - group: gateway.networking.k8s.io
    kind: HTTPRoute
    namespace: production
  to:
  - group: gateway.networking.k8s.io
    kind: Gateway
    name: main-gateway

8. GRPCRoute

apiVersion: gateway.networking.k8s.io/v1
kind: GRPCRoute
metadata:
  name: grpc-route
spec:
  parentRefs:
  - name: main-gateway
    namespace: infra
  hostnames:
  - "grpc.example.com"
  rules:
  - matches:
    - method:
        service: mypackage.MyService
        method: GetUser
    backendRefs:
    - name: user-service
      port: 9090

9. Implementations Gateway API

  • Cilium Gateway API: eBPF-based, tích hợp native với Cilium CNI, hiệu quả nhất
  • Envoy Gateway: Envoy-based, feature-rich, CNCF project
  • nginx-gateway-fabric: nginx-based, ổn định
  • Istio: tích hợp với service mesh Istio
  • Traefik: hỗ trợ Gateway API v1 từ v3.0

10. Migration từ Ingress sang Gateway API

# Ingress cũ
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  annotations:
    nginx.ingress.kubernetes.io/rewrite-target: /
spec:
  rules:
  - host: example.com
    http:
      paths:
      - path: /api
        pathType: Prefix
        backend:
          service:
            name: api-service
            port:
              number: 8080

Tương đương Gateway API (không cần annotations!)

HTTPRoute như ví dụ ở phần 3.3

Tóm tắt

  • Gateway API v1.4 GA (10/2025) = chuẩn mới thay Ingress
  • Role-oriented: GatewayClass (infra) → Gateway (cluster ops) → HTTPRoute (app dev)
  • Traffic splitting, header matching, URL rewrite là first-class
  • BackendTLSPolicy: TLS đến backend (v1.4)
  • Cilium Gateway API: eBPF-based, khuyến nghị với Cilium CNI
  • Ingress-NGINX: maintenance mode tháng 3/2026 — nên migrate sang Gateway API