When someone visits your application's hostname, something must accept the connection and send it to the right Kubernetes Service. An Ingress controller or gateway performs that job, often handling HTTPS certificates and routing by hostname or URL path as well.

Ingress and Gateway API describe routing rules in Kubernetes; a controller implements those rules. Gateway API gives shared infrastructure and application routes separate resources. Installing its definitions alone does not install a working proxy. You still need an implementation such as Envoy Gateway, Cilium's Gateway support, Traefik or a provider-managed gateway.

Envoy Gateway manages an Envoy proxy for gateway traffic. Cilium adds gateway capabilities to its broader Kubernetes networking system. Traefik is a reverse proxy with Kubernetes routing integrations. Compare Envoy Gateway versus Traefik when selecting a dedicated gateway, and assess Cilium when it already supplies your cluster network. A managed gateway can suit a team that prefers the cloud provider to handle more of the infrastructure.

The community ingress-nginx controller retired in March 2026. That does not retire the Ingress API or F5 NGINX Ingress Controller, which is a separate project. Identify the controller you actually run before deciding to migrate.

Choose a gateway for the traffic your application uses

If your platform team already operates Cilium, assess its Gateway integration within that supported platform. If you want an independently operated Envoy-based gateway, evaluate Envoy Gateway. Traefik is another candidate for teams needing a path across Ingress and Gateway resources. Cloud-managed gateways can reduce controller operations but introduce provider-specific features and service limits. None is a universal winner.

  1. List protocols and traffic patterns: HTTP, gRPC, WebSocket, TCP, large uploads, streaming responses and long-lived connections.
  2. Inventory behavior beyond routing: authentication, source-IP handling, redirects, rewrites, rate limits, certificate ownership and access logs.
  3. Check the implementation's conformance report for the exact release. Passing core conformance does not establish support for every extension you use.
  4. Choose who owns gateway infrastructure and who may attach routes. Test cross-namespace permissions and certificate access explicitly.

Compare behavior, not checkbox totals

A routing rule that looks equivalent can change path matching, forwarded headers or backend TLS. A successful health check proves little about authentication and request transformations. Use recorded synthetic requests against both controllers, then compare status, headers, routing and latency under your workload. Keep sensitive production payloads out of the fixture.

Adoption and exit cost

Record cloud load-balancer costs, policy resources, custom annotations, extension APIs and troubleshooting ownership. A portable API reduces some coupling; it does not erase implementation differences. Keep the old data plane available during a staged cutover and agree on error-rate and authentication-failure thresholds before moving traffic.

This comparison is a decision framework based on upstream documentation, not a benchmark. The historical comparison remains useful for understanding old links; its product generations and feature claims should be read in their original period. Continue with the migration planning guide.

Build a request-level comparison

Use a small test application that can report the received method, path and selected headers. Give each test a hostname, request, expected backend, expected response and security expectation. This makes a controller decision reviewable without pretending that one product's annotation has a direct equivalent in every other implementation.

  • Routing: check exact paths, prefixes, trailing slashes, overlapping hostnames, unknown hosts and an unavailable backend. Record which rule wins when several might match.
  • Identity: test authenticated, expired, missing and malformed credentials. Check whether an unauthorized request reaches the backend and whether an authentication outage fails as intended.
  • Transport: include long requests, WebSockets or gRPC where used, client disconnects, TLS termination and backend TLS. Match timeouts across the client, gateway and application.
  • Request transformation: verify rewrites, redirects, preserved query strings, forwarded scheme and client address. Confirm the application trusts only the intended proxy path.
  • Operations: test certificate replacement, gateway restart, rolling update and endpoint withdrawal. Confirm that a responder can identify a rejected route from status and logs.

Understand what the API standardizes

Gateway API separates infrastructure and application routing responsibilities. That separation is useful when a platform team controls shared gateways while application teams own routes. It still requires an agreed permission model. Decide which namespaces may attach to a listener and which cross-namespace references are allowed. An overly broad attachment policy can let an application claim traffic it should not receive.

Read the selected implementation's conformance and feature documentation for the release you intend to install. Distinguish a standard feature, an optional extended feature and a vendor-specific policy. Put every extension in the platform inventory so the next migration starts with a clear list of dependencies. An upstream example on a development branch is not a compatibility guarantee for an older installed release.

Make the shortlist small enough to test

For an existing Cilium installation with a supported configuration, evaluate whether its gateway capability meets the request matrix before adding another networking control plane. For a team that wants a dedicated gateway lifecycle, assess Envoy Gateway or another maintained implementation independently. For a cloud-managed option, check the provider's supported route features, provisioning delay, quotas and observability access alongside the recurring price.

Traefik's suitability depends on the particular APIs and middleware a workload needs. F5 NGINX Ingress Controller is a separate project with its own documentation and support model. Neither name similarity nor use of the NGINX proxy proves equivalence to community ingress-nginx. Use the controller image, repository and IngressClass from the actual installation to identify what is running.

Decide from evidence

Keep a short decision record: required behaviors, results for each candidate, unsupported cases, operating owner and rollback path. Prefer a target that passes the required cases with understandable operations. Do not reward optional features that the platform has no plan to run or support. Recheck the record when a major controller upgrade changes the behavior you rely on.

A shortlist by operating model

Choose columns
Visible columns
A shortlist by operating model
CandidateBest reason to evaluateVerify before choosing
Envoy GatewayIndependent Gateway API control plane with EnvoyExtension policies, Gateway CRD ownership and required route features
TraefikIngress and Gateway adoption within one controller familyExisting annotations, middleware behavior and supported release
Cilium GatewayNetworking team already operates a supported Cilium platformCNI/kernel constraints, feature support and upgrade blast radius
Managed cloud gatewayProvider-operated load balancing and integrationsRegion, protocol limits, ownership and recurring charges

4 rows

The original record

Historical Kubedex content

Original publication: 2018-09-11T17:14:12+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Reading Time: 4 minutes

Last Updated on August 2, 2021

As far as I know this is the complete list of Ingresses available for Kubernetes. Technically ambassador isn’t an ingress but it acts like one which is good enough. As you can probably see I’ve made quite a large table comparing features.

For those who struggle with reading the image there’s a link to open the google sheet directly below. Feel free to leave comments and I’ll update this blog post with corrections.

Historical illustration

View the full Google sheet here.

Based on the features, my own experience and anecdotal blog evidence I’ll attempt to provide my usual unbiased opinion on each.

1. ingress-nginx

This is probably the most commonly installed ingress. Safe, boring and reliable. Supports http, https and does ssl termination. You can also get TCP and UDP working but from looking at the Github issues I think I’d try to avoid it. You get quite a few nice load balancing options as well as powerful routing, websocket support, basic authentication and tracing.

It’s quite common to use this ingress in conjunction with cert-manager for generating SSL certs and external-dns for updating cloud based DNS entries.

The lack of dynamic discovery is a bit of a downer. There is a config generator that you can use to automate this but apparently it’s terrible.

Note: There’s the official Kubernetes ingress which is what we’re talking about here. There’s also the Ingress from Nginx corp which has different settings.

2. Kong

Most people will use Kong when they want an API gateway. Kong includes a plugin system that extends the features to beyond what a normal Ingress would do. I wouldn’t use this as a generic http load balancer but if you want API management features then Kong is definitely a good choice.

At previous companies I’ve always put an ingress in front of Kong and routed /api/ requests to it. However, more recently the developers of Kong have been making a lot of progress turning Kong into an Ingress.

3. Traefik

This one surprised me with just how many features it has. The resiliency features look awesome and from reading a broad selection of tech blogs it seems quite stable. Supporting dynamic configurations is a big upgrade if you’re currently using ingress-nginx.

One downside is it only supports http, https and grpc. If you need TCP load balancing then you’ll need to choose something else. TCP is now in the Alpha release.

Another consideration is minimizing server reloads because that impacts load balancing quality and existing connections etc. Traefik doesn’t support hitless reloads so you need NGINX or Envoy Proxy for this. For a lot of people this is a big deal.

4. HAProxy

This is the king of the ingresses when it comes to load balancing algorithms. It’s also the best choice for load balancing TCP connections. HAProxy has a track record of being extremely stable software. You can also get a paid support subscription if you want one.

5. Voyager

Another ingress based on HAProxy under the covers. Voyager is packaged up nicely and the docs look good. I couldn’t see where the load balancing algorithms were configured so assumed it’s just defaulting to round robin. If that’s wrong let me know in the comments and I’ll update.

6. Contour

Based on Envoy this has some more modern features like supporting Canary deploys. It also has a good set of load balancing algorithms and support for a variety of protocols. Unlike some of the others listed I got the impression from Github that this is under pretty rapid development still. There are discussions about adding more features which seems promising.

7. Ambassador

As mentioned above this one isn’t technically an ingress if you go by the strict Kubernetes definition. With Ambassador you simply annotate your services and it acts like an ingress by routing traffic. Ambassador has some very cool features that none of the other ingresses have like traffic shadowing which allows you to test services in a live production environment by mirroring request data.

Ambassador integrates nicely with both Opentracing and Istio.

8. Istio Ingress

If you’re already running Istio then this is probably a good default choice. It has some of the more modern features that Ambassador has. It also has fault injection which looks like it might be fun to play with. However, Istio is currently doing a lot of work in this area and is moving away from Ingress towards Gateways. So if you’re looking for something that’s not changing every 5 seconds you may want to still consider Ambassador.

Istio ingress also doesn’t support things like redirect from cleartext to TLS & authentication which are common features you want in your edge.

9. Gloo Solo

Gloo has some unique features like function based routing and service discovery across multiple IaaS, FaaS and PaaS providers. This is definitely the Ingress you should evaluate if you’re moving heavily in a serverless direction.

Summary

There’s no clear winner in this one because you’re going to need to pick the ingress based on your requirements. No single ingress currently does it all.

The safest choice is ingress-nginx. This is the one that most people use and it’s extremely reliable. The problem with ingresses is that when there’s a problem literally everyone complains. Ingress-nginx will cover 99% of use cases, so start here and then test others in a dev environment for a while before switching. Before you begin I’d recommend you read this blog to get ahead of some of the problems you may encounter.

Edit: As of 2021 I’ve switched over to Traefik and I notice quite a few other companies have done the same. It’s simple, works very well and I’ve had zero issues with it in production.

Historical workbook values; blanks mean unknown, not No. Prices, versions, maturity labels and feature claims are not current recommendations.

Kubernetes Ingress / Transposed (historical)

Historical snapshot

Recovered comparison data. Versions, prices and availability describe the original research, not a current benchmark. Blank or damaged source values are marked unknown.

Choose columns
Visible columns
Kubernetes Ingress / Transposed (historical)
Historical controllerbackend service discoveryProtocol: allProtocol: httpProtocol: httpsProtocol: tcpProtocol: tcp+tlsProtocol: udpProtocol: grpcbased onssl terminationwebsocketroutingscoperesiliencylb algorithmsauthColumn 18 (unnamed)Tracingcanary/shadowistio integrationstatePaid supportlinkdashboardsticky sessionslua
ingress-nginxdynamichttp,https,tcp (separate lb),udp,grpc,fastcgi,IPC socketYesYesYesUnknownYesYesnginxyesyeshost,path(with regex)cross-namespacerate limit, retriesrr,ewma,ip_hashbasic, digest, external authUnknownyescanary-kubernetes-https://kubernetes.github.io/ingress-nginx/Metrics can be seen in GrafanaYesYes
ambassadordynamichttp,https,grpc,tcp, tcp+ssl/tlsYesYesYesYesNoYesenvoyyesyeshost,header,pathcross-namespacecircuit break, rate limit, retrieswrr,ring hash,maglevyesUnknownyescanary,shadowyeskubernetesyeshttps://www.getambassador.io/Metrics can be seen in Grafana and PrometheusYesYes(envoy)
gloo (solo.io) dynamichttp, https, grpc, tcp, tcp+ssl/tls, graphql, swagger, lambdasYesYesYesYesNoYesenvoyyesyesheader, query param, http method, path, plugin, functioncross-namespacecircuit break, rate limit, retries, prometheus & grafana, role delegation, tracing, traffic shifting, shadowinground robin, least request, ring hash, maglev, randomtls, vault secrets, custom authentication, data loss prevention, WAF, API Key, JWT, LDAP, OAuth, OIDC, OPA, CustomUnknownyescanary & shadowyeskubernetes, nomadyeshttps://www.solo.io/products/gloo/Admin Dashboard + Prometheus and GrafanaYesYes (envoy)
traefikdynamichttp,https,grpc,tcp + tls (alpha)YesYesUnknownYesUnknownYestraefikyesyeshost,pathcross-namespacecircuit break, retriesrr, wrrbasic, digest and forward auth in alphaUnknownyescanary-kubernetesyeshttps://docs.traefik.io/configuration/backends/kubernetes/IncludedYes(traefik.ingress.kubernetes.io/affinity: "true")No
kongdynamichttp,https, grpcYesYesYesYesNoYesnginxyesyeshost, header, path, methodcross-namespaceactive and passive health check, circuit break, rate limit, retriesrr, hash, header, cookie Basic Auth, HMAC, JWT, Key, LDAP, OAuth 2.0, PASETO, plus paid Kong Enterprise options like OpenID ConnectUnknownyescanaryyeskubernetesyeshttps://github.com/Kong/kubernetes-ingress-controllerAdmin Dashboard + Grafana+Prometheus statsd Datadog SignalFxYesYes(nginx)
istio ingressdynamictcp,http,https,grpcYesYesUnknownYesUnknownYesenvoyyesyeshost,usercross-namespacecircuit break, retriesrr,leastconn,random,passthroughJWTUnknownyesUnknownyeskubernetes-https://istio.io/docs/tasks/traffic-management/ingress/Metrics can be seen in Grafana and Prometheus, tracing can be seen through jaeger or zipkin UIYesYes(envoy)
contourdynamichttp,https,tcp,grpcYesYesYesUnknownUnknownYesenvoyyesyeshost,pathcross namespaceretrieswrr,wlr,ring hash, maglev, random-Unknown-canary-kubernetes-https://github.com/heptio/contour-YesYes(envoy)
haproxydynamichttp,tcpYesUnknownYesUnknownUnknownUnknownhaproxyyesyeshost,pathoptional cross-namespace-rr, srr, leastconn,first,source,uri,url_param,hdr,rdp-cookiebasicUnknown---kubernetesyeshttps://www.haproxy.com/blog/haproxy_ingress_controller_for_kubernetes/Metrics can be seen in Grafana or DatadogYesYes
Citrix Ingress Controllerdynamichttp,https,tcp,ssl-tcp,udpYesYesYesYesYesUnknownCitrix ADCyesyeshost,pathcross-namespacehealth checkrr,least_conn,wrr,least_response,hashbasicUnknown-canary-kubernetesyeshttps://github.com/citrix/citrix-k8s-ingress-controllerMetrics can be shown in Grfana https://github.com/citrix/netscaler-metrics-exporterYesYes
Unknown product (damaged row identity)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)
Unknown product (damaged row identity)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)Unknown (ambiguous product association)
AWS ALB IngressUnknownhttp, httpsYesYesUnknownUnknownUnknownUnknownAWS ALByesyesUnknowncross-namespacerate-limit, health-checkUnknownUnknownUnknownUnknownUnknownUnknownUnknownUnknownhttps://github.com/kubernetes-sigs/aws-alb-ingress-controllerAWS CloudWatchUnknownUnknown
voyagerdynamichttp,https,tcpYesYesYesUnknownUnknownUnknownhaproxyyesyeshost,pathcross-namespace-rrbasic,oauthUnknown---kubernetesyeshttps://appscode.com/products/voyager/Built on top of HAProxy with similar dashboard optionsUnknownUnknown

13 rows

Kubernetes Ingress / Ingresses (historical)

Historical snapshot

Recovered comparison data. Versions, prices and availability describe the original research, not a current benchmark. Blank or damaged source values are marked unknown.

Choose columns
Visible columns
Kubernetes Ingress / Ingresses (historical)
Unknown (damaged historical cell)ingress-nginxistio ingresstraefik 2.0kongcontourhaproxycitrix ingress controllerF5 NetworksvoyagerAWS ALB IngressTyk
authbasic, digest, external authJWTbasic, digest and forward auth in alpha Basic Auth, HMAC, JWT, Key, LDAP, OAuth 2.0, PASETO, plus paid Kong Enterprise options like OpenID Connect-basicbasicWide range of auth options with APM modulebasic,oauthUnknownBasic, Token, OpenID, HMAC, OAuth 2.0, Custom, mTLS, JWT (lua, js, gRPC, go)
Tracingyesyesyesyes-----Unknownyes
istio integration-yes-yes-----Unknown-
linkerd2yes-yes--yes--UnknownUnknown-
canary/shadowcanaryUnknowncanary, mirroringcanarycanary-canaryBlue-Green Deployment, A/B Deployment-UnknownWith goreplay plugin https://github.com/buger/goreplay
scopecross-namespacecross-namespacecross-namespacecross-namespacecross namespaceoptional cross-namespacecross-namespacecross-namespacecross-namespacecross-namespacecross-namespace
backend service discoverydynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamic
based onnginxenvoytraefiknginx + openrestyenvoyhaproxyCitrix ADCF5 ADChaproxyAWS ALBGo - Tyk
routinghost,path(with regex)host,userhost,pathhost,path (with regex), method, headerhost,pathhost,pathhost,path- Full Ingress support - Openshift Routes - Any L3/L4/L7 info when using AS3 Extension integrationhost,pathUnknownhost, path, method, header RE2 Regexp
protocolhttp,https,tcp (separate lb),udp,grpc,fastcgi,IPC sockettcp,http,https,grpchttp,https,grpc,tcp + tlshttp,https, grpc, tcp, tcp+tlshttp,https,tcp,grpchttp,tcphttp,https,tcp,ssl-tcp,udptcp, http, httpshttp,https,tcp,grpchttp, httpshttp, https, gRPC, TCP, TLS-TCP
linkhttps://kubernetes.github.io/ingress-nginx/https://istio.io/docs/tasks/traffic-management/ingress/https://docs.traefik.io/providers/kubernetes-crd/https://github.com/Kong/kubernetes-ingress-controllerhttps://github.com/projectcontour/contourhttps://www.haproxy.com/blog/haproxy_ingress_controller_for_kubernetes/https://github.com/citrix/citrix-k8s-ingress-controllerhttps://github.com/istio/api/blob/master/networking/v1alpha3/gateway.protohttps://appscode.com/products/voyager/https://github.com/kubernetes-sigs/aws-alb-ingress-controllerhttps://github.com/TykTechnologies/tyk-helm-chart/#using-the-ingress-controller
statekuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskubernetesUnknownUnknown
dashboardMetrics can be seen in GrafanaMetrics can be seen in Grafana and Prometheus, tracing can be seen through jaeger or zipkin UIIncluded; https://docs.traefik.io/observability/metrics/prometheus/Grafana+Prometheus statsd Datadog SignalFxMetrics can be seen in Grafana and PrometheusMetrics can be seen in Grafana or DatadogMetrics can be shown in Grfana https://github.com/citrix/netscaler-metrics-exporterbuilt in dashboard + export with Telemetry Services which include https://clouddocs.f5.com/products/extensions/f5-telemetry-streaming/latest/Built on top of HAProxy with similar dashboard optionsAWS CloudWatchTyk Dashboard, Prometheus, StatsD, DataDog, Logz.io, Loggly, Splunk https://github.com/TykTechnologies/tyk-pump/tree/master/pumps
resiliencyrate limit, retriescircuit break, retrieshttps://docs.traefik.io/middlewares/overview/ ; CircuitBreaker, RateLimit, Retry, Buffering, many more.active and passive health check, circuit break, rate limit, retriesretries-health checkactive and passive health check, ramp-up, rate limit, retries-rate-limit, health-checkuptime tests, enforced timeouts, circuit breaker, throttling
lb algorithmsrr,ewma,ip_hashrr,leastconn,random,passthroughHTTP: rr, wrr, mirroring; TCP: RR, WRR;HTTPSrr, hash, header, cookiewrr,wlr,ring hash, maglev, randomrr, srr, leastconn,first,source,uri,url_param,hdr,rdp-cookierr,least_conn,wrr,least_response,hash“dynamic-ratio-member”, “dynamic-ratio-node”, “fastest-app-response”, “fastest-node”, “least-connections-member”, “least-connections-node”, “least-sessions”, “observed-member”, “observed-node”, “predictive-member”, “predictive-node”, “ratio-least-connections-member”, “ratio-least-connections-node”, “ratio-member”, “ratio-node”, “ratio-session”, “round-robin”, “weighted-least-connections-member”, “weighted-least-connections-node”rrUnknownrr
ssl terminationyesyesyesyesyesyesyesyesyesyesyes
websocketyesyesyesyesyesyesyesyesyesyesyes
Paid support--yesyesyesyesyesyesyesUnknownyes
sticky sessionsYesYesYes(traefik.ingress.kubernetes.io/affinity: "true")YesYesYesYes-UnknownUnknownUnknown
luaYesYes(envoy)willYes(nginx)Yes(envoy)YesYes-UnknownUnknownlua plugin support

20 rows

Kubernetes Ingress / Copy of Ingresses (historical)

Historical snapshot

Recovered comparison data. Versions, prices and availability describe the original research, not a current benchmark. Blank or damaged source values are marked unknown.

Choose columns
Visible columns
Kubernetes Ingress / Copy of Ingresses (historical)
Feature / source labelingress-nginxambassadortraefikkongistio ingresscontourhaproxycitrix ingress controllerGloo SoloF5 NetworksAWS ALB Ingressvoyager
backend service discoverydynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamicdynamic
protocolhttp,https,tcp (separate lb),udp,grpc,fastcgi,IPC sockethttp,https,grpc,tcp, tcp+ssl/tlshttp,https,grpc,tcp + tls (alpha)http,https, grpctcp,http,https,grpchttp,https,tcp,grpchttp,tcphttp,https,tcp,ssl-tcp,udptcp,http,https,grpctcp, http, httpshttp, httpshttp,https,tcp
based onnginxenvoytraefikkong (nginx)envoyenvoyhaproxyCitrix ADCenvoyF5 ADCAWS ALBhaproxy
ssl terminationyesyesyesyesyesyesyesyesyesyesyesyes
websocketyesyesyesyesyesyesyesyesyesyesyesyes
routinghost,path(with regex)host,header,pathhost,pathhost,path (with regex), method, headerhost,userhost,pathhost,pathhost,pathheader, query param, http method, path, plugin, function- Full Ingress support - Openshift Routes - Any L3/L4/L7 info when using AS3 Extension integrationUnknownhost,path
scopecross-namespacecross-namespacecross-namespacecross-namespacecross-namespacecross namespaceoptional cross-namespacecross-namespacecross-namespacecross-namespacecross-namespacecross-namespace
resiliencyrate limit, retriescircuit break, rate limit, retriescircuit break, retriesactive and passive health check, circuit break, rate limit, retriescircuit break, retriesretries-health checkrate limit, health checkactive and passive health check, ramp-up, rate limit, retriesrate-limit, health-check-
lb algorithmsrr,ewma,ip_hashwrr,ring hash,maglevrr, wrrrr, hash, header, cookierr,leastconn,random,passthroughwrr,wlr,ring hash, maglev, randomrr, srr, leastconn,first,source,uri,url_param,hdr,rdp-cookierr,least_conn,wrr,least_response,hashrr, least request, random“dynamic-ratio-member”, “dynamic-ratio-node”, “fastest-app-response”, “fastest-node”, “least-connections-member”, “least-connections-node”, “least-sessions”, “observed-member”, “observed-node”, “predictive-member”, “predictive-node”, “ratio-least-connections-member”, “ratio-least-connections-node”, “ratio-member”, “ratio-node”, “ratio-session”, “round-robin”, “weighted-least-connections-member”, “weighted-least-connections-node”Unknownrr
authbasic, digest, external authyesbasic, digest and forward auth in alpha Basic Auth, HMAC, JWT, Key, LDAP, OAuth 2.0, PASETO, plus paid Kong Enterprise options like OpenID ConnectJWT-basicbasicbasic, oidc, customWide range of auth options with APM moduleUnknownbasic,oauth
Tracingyesyesyesyesyes---yes-Unknown-
canary/shadowcanarycanary,shadowcanarycanaryUnknowncanary-canarycanaryBlue-Green Deployment, A/B DeploymentUnknown-
istio integration-yes--yes---yes-Unknown-
statekuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskuberneteskubernetesUnknownkubernetes
Paid support-yesyesyes--yesyesyesyesUnknownyes
linkhttps://kubernetes.github.io/ingress-nginx/https://www.getambassador.io/https://docs.traefik.io/configuration/backends/kubernetes/https://github.com/Kong/kubernetes-ingress-controllerhttps://istio.io/docs/tasks/traffic-management/ingress/https://github.com/heptio/contourUnknown (damaged historical cell)https://github.com/citrix/citrix-k8s-ingress-controllerhttps://gloo.solo.io/https://github.com/istio/api/blob/master/networking/v1alpha3/gateway.protohttps://github.com/kubernetes-sigs/aws-alb-ingress-controllerhttps://appscode.com/products/voyager/
dashboardMetrics can be seen in GrafanaMetrics can be seen in Grafana and PrometheusIncludedGrafana+Prometheus statsd Datadog SignalFxMetrics can be seen in Grafana and Prometheus, tracing can be seen through jaeger or zipkin UI-Metrics can be seen in Grafana or DatadogMetrics can be shown in Grfana https://github.com/citrix/netscaler-metrics-exporterMetrics can be seen in Grafana and Prometheusbuilt in dashboard + export with Telemetry Services which include: Splunk Microsoft Azure Log Analytics AWS Cloud Watch AWS S3 Graphite Kafka ElasticSearch Sumo Logic StatsD Generic HTTP See more in https://clouddocs.f5.com/products/extensions/f5-telemetry-streaming/latest/ Show lessAWS CloudWatchBuilt on top of HAProxy with similar dashboard options
sticky sessionsYesYesYes(traefik.ingress.kubernetes.io/affinity: "true")YesYesYesYesYesyes-UnknownUnknown
luaYesYes(envoy)NoYes(nginx)Yes(envoy)Yes(envoy)YesYesYes(envoy)-UnknownUnknown

19 rows

Sources & further reading

  1. Kubernetes retirement notice
  2. Gateway implementation and conformance directory
  3. F5 NGINX Ingress Controller
  4. Envoy Gateway installation
  5. Cilium Helm installation
  6. Traefik chart
  7. Recovered historical source (Common Crawl index)
  8. Kubernetes Ingress: historical workbook

Spotted something that needs another look?

Help improve this page →