Skip to lesson
supraj.dev THE ENGINEERING HANDBOOKS
LEARN / BUILD / VERIFY2026 edition · checked 06 Oct

CHAPTER 09 / 30 · Connect the workload

Ingress and Gateway API prerequisites

Distinguish API resources from the controllers and infrastructure that implement traffic routing.

4 min read + practiceWorked exerciseInterview practice

The mechanism

External HTTP routing requires more than creating an API object. An Ingress describes routing rules that an Ingress controller implements. Gateway API provides a more role-oriented resource model, also requiring installed API resources and a compatible implementation.

The Kubernetes documentation describes Ingress as frozen and directs new feature development toward Gateway API. That does not mean every cluster already has Gateway API or that every controller supports every feature. Verify resource availability, controller class and supported capabilities.

Keep exposure deliberate. A learning example should not create a public load balancer, change DNS or obtain certificates automatically. First draw the route and review the ownership of each boundary.

External client
Gateway or ingress controller
Service
Ready backend

Worked example

This is an architecture worksheet, not an apply-ready Gateway manifest. It highlights the dependencies that a copied route example often hides. Every pending item needs actual cluster evidence before implementation.

Public hostname: not configured
TLS certificate: not requested
Gateway API CRDs: unverified
Compatible controller: unverified
GatewayClass / ownership: unverified
Route -> parcelops Service port 80: proposed
Backend readiness and policy: must be checked separately

Practice: predict, inspect, explain

Offline exercise. Assign platform-owner and application-owner responsibilities for listener configuration, route attachment, certificates and backend Services. Then consider a route that exists but is not accepted by its parent. Explain why the object’s existence alone does not establish traffic flow.

Expected observation: status conditions and implementation support matter as much as YAML structure. Describe an internal-only review path before public exposure. Keep controller installation, load-balancer provisioning and DNS changes outside this handbook’s executed scope.

Troubleshooting and trade-offs

If a route does nothing, inspect whether its controller and API resources exist and whether attachment is accepted. If TLS fails, identify the termination point and certificate ownership. If backend traffic fails, return to Service endpoints and policy. Avoid solving a missing controller by installing an arbitrary package or opening broad network access without review.

Interview practice

Does creating an Ingress start a proxy?

Not by itself. An appropriate controller must observe the resource and configure the actual routing infrastructure.

Why choose Gateway API carefully?

It offers a richer, role-oriented model, but requires compatible CRDs and implementation support. Feature availability and ownership must be verified for the actual cluster.

Completion check

List the prerequisites and acceptance evidence for one proposed external route without provisioning it.

Sources and version notes

Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.

YOUR NEXT STEP

Make the understanding yours.

Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.

Self-assessed reading progress. This does not certify that a lab ran or a system is secure.