Networking
Part 6 of 6 · Private NetworkingIngress Controllers & North-South — K8s Ingress/Gateway API, L7 vs L4, TLS
North-south is traffic entering or leaving a cluster. Ingress and Gateway API configure that entry and need an implementation. L4 forwards connections. L7 routes on host and path. TLS termination is a trust boundary. A service mesh is a different problem.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Who operates the HTTP edge
Prefer
ALB when AWS integration is the point
Managed scaling, ACM certificates, and WAF. The AWS Load Balancer Controller programs the ALB from Ingress or Gateway API. You still run the controller and its IAM.
- Host and path routing without an in-cluster proxy fleet.
- Cost is load-balancer capacity, rules, and processed traffic.
- Tied to AWS behavior and controller version.
Alternative
nginx or Envoy ingress when you want a portable proxy
You size replicas, upgrades, drain, and observability. Envoy at the edge is not a service mesh. Annotations often fail to move between controllers.
- Gateway API or Envoy Gateway can be the API.
- NLB in front is a common L4 plus static-IP pattern.
- You own capacity. A missed upgrade hits every route.
Overview
North-south networking is traffic entering or leaving a cluster, typically from a user, partner, or external system. It is different from service-mesh networking, which is primarily east-west between workloads. Ingress and Gateway API configure an external entry point. A mesh is not a prerequisite. Do not recap that cluster here.
Start from requirements: HTTP or arbitrary TCP/UDP, host or path routing, where TLS terminates, static IPs, WAF, cloud integration, and who operates the controller. Then name the path. East-west proxy internals stay on the mesh hub.
L4 distributes connections using addresses and ports. L7 understands HTTP and can use host, path, and headers. TLS behavior comes from the listener, not from the Kubernetes object name.
Layer cheat sheet
- ClusterIP. Internal virtual IP. It does not publish the app.
- NodePort. A port on nodes. Usually an implementation detail behind a cloud load balancer, not the public endpoint you want.
- LoadBalancer Service. Asks the cloud integration for an external load balancer. The Service type alone does not promise L4 or L7 features.
- Ingress. HTTP(S) host and path rules. The object does nothing until a controller watches it.
- Gateway API. Role split. Platform teams manage GatewayClass and Gateway. App teams attach HTTPRoute.
- ALB Ingress. The AWS Load Balancer Controller can translate supported Ingress or Gateway config into an ALB, including ACM and WAF, depending on version.
- nginx or Envoy ingress. In-cluster proxies. Portable and feature-rich. You operate deployment, capacity, upgrades, and metrics. "Ingress" might mean the API or, loosely, the controller. Say which.
- NLB. L4 TCP/UDP and connection distribution, often with static IPs. A TCP listener passes encrypted bytes through. An NLB TLS listener terminates at the NLB.
- ALB. L7 HTTP(S), host and path, WAF, OIDC integration. AWS-specific cost model.
Envoy Gateway or Contour are edge-proxy examples. Mentioning Envoy does not mean the cluster runs a mesh.
Decision rule: ALB when AWS-managed L7 features matter most. nginx or Envoy when portability or a cluster-managed edge matters more. Validate protocol, TLS, health checks, scale limits, and ownership.
TLS and path routing
DNS points clients at the external endpoint. The L7 layer selects a Service from host and path. An AWS controller may program an ALB directly. An in-cluster controller may run Envoy or nginx behind a Service. The diagram is the logical order, not a promise of an extra hop.
Flow
- 1
1 Client TLS
- next2 DNS
- 2
2 DNS
- next3 ALB NLB or Ingress
- 3
3 ALB NLB or Ingress
- next4 Controller or Gateway
- 4
4 Controller or Gateway
- next5 Path api Service A
- 5
5 Path api Service A
- next6 Path web Service B
- 6
6 Path web Service B
Lesson map
Ingress Controllers & North-South — K8s Ingress/Gateway API, L7 vs L4, TLS
North-south is traffic entering or leaving a cluster. Ingress and Gateway API configure that entry and need an implementation. L4 forwards connections. L7 routes on host and path. TLS termination is a trust boundary. A service mesh is a different problem.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB client["Client"] alb["ALB"] grpc["gRPC backend"] client -->|HTTP/1.1| alb alb -->|Broken streaming| grpc
Where TLS ends:
- Terminate at ALB or Gateway. The edge presents the certificate and can route on HTTP. The next hop may be plaintext or TLS. Protect it if policy says the bytes stay encrypted.
- Passthrough at NLB. TCP so the backend owns TLS. The L4 device cannot read the HTTP path. Route by connection properties, or by SNI if the proxy you chose supports it.
- Re-encrypt. Terminate at the edge, then a second TLS session to the workload. Extra certificates, trust, and health checks. Say whether backend identity is validated.
- End-to-end TLS. The application owns the client-facing session. An L7 proxy that terminates TLS breaks that single session even if it opens another encrypted hop.
DNS-01 proves domain control for certificate issuance. It is not a routing mechanism.
Gateway API versus Ingress
Ingress is a compact HTTP(S) API. Real features often hide in controller annotations, which mix app intent with infrastructure and do not move cleanly.
Gateway API splits ownership. Platform defines GatewayClass and Gateway (listener and address). Applications attach HTTPRoute. Support depends on the implementation and its conformance level.
Both are north-south routing APIs. Gateway API does not replace a mesh. Mesh scope is workload-to-workload policy. For the interview, say who owns the shared entry and who may attach routes. East-west depth stays on the mesh hub.
Wrong protocol
gRPC commonly uses HTTP/2. A listener, target group, or backend protocol mismatch can fail even when a TCP health check passes. Symptoms include negotiation failures, resets, and broken streams. ALB can support gRPC in supported configurations. NLB can pass TCP through and does not do HTTP path routing.
Sequence
- 1
Client
HTTP/2 required
- 2
Client → ALB
HTTP/1.1 misconfig
- 3
ALB → gRPC backend
Broken streaming
- 4
Client
Fix ALB HTTP/2 or NLB TCP
The last note is a decision, not a universal fix. Confirm client and backend expectations.
Sandbox: NLB vs ALB vs in-cluster (Python)
Illustrative preference order, not a law. A static IP does not ban every L7 design. TLS passthrough is about where decryption happens. Real designs combine products, for example an NLB in front of an in-cluster gateway.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Sandbox: first-match host and path (TypeScript)
Rule order matters in this first-match function. A longer prefix should win if you sort by specificity. /v10 must not match /v1 when you meant a path segment. Kubernetes and Gateway API define real precedence. This function does not reproduce them.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Pitfalls
Draw an API and a web frontend. Mark client to edge, edge to proxy, proxy to pod. Change one requirement — static IP, WAF, gRPC, or multi-cloud — and say what you would swap and who operates it.
Interview Q&A
When would you choose NLB over ALB?
Answer
NLB for arbitrary TCP or UDP, connection-level balancing, static IPs, or TCP passthrough so the backend handles TLS. ALB when host and path routing, WAF, or HTTP authentication matter. An NLB does not provide HTTP path routing. Product context: Cloud Equivalents.
Is an Ingress a Service?
Answer
No. Ingress is an API for HTTP(S) routing intent. A controller implements it, often by configuring a proxy or cloud load balancer. Routes usually target Services.
Where should TLS terminate?
Answer
Usually at a managed edge when you want centralized certificates and L7 routing. Passthrough when the backend must own TLS or the edge must not decrypt. Compliance may require terminate plus re-encrypt. Name both trust boundaries and how certificates rotate.
Does Gateway API replace a service mesh?
Answer
No. Gateway API is a Kubernetes API for traffic entry and routing, with a split between platform and application owners. A mesh focuses on east-west communication and policy. Scopes differ. See Sidecar & Service Mesh for that topic only.
How would you troubleshoot a route that returns 404?
Answer
DNS and the external listener, then whether the controller accepted the route. Host header, path match, route attachment, Service name and port, endpoint readiness. Controller events, then the programmed cloud or proxy rules. A connection to the load balancer does not prove the route matched.
What would you mention about high availability?
Answer
Controller replicas across failure domains, disruption budgets, resource requests, and a load balancer that targets healthy endpoints. For a managed ALB, separate cloud-service availability from the controller that configures it. Include health checks, rollout, and peak capacity.
What does a LoadBalancer Service guarantee?
Answer
That the platform will try to provision an external load balancer. Not ALB features, not WAF, not HTTP/2. Read the implementation.
Why is a public NodePort a problem?
Answer
It can bypass the intended load balancer, WAF, and security-group story. Keep node ports as an implementation detail and restrict node access.
Why do gRPC calls fail a TCP health check that is green?
Answer
The check proved a port, not HTTP/2. Fix the ALB protocol or use NLB passthrough, and confirm the backend speaks the same version.
Who owns a Gateway versus an HTTPRoute?
Answer
Platform or infrastructure typically owns GatewayClass and Gateway. Application teams attach HTTPRoute. That split is the point of the API. Conformance still depends on the installed controller.
Is an Envoy ingress a mesh?
Answer
No. An edge Envoy routes north-south. A mesh is a fleet of workload proxies and a control plane for east-west policy. Do not import that design into this answer.
What is a bad double-TLS setup?
Answer
The edge terminates, the backend expects plaintext or a different trust root, and the health check uses the wrong protocol. Clients see timeouts that look like application bugs.