Ingress Routing
Ingress Routing and Path Matching¶
Ingress controllers in Kubernetes act as the gateway for external traffic, enabling sophisticated routing rules to direct requests to the appropriate backend services. Path-based routing and advanced matching rules are critical for managing traffic in multi-service deployments. This section covers configuring path-based routing, path rewriting, and annotation-based configuration for ingress controllers.
Path-Based Routing¶
Path-based routing allows you to direct traffic to different services based on the URL path. Ingress resources define these rules using the path field. By default, path matching is prefix-based, meaning a path like /api will match /api/v1, /api/users, etc. For exact matches, use the pathType: Exact field.
Example: Basic Path-Based Routing¶
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: multi-path-ingress
namespace: default
spec:
rules:
- http:
paths:
- path: /app1
pathType: Prefix
backend:
service:
name: app1-service
port:
number: 80
- path: /app2
pathType: Prefix
backend:
service:
name: app2-service
port:
number: 80
This configuration routes traffic to app1-service for paths starting with /app1 and to app2-service for /app2.
Advanced Path Matching Rules¶
Path Rewriting¶
Some ingress controllers (e.g., NGINX) support path rewriting to modify the request path before routing. Use the rewrite field to strip prefixes or adjust paths.
Example: Path Rewriting¶
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: rewrite-ingress
namespace: default
spec:
rules:
- http:
paths:
- path: /old-path
pathType: Prefix
backend:
service:
name: app-service
port:
number: 80
rewrite: /new-path
This rule routes traffic to app-service and rewrites the path to /new-path before forwarding the request.
Annotation-Based Configuration¶
Annotations allow you to fine-tune ingress controller behavior. These are controller-specific and often used for advanced settings like timeouts, TLS configurations, or load balancing. For example, the NGINX Ingress Controller uses annotations like nginx.ingress.kubernetes.io/rewrite-target for path rewriting.
Example: Annotation for Timeout Settings¶
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: timeout-ingress
namespace: default
annotations:
nginx.ingress.kubernetes.io/proxy-read-timeout: "300"
nginx.ingress.kubernetes.io/proxy-send-timeout: "300"
spec:
rules:
- http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: timeout-service
port:
number: 80
This configuration sets proxy timeouts to 300 seconds for the NGINX controller.
Key Takeaways¶
- Use
pathType: Prefixfor general path matching andExactfor strict matches. - Path rewriting is useful for removing URL prefixes or redirecting traffic.
- Annotations provide controller-specific customization, such as timeouts or TLS settings.
- Always test routing rules with tools like
curlorkubectlto validate behavior.