Skip to content

Ingress Controllers

Advanced Features

  • Rate Limiting: NGINX uses nginx.ingress.kubernetes.io/limit-rps or nginx.ingress.kubernetes.io/limit-req for rate limiting. Example:
    apiVersion: networking.k8s.io/v1
    kind: Ingress
    metadata:
      name: rate-limit-ingress
      annotations:
        nginx.ingress.kubernetes.io/limit-rps: "100"
        nginx.ingress.kubernetes.io/limit-req: "rate-limit"
    spec:
      rules:
      - http:
          paths:
          - path: /
            pathType: Prefix
            backend:
              service:
                name: my-service
                port:
                  number: 80
    
  • Headers: Add custom headers via annotations (e.g., nginx.ingress.kubernetes.io/add-header). Example:
    annotations:
      nginx.ingress.kubernetes.io/add-header: "X-Custom-Header: MyValue"
    
  • Dynamic Updates: Traefik automatically reloads configurations when services change. Example IngressRoute for dynamic routing:
    apiVersion: traefik.containo.us/v1alpha1
    kind: IngressRoute
    metadata:
      name: dynamic-route
    spec:
      entryPoints:
        - web
      routes:
        - match: Host(`example.com`)
          kind: Service
          name: my-service
          port: 80
      tls:
        secretName: traefik-cert
    
  • TLS Setup: For NGINX, use nginx.ingress.kubernetes.io/ssl-redirect and nginx.ingress.kubernetes.io/force-ssl-redirect for HTTPS redirection. For Traefik, configure TLS with a secretName in IngressRoute or use Let's Encrypt via ACME challenges. Example:
    annotations:
      cert-manager.io/cluster-issuer: letsencrypt-prod
    
    Ensure a Certificate resource is defined for automatic certificate management.

Key takeaways

  • Ingress controllers like NGINX and Traefik manage external traffic to Kubernetes services, enabling TLS, routing, and scalability.
  • NGINX relies on Ingress resources with annotations, while Traefik uses IngressRoute and dynamic discovery.
  • TLS termination and path-based routing are critical for securing and organizing external access.
  • Proper configuration ensures secure, maintainable, and scalable external access to cluster resources.