The mechanism
External HTTP routing requires more than creating an API object. An Ingress describes routing rules that an Ingress controller implements. Gateway API provides a more role-oriented resource model, also requiring installed API resources and a compatible implementation.
The Kubernetes documentation describes Ingress as frozen and directs new feature development toward Gateway API. That does not mean every cluster already has Gateway API or that every controller supports every feature. Verify resource availability, controller class and supported capabilities.
Keep exposure deliberate. A learning example should not create a public load balancer, change DNS or obtain certificates automatically. First draw the route and review the ownership of each boundary.
Worked example
This is an architecture worksheet, not an apply-ready Gateway manifest. It highlights the dependencies that a copied route example often hides. Every pending item needs actual cluster evidence before implementation.
Public hostname: not configured
TLS certificate: not requested
Gateway API CRDs: unverified
Compatible controller: unverified
GatewayClass / ownership: unverified
Route -> parcelops Service port 80: proposed
Backend readiness and policy: must be checked separately
Practice: predict, inspect, explain
Offline exercise. Assign platform-owner and application-owner responsibilities for listener configuration, route attachment, certificates and backend Services. Then consider a route that exists but is not accepted by its parent. Explain why the object’s existence alone does not establish traffic flow.
Expected observation: status conditions and implementation support matter as much as YAML structure. Describe an internal-only review path before public exposure. Keep controller installation, load-balancer provisioning and DNS changes outside this handbook’s executed scope.
Troubleshooting and trade-offs
If a route does nothing, inspect whether its controller and API resources exist and whether attachment is accepted. If TLS fails, identify the termination point and certificate ownership. If backend traffic fails, return to Service endpoints and policy. Avoid solving a missing controller by installing an arbitrary package or opening broad network access without review.
Interview practice
Does creating an Ingress start a proxy?
Not by itself. An appropriate controller must observe the resource and configure the actual routing infrastructure.
Why choose Gateway API carefully?
It offers a richer, role-oriented model, but requires compatible CRDs and implementation support. Feature availability and ownership must be verified for the actual cluster.
Completion check
List the prerequisites and acceptance evidence for one proposed external route without provisioning it.
Sources and version notes
Baseline checked 6 October 2026: the official release page lists Kubernetes 1.37.1. Verify your cluster and distribution prerequisites. All manifests are offline teaching examples; no cluster mutations or cloud resources are executed by this handbook.
Make the understanding yours.
Use the completion check above. Mark this chapter when you can explain the mechanism and its limits.
Self-assessed reading progress. This does not certify that a lab ran or a system is secure.