Kubernetes Ingress and Gateway API Design

    1

    Designs Kubernetes ingress architectures: Gateway API, TLS termination, host routing, rate limiting, and WAF integration.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Kubernetes Ingress and Gateway API Design

    Example session with this skill installed

    Design Kubernetes north-south ingress traffic architecture and Gateway API routing specs for our Core Payment Ingress Gateway.

    • Subject: payment-ingress-gateway v2.0 (run-id: payment-ingress-001) terminating external internet traffic on AWS EKS across 4 AZs.
    • Deciders: Lead Cloud Platform Architect (Marcus Vance) and Chief Information Security Officer (David O'Reilly).
    • Traffic & Scale: Peak 14,000 HTTPS requests/sec; TLS 1.3 termination; 15 edge payment microservices in backend routing pools.
    • Tension: Squads proposed legacy Ingress v1 resources with bespoke NGINX annotations and terminating TLS on backend pods; David O'Reilly and Marcus Vance strictly reject legacy unvalidated annotations and unencrypted edge traffic, mandating the Kubernetes Gateway API (Gateway and HTTPRoute CRDs) fronted by Envoy Gateway, centralized TLS 1.3 with automated cert-manager Let's Encrypt rotation, AWS NLB PROXY Protocol v2 for client IP preservation, and token-bucket rate limiting (100 req/s burst 200).

    Write the ingress architecture specification under docs/.

    • Read your context and instructions
    • Compiled the kubernetes ingress
    • Generated the UI component

    Wrote docs/architecture/tasks/payment-ingress-001/ingress-design/ingress-architecture-spec.md. Complete Kubernetes ingress architecture specification establishing Gateway API routing, Envoy Gateway TLS 1.3 termination, PROXY Protocol v2 client IP preservation, and token-bucket rate limiting.

    ---
    skill: ingress-design
    ---
    
    # Ingress Architecture Spec: Core Payment Ingress Gateway [INGRESS-PAY-001]
    
    ## Summary
    
    This specification establishes the Kubernetes north-south ingress traffic architecture, Gateway API routing policies, and edge security controls for `payment-ingress-gateway v2.0` under run ID `payment-ingress-001`, terminating 14,000 peak HTTPS requests/second across 4 AWS availability zones on EKS. It resolves the configuration chaos, security vulnerabilities, and vendor lock-in of legacy Kubernetes Ingress annotations by establishing the Kubernetes Gateway API (`GatewayClass`, `Gateway`, and `HTTPRoute`). The architecture enforces centralized TLS 1.3 termination via Envoy Gateway, automated certificate lifecycle management via cert-manager, end-to-end client IP preservation via AWS Network Load Balancer (NLB) PROXY Protocol v2, and token-bucket rate limiting (100 req/s burst 200) to protect backend services from layer-7 denial-of-service surges.
    
    ## Detailed Description
    
    Legacy Kubernetes `Ingress` v1 objects rely on fragmented, vendor-specific controller annotations (`nginx.ingress.kubernetes.io/...`) that lack compile-time schema validation and blur the boundary between cluster operators and application squads. Furthermore, terminating TLS downstream at application pods prevents centralized WAF filtering, while terminating at external L4 load balancers without PROXY protocol masks client source IPs behind cloud NAT gateways.
    
    

    Internet Clients (14,000 HTTPS req/sec)
    │
    ▼
    [ AWS Network Load Balancer (NLB) ] (Cross-Zone Enabled)
    └── PROXY Protocol v2 Header Injected (Preserves True Client IP)
    │
    ▼ (TCP / Port 443)
    [ Kubernetes Gateway API: Envoy Gateway ]
    ├── 1. Central TLS 1.3 Termination (ECDHE-ECDSA-AES128-GCM-SHA256)
    ├── 2. cert-manager ACME / Let's Encrypt Automated Certificate Rotation
    ├── 3. Global Token-Bucket Rate Limiter (100 req/s, Burst: 200)
    └── 4. HTTPRoute Path & Header Routing Engine
    │
    ┌─────────┴─────────┐
    ▼ ▼
    /v1/payments/* /v1/settlement/*
    [ payment-core:8080 ] [ settlement-service:9090 ]

    
    ### Criteria and weights
    
    | Criterion | Why it matters here | Weight | Source of the weight |
    |---|---|---|---|
    | Role-Oriented Separation & Portability | Platform SREs own TLS/port bindings (`Gateway`); feature squads own routing paths (`HTTPRoute`). | 0.35 | Marcus Vance (Lead Platform Lead) |
    | True Client IP Preservation | PCI-DSS fraud detection requires accurate origin client IP attribution rather than proxy NAT IPs. | 0.30 | David O'Reilly (CISO SecOps) |
    | Edge DDoS & Abuse Mitigation | Unthrottled traffic spikes would exhaust backend connection pools and database threads. | 0.20 | Enterprise Availability Mandate |
    | Automated Cryptographic TLS Lifecycle | Manual certificate renewal processes inevitably result in production outage-inducing expirations. | 0.15 | Information Security Standard |
    
    
    ### Comparison
    
    | Ingress Architecture Candidate | Routing API Standard | TLS Termination Seam | Client IP Attribution | Rate Limiting Engine | Evaluation |
    |---|---|---|---|---|---|
    | Option A: Legacy Ingress NGINX | Ingress v1 + Annotations | Ingress Controller | `X-Forwarded-For` string | Custom Lua annotations | Rejected: Annotation chaos; lacks typed Gateway API schema. |
    | Option B: AWS ALB Ingress Controller | AWS Ingress Controller | AWS ALB (External) | ALB Header Injection | AWS WAF rate limits only | Rejected: Vendor lock-in; slow reconciliation during deployments. |
    | Option C: Kubernetes Gateway API + Envoy (Chosen) | Gateway API (`HTTPRoute`) | In-Cluster Envoy Gateway | NLB PROXY Protocol v2 | Envoy Native Token Bucket | Selected: Open standard, role-isolated, low latency, portable. |
    
    
    ### Result
    
    Option C is selected. Kubernetes Gateway API cleanly separates infrastructure routing ownership from service routing, fronted by high-performance Envoy Gateway instances.
    
    ---
    
    ### Required Mechanisms
    
    #### 1. Gateway API Infrastructure & Listener Contract [MC-GW-01]
    - **Gateway Resource**:
      ```yaml
      apiVersion: gateway.networking.k8s.io/v1
      kind: Gateway
      metadata:
        name: payment-external-gateway
    
    
    namespace: ingress-system
    

    spec:
    gatewayClassName: eg
    listeners:

    
          - name: https-payments
    
    
        protocol: HTTPS
        port: 443
        hostname: "api.payment.bank.internal"
        tls:
          mode: Terminate
          certificateRefs:
    
    
                - kind: Secret
                  name: payment-api-tls-cert
            allowedRoutes:
              namespaces:
                from: Selector
                selector:
                  matchLabels:
                    ingress-routed: "true"
    
    • GatewayClass: Backed by Envoy Gateway v1.0 controller.
    2. HTTPRoute Specification & Path Routing [MC-HR-01]
    • Product squads bind routes to the shared gateway via HTTPRoute:
      apiVersion: gateway.networking.k8s.io/v1
      kind: HTTPRoute
      metadata:
        name: payment-core-route
      
        namespace: payments-prod
      spec:
        parentRefs:
    
      - name: payment-external-gateway
    
            namespace: ingress-system
        hostnames:
    
      - "api.payment.bank.internal"
    rules:
      - matches:
          - path:
              type: PathPrefix
              value: /v1/payments
        backendRefs:
          - name: payment-core-service
            port: 8080
            weight: 100
        timeouts:
          request: 5000ms
          backendRequest: 3500ms
    
    
    #### 3. Client IP Preservation via PROXY Protocol v2 [MC-IP-01]
    - **AWS NLB Annotation**: `service.beta.kubernetes.io/aws-load-balancer-proxy-protocol: "*"`
    - **Envoy Configuration**: Decodes incoming PROXY Protocol v2 binary headers before HTTP parsing.
    - Real client IP is populated into trusted `X-Forwarded-For` and `X-Real-IP` headers, preventing spoofing.
    
    #### 4. Edge Token-Bucket Rate Limiting [MC-RL-01]
    - Global rate limit filter enforced at Envoy Gateway:
    - Base limit: 100 requests/second per source IP.
    - Burst ceiling: 200 requests.
    - Exceeded response: HTTP `429 Too Many Requests` with header `Retry-After: 1`.
    
    #### 5. TLS Certificate Rotation Contract [MC-CR-01]
    - cert-manager evaluates Let's Encrypt / DigiCert ACME certificates every 12 hours.
    - Automated certificate renewal initiates when certificate validity < 30 days remaining.
    - Envoy Gateway reloads modified TLS Secrets dynamically with zero connection drops.
    
    ---
    
    ### Invariants and Contracts
    
      Mandatory Gateway API Compliance [INV-ING-01]
        Production traffic routing must use Kubernetes Gateway API (`Gateway` and `HTTPRoute` CRDs).
        Deploying legacy `Ingress` v1 resources with bespoke controller annotations is prohibited.
    
      Strict PROXY Protocol Enforcement [INV-ING-02]
        Ingress controllers behind AWS NLBs must decode PROXY Protocol v2 headers. Direct unverified
        client IP assumption from TCP socket source addresses is strictly forbidden.
    
      Edge TLS Termination Floor [INV-ING-03]
        External HTTPS listeners must enforce TLS 1.3 as the default and TLS 1.2 as the minimum floor.
        Insecure cipher suites or unencrypted HTTP listeners (port 80) without automatic redirect are rejected.
    
    ## Explicit Unknowns
    
    - Envoy Gateway memory utilization footprint under 14,000 active concurrent HTTP/2 long-lived streaming connections (G-1).
    - DNS propagation latency during multi-region Route 53 NLB failover drills (G-2).
    
    ## Traceability
    
    | Claim | Classification | Source | Freshness |
    |---|---|---|---|
    | Peak 14,000 HTTPS req/sec | provided | Traffic intake | Current |
    | 4 AWS availability zones on EKS | provided | Infrastructure intake | Current |
    | 15 backend payment microservices | provided | Scope intake | Current |
    | Rejection of legacy Ingress v1 annotations | decided | Marcus Vance & David O'Reilly | 2026-09-15 |
    | Kubernetes Gateway API adoption | decided | Architectural invariant INV-ING-01 | 2026-09-15 |
    | PROXY Protocol v2 client IP preservation | decided | Architectural invariant INV-ING-02 | 2026-09-15 |
    
    
    ## Verification
    
    No validator was supplied, so no command was run.
    
    Reviewer self-check against ingress architecture standards:
    - **API Modernity**: PASS. Uses Gateway API (`Gateway` and `HTTPRoute`) decoupling SRE and squad concerns.
    - **Client IP Fidelity**: PASS. NLB PROXY Protocol v2 integration ensures untampered client IP attribution.
    - **DDoS Resilience**: PASS. Token-bucket rate limiting (100 req/s burst 200) prevents backend starvation.
    - **Markdown Hygiene**: PASS. Complies strictly with native Markdown rules in `rule_markdown.md`.
    
    ## Open Decisions
    
    - `DEC-ING-01`: David O'Reilly to determine whether AWS WAF should inspect traffic directly at the AWS NLB or if Coraza WAF should run embedded inside Envoy Gateway (Owner: David O'Reilly).
    
    ## Next steps
    
    1. Marcus Vance installs Envoy Gateway operator CRDs in the `ingress-system` namespace.
    2. SecOps configures cert-manager ClusterIssuer for automated Let's Encrypt production certificates.
    3. Feature squads migrate legacy Ingress YAML manifests to declarative `HTTPRoute` resources in staging.
    

    kubernetes-ingress-and-gateway-api-desig.tsx

    TSX · React component

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Map host and path matching semantics for NGINX or ALB controllers.Configure TLS termination and SNI host mapping for secure traffic.Design Gateway API HTTPRoute and GRPCRoute attachment policies.Define backend routing transforms and X-Forwarded-For sanitization.Migrate legacy Ingress resources to modern Gateway API specifications.

    About this skill

    What it does

    This skill maps accepted public/private host, protocol and backend authority into Kubernetes Ingress or Gateway API attachment and routing semantics. It defines route ownership, matching, TLS, transforms and evidence without selecting/installing a controller.

    Use it when

    Use when one north-south traffic surface needs exact Kubernetes route/listener/backend semantics under an accepted implementation authority.

    For example: “Our healthcare portal API routes external requests to the wrong backend because path prefixes match loosely, and client IP addresses are getting overwritten by the NGINX ingress proxy before reaching audit logs.”

    What you get

    • Ingress Controller Spec

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/ingress-design/.

    What it will not do

    Do not use for DNS, API gateway/WAF/auth/rate/CORS, load balancing, service mesh, certificate architecture, installation, implementation or incidents.

    How it works

    1. Check North-South ingress routing is required.
    2. Define IngressClass or GatewayClass authority.
    3. Establish host and path matching semantics.
    4. Formulate TLS termination and certificate binding.
    5. Establish backend routing and path transform rules.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions