Contour turns Kubernetes routing configuration into rules for Envoy, the proxy that receives and forwards application traffic. It gives teams a way to publish several services through controlled entry points, with routes defined alongside their applications. It supports different resource models, including Ingress, HTTPProxy and Gateway API, so choose the one appropriate to the deployment. Contour manages the configuration; Envoy is the part that actually handles the requests.
Current guidance
Contour is an Envoy-based Kubernetes ingress controller. Its versioned documentation describes Ingress, the HTTPProxy custom resource and Gateway API. The recovered IngressRoute description belongs to the historical API. Gateway API deployments can use static provisioning or the Contour Gateway Provisioner; each Gateway corresponds to its own Contour and Envoy deployment.
The project supports one release track at a time and requires the most recent patch in that track for security and critical bug fixes. Use the compatibility matrix to match Contour, Envoy, Kubernetes and Gateway API versions. A combination listed for the development branch is not a released-version support claim.
Review the selected release’s route types, CRD ownership, authentication and TLS behavior before migrating traffic. Static provisioning leaves the operator responsible for keeping Gateway and proxy resources aligned; dynamic provisioning manages that relationship. Compare representative requests with the existing controller and test rollback. Documentation of Gateway API support does not establish every extension or current conformance profile, and this review did not run a deployment or benchmark.
Historical upstream link check · 2026-10-09
The recorded upstream address redirects to https://github.com/projectcontour/contour and returned HTTP 200 on 2026-10-09. GitHub does not mark projectcontour/contour archived or disabled; this does not establish active maintenance, support or compatibility. GitHub resolves the old repository identity to projectcontour/contour. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
Contour is an Ingress controller for Kubernetes that works by deploying the Envoy proxy as a reverse proxy and load balancer. Unlike other Ingress controllers, Contour supports dynamic configuration updates out of the box while maintaining a lightweight profile.
Contour also introduces a new ingress API (IngressRoute) which is implemented via a Custom Resource Definition (CRD). Its goal is to expand upon the functionality of the Ingress API to allow for a richer user experience as well as solve shortcomings in the original design.
Check out the roadmap to see where we plan to go with the project.
Also see the launch blog post for our vision of how Contour fits into the larger Kubernetes ecosystem.
Sources & further reading
Spotted something that needs another look?
Help improve this page →