PageSourceSearch

https://archive-ce-3-19.netlify.app/assets/js/b29899bb.2598ad31.js

js archive-ce-3-19.netlify.app collected 2026-10-03 10:28:09 UTC 14,039 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["103"],{79677:function(e,s,n){n.r(s),n.d(s,{frontMatter:()=>o,toc:()=>c,default:()=>h,metadata:()=>i,assets:()=>l,contentTitle:()=>a});var i=JSON.parse('{"id":"network-policy/get-started/about-kubernetes-ingress","title":"Kubernetes ingress","description":"Learn the different ingress implementations and how ingress and policy interact.","source":"@site/calico-enterprise_versioned_docs/version-3.19-2/network-policy/get-started/about-kubernetes-ingress.mdx","sourceDirName":"network-policy/get-started","slug":"/network-policy/get-started/about-kubernetes-ingress","permalink":"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-ingress","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico-enterprise_versioned_docs/version-3.19-2/network-policy/get-started/about-kubernetes-ingress.mdx","tags":[],"version":"3.19-2","frontMatter":{"description":"Learn the different ingress implementations and how ingress and policy interact."},"sidebar":"calicoEnterpriseSidebar","previous":{"title":"Kubernetes services","permalink":"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-services"},"next":{"title":"Kubernetes egress","permalink":"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-egress"}}'),t=n(70689),r=n(17869);let o={description:"Learn the different ingress implementations and how ingress and policy interact."},a="Kubernetes ingress",l={},c=[{value:"What is Kubernetes ingress?",id:"what-is-kubernetes-ingress",level:2},{value:"Why use Kubernetes Ingress?",id:"why-use-kubernetes-ingress",level:2},{value:"Types of Ingress solutions",id:"types-of-ingress-solutions",level:2},{value:"In-cluster ingress solutions",id:"in-cluster-ingress-solutions",level:3},{value:"External ingress solutions",id:"external-ingress-solutions",level:3},{value:"Show me everything!",id:"show-me-everything",level:2},{value:"Additional resources",id:"additional-resources",level:2}];function d(e){let s={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",img:"img",li:"li",p:"p",strong:"strong",ul:"ul",...(0,r.R)(),...e.components};return(0,t.jsxs)(t.Fragment,{children:[(0,t.jsx)(s.header,{children:(0,t.jsx)(s.h1,{id:"kubernetes-ingress",children:"Kubernetes ingress"})}),"\n",(0,t.jsx)(s.admonition,{type:"note",children:(0,t.jsx)(s.p,{children:"This guide provides education material\nthat is not specific to Calico Enterprise."})}),"\n",(0,t.jsx)(s.p,{children:"In this guide you will learn:"}),"\n",(0,t.jsxs)(s.ul,{children:["\n",(0,t.jsx)(s.li,{children:"What is Kubernetes ingress?"}),"\n",(0,t.jsx)(s.li,{children:"Why use ingress?"}),"\n",(0,t.jsx)(s.li,{children:"What are the differences between different ingress implementations?"}),"\n",(0,t.jsx)(s.li,{children:"How does ingress and network policy interact?"}),"\n",(0,t.jsx)(s.li,{children:"How does ingress and services fit together under the covers?"}),"\n"]}),"\n",(0,t.jsx)(s.h2,{id:"what-is-kubernetes-ingress",children:"What is Kubernetes ingress?"}),"\n",(0,t.jsxs)(s.p,{children:["Kubernetes Ingress builds on top of Kubernetes ",(0,t.jsx)(s.a,{href:"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-services",children:"Services"})," to provide\nload balancing at the application layer, mapping HTTP and HTTPS requests with particular domains or URLs to Kubernetes\nservices. Ingress can also be used to terminate SSL / TLS before load balancing to the service."]}),"\n",(0,t.jsxs)(s.p,{children:["The details of how Ingress is implemented depend on which ",(0,t.jsx)(s.a,{href:"https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/",children:"Ingress Controller"})," you are using. The Ingress\nController is responsible for monitoring Kubernetes ",(0,t.jsx)(s.a,{href:"https://kubernetes.io/docs/concepts/services-networking/ingress/",children:"Ingress"})," resources and provisioning / configuring one\nor more ingress load balancers to implement the desired load balancing behavior."]}),"\n",(0,t.jsx)(s.p,{children:"Unlike Kubernetes services, which are handled at the network layer (L3-4), ingress load balancers operate at the\napplication layer (L5-7). Incoming connections are terminated at the load balancer so it can inspect the individual HTTP /\nHTTPS requests. The requests are then forwarded via separate connections from the load balancer to the chosen service\nbacking pods. As a result, network policy applied to the backing pods can restrict access to only allow connections from the load\nbalancer, but cannot restrict access to specific original clients."}),"\n",(0,t.jsx)(s.h2,{id:"why-use-kubernetes-ingress",children:"Why use Kubernetes Ingress?"}),"\n",(0,t.jsxs)(s.p,{children:["Given that Kubernetes ",(0,t.jsx)(s.a,{href:"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-services",children:"Services"})," already provide a mechanism for load\nbalancing access to services from outside of the cluster, why might you want to use Kubernetes Ingress?"]}),"\n",(0,t.jsx)(s.p,{children:"The mainline use case is if you have multiple HTTP / HTTPS services that you want to expose through a single external IP\naddress, perhaps with each service having a different URL path, or perhaps as multiple different domains. This is lot\nsimpler from a client configuration point of view than exposing each service outside of the cluster using Kubernetes\nServices, which would give each service a separate external IP address."}),"\n",(0,t.jsxs)(s.p,{children:['If on the other hand, your application architecture is fronted by a single "front end" microservice then Kubernetes\nServices likely already meet your needs. In this case you might prefer to not add Ingress to the picture, both from a\nsimplicity point of view, and potentially also so you can more easily restrict access to specific clients using network\npolicy. In effect, your "front end" microservice already plays the role of Kubernetes Ingress, in a way that is not that\ndissimilar to ',(0,t.jsx)(s.a,{href:"#in-cluster-ingress-solutions",children:"in-cluster ingress"}
1)," solutions discussed below."]}),"\n",(0,t.jsx)(s.h2,{id:"types-of-ingress-solutions",children:"Types of Ingress solutions"}),"\n",(0,t.jsx)(s.p,{children:"Broadly speaking there are two types of ingress solutions:"}),"\n",(0,t.jsxs)(s.ul,{children:["\n",(0,t.jsx)(s.li,{children:"In-cluster ingress - where ingress load balancing is performed by pods within the cluster itself."}),"\n",(0,t.jsx)(s.li,{children:"External ingress - where ingress load balancing is implemented outside of the cluster by\nappliances or cloud provider capabilities."}),"\n"]}),"\n",(0,t.jsx)(s.h3,{id:"in-cluster-ingress-solutions",children:"In-cluster ingress solutions"}),"\n",(0,t.jsx)(s.p,{children:"In-cluster ingress solutions use software load balancers running in pods within the cluster itself. There are many\ndifferent ingress controllers to consider that follow this pattern, including for example the NGINX ingress controller."}),"\n",(0,t.jsx)(s.p,{children:"The advantages of this approach are that you can:"}),"\n",(0,t.jsxs)(s.ul,{children:["\n",(0,t.jsx)(s.li,{children:"horizontally scale your ingress solution up to the limits of Kubernetes"}),"\n",(0,t.jsx)(s.li,{children:"choose the ingress controller that best suits your specific needs, for example, with particular load balancing\nalgorithms, or security options."}),"\n"]}),"\n",(0,t.jsxs)(s.p,{children:["To get your ingress traffic to the in-cluster ingress pods, the ingress pods are normally exposed externally as a\nKubernetes service, so you can use any of the standard ways of accessing the service from outside of the cluster. A\ncommon approach is use an external network load balancer or service IP advertisement, with ",(0,t.jsx)(s.code,{children:"externalTrafficPolicy:local"}),".\nThis minimizes the number of network hops, and retains the client source IP address, which allows network policy to be used\nto restrict access to the ingress pods to particular clients if desired."]}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.img,{alt:"In-cluster ingress",src:n(28272).A+"",width:"760",height:"248"})}),"\n",(0,t.jsx)(s.h3,{id:"external-ingress-solutions",children:"External ingress solutions"}),"\n",(0,t.jsx)(s.p,{children:"External ingress solutions use application load balancers outside of the cluster. The exact details and\nfeatures depend on which ingress controller you are using, but most cloud providers include an ingress controller that\nautomates the provisioning and management of the cloud provider's application load balancers to provide ingress."}),"\n",(0,t.jsx)(s.p,{children:"The advantages of this type of ingress solution is that your cloud provider handles the operational complexity of the\ningress for you. The downsides are a potentially more limited set of features compared to the rich range of in-cluster\ningress solutions, and the maximum number of services exposed by ingress being constrained by cloud provider specific\nlimits."}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.img,{alt:"External ingress",src:n(13040).A+"",width:"760",height:"248"})}),"\n",(0,t.jsxs)(s.p,{children:["Note that most application load balancers support a basic mode of operation of forwarding traffic to the chosen service\nbacking pods via the ",(0,t.jsx)(s.a,{href:"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-services#node-port-services",children:"node port"})," of the\ncorresponding service."]}),"\n",(0,t.jsx)(s.p,{children:"In addition to this basic approach of load balancing to service node ports, some cloud providers support a second mode\nof application layer load balancing, which load balances directly to the pods backing each service, without going via\nnode-ports or other kube-proxy service handling. This has the advantage of eliminating the potential second network hop\nassociated with node ports load balancing to a pod on a different node. The potential disadvantage is that if you are\noperating at very high scales, for example with hundreds of pods backing a service, you may exceed the application layer\nload balancers maximum limit of IPs it can load balance to in this mode. In this case switching to an in-cluster ingress\nsolution is likely the better fit for you."}),"\n",(0,t.jsx)(s.h2,{id:"show-me-everything",children:"Show me everything!"}),"\n",(0,t.jsxs)(s.p,{children:["All the above diagrams focus on connection level (L5-7) representation of ingress and services. You can learn more about\nthe network level (L3-4) interactions involved in handling the connections, including which scenarios client source IP\naddresses are maintained, in the ",(0,t.jsx)(s.a,{href:"/calico-enterprise/3.19/network-policy/get-started/about-kubernetes-services",children:"About Kubernetes Services"})," guide."]}),"\n",(0,t.jsx)(s.p,{children:"If you are already up to speed on how services work under the covers, here are some more complete diagrams that show details of how services are load balanced at the network layer (L3-4)."}),"\n",(0,t.jsx)(s.admonition,{type:"note",children:(0,t.jsx)(s.p,{children:"You can successfully use ingress without needing to understand this next level of detail! So feel free to skip\nover these diagrams if you don't want to dig deeper into how services and ingress interact under the covers."})}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsxs)(s.strong,{children:["In-cluster ingress solution exposed as service type ",(0,t.jsx)(s.code,{children:"LoadBalancer"})," with ",(0,t.jsx)(s.code,{children:"externalTrafficPolicy:local"})]})}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.img,{alt:"In-cluster ingress with NLB local",src:n(89393).A+"",width:"1060",height:"380"})}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.strong,{children:"Exter
1nal ingress solution via node ports"})}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.img,{alt:"External ingress via node port",src:n(51293).A+"",width:"960",height:"380"})}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.strong,{children:"External ingress solution direct to pods"})}),"\n",(0,t.jsx)(s.p,{children:(0,t.jsx)(s.img,{alt:"External ingress direct to pods",src:n(90254).A+"",width:"802",height:"380"})}),"\n",(0,t.jsx)(s.h2,{id:"additional-resources",children:"Additional resources"}),"\n",(0,t.jsxs)(s.ul,{children:["\n",(0,t.jsx)(s.li,{children:(0,t.jsx)(s.a,{href:"https://www.projectcalico.org/everything-you-need-to-know-about-kubernetes-ingress-networking/",children:"Video: Everything you need to know about Kubernetes Ingress networking "})}),"\n",(0,t.jsx)(s.li,{children:(0,t.jsx)(s.a,{href:"https://www.projectcalico.org/everything-you-need-to-know-about-kubernetes-services-networking/",children:"Video: Everything you need to know about Kubernetes Services networking "})}),"\n"]})]})}function h(e={}){let{wrapper:s}={...(0,r.R)(),...e.components};return s?(0,t.jsx)(s,{...e,children:(0,t.jsx)(d,{...e})}):d(e)}},13040:function(e,s,n){n.d(s,{A:()=>i});let i=n.p+"assets/images/ingres-external-61762bf0d132a8eb2ab1080e1b65bac3.svg"},90254:function(e,s,n){n.d(s,{A:()=>i});let i=n.p+"assets/images/ingress-external-direct-to-pods-95ae5150ca478ff2b87b750586f19c6b.svg"},51293:function(e,s,n){n.d(s,{A:()=>i});let i=n.p+"assets/images/ingress-external-node-ports-c8e0de7aec96801c340be6436d52d6ab.svg"},89393:function(e,s,n){n.d(s,{A:()=>i});let i=n.p+"assets/images/ingress-in-cluster-nlb-local-7524c660d10f21f3f7875eb553ca37f0.svg"},28272:function(e,s,n){n.d(s,{A:()=>i});let i=n.p+"assets/images/ingress-in-cluster-cd15c60b9423ec081e33c35221e091b7.svg"},17869:function(e,s,n){n.d(s,{R:()=>o,x:()=>a});var i=n(16645);let t={},r=i.createContext(t);function o(e){let s=i.useContext(r);return i.useMemo(function(){return"function"==typeof e?e(s):{...s,...e}},[s,e])}function a(e){let s;return s=e.disableParentContext?"function"==typeof e.components?e.components(t):e.components||t:o(e.components),i.createElement(r.Provider,{value:s},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.