Kanali placed an API-management gateway in front of Kubernetes services. It combined request routing with controls such as API-key authorization, quotas and rate limits, using Kubernetes resources and plugins to describe the behavior. It was useful when services needed a shared API entry point and policy layer. The project is deprecated, so a replacement must preserve those client-facing policies and custom behavior as well as the basic routes.
Current guidance
The northwesternmutual/kanali repository opens with a deprecation and no-longer-maintained notice. That is a project-level lifecycle statement, not merely the retirement of a Helm chart. Kanali combined Kubernetes ingress with API-key authorization, quotas, rate limits and a custom plugin framework.
For migration, export both routing configuration and the behavior implemented by plugins or gateway policies. A replacement that accepts an HTTPRoute or Ingress does not automatically reproduce API-key handling, request transformations, quotas or analytics. Identify the consumers and credentials affected by each policy before selecting a gateway implementation.
Replay representative permitted and rejected requests against a separate endpoint, including missing keys, exceeded limits, malformed headers and backend errors. Check how the new system stores secrets and distributes configuration, and decide how counters and client credentials will be migrated. Keep DNS or traffic switching reversible until behavior is understood. The historical performance claims have not been reproduced, and this page does not name an official Kanali successor; compare candidates by the required behaviors rather than by similar marketing descriptions.
Historical upstream link check · 2026-10-09
The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub marks northwesternmutual/kanali as archived. This confirms the repository's read-only archive state; any successor or supported distribution needs separate evidence. Link availability does not certify the historical installation instructions or current security support.
Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.
Historical Kubedex content
Preserved for context. Commands, versions, prices and results below reflect the original research.
Kanali is a lightweight, Kubernetes native API management gateway that together with network policies provide a robust, open source solution to Kubernetes ingress, API management, and API security.
Notable features:
- Kubernetes Native: Kanali extends the Kubernetes API by using Custom Resource Definitions, allowing Kanali to be configured and used in the same way as native Kubernetes resources.
- Performance Centric: As a middleware component, Kanali is developed with performance as the highest priority!
- Plugin Framework: Need to perform complex transformations or integrations with a legacy system? Kanali provides a framework allowing developers to create, integrate, and version control custom plugins.
- User-Defined Configurations: Kanali gives you control over declaratively configuring how your proxy behaves. Need mutual TLS, dynamic service discovery, mock responses, etc.? Kanali makes it easy!
- Robust API Management: Fine grained API key authorization, JWT validation, quota policies, rate limiting, etc., these are some of the built in API management capabilities that Kanali provides.
- Analytics & Monitoring: Kanali integrates with Prometheus and Grafana to provide a robust set of metrics and a customizable dashboard so that you can monitor the performance of your APIs in real time.
- Production Ready: Northwestern Mutual uses Kanali in production at scale for all of its API management needs in their cloud native stack.
- Cloud Native Deployment: Kanali is deployed using native Kubernetes constructs which is assisted by an included Helm chart.
- Open Tracing Integration: Kanali integrates with OpenTracing, a vendor-neutral open standard for distributed tracing. Jaeger, a distributed tracing system, is supported out of the box to provide a visual representation for your traces.
Sources & further reading
Spotted something that needs another look?
Help improve this page →