Q: Explain Ingress Controller. What is the difference between Ingress resource, Ingress Controller, and Service?
Demystifying the Kubernetes Ingress architecture: distinguishing the Ingress Resource (manifest), Ingress Controller (reverse proxy daemon), and ClusterIP Services, tracing packet flow from client to container.
#Kubernetes #Ingress #Ingress Controller #NGINX #ALB #AGIC #Cert-Manager
🎙️ Candidate Opening & Architectural Context
"Candidates often confuse the declarative Ingress YAML with the actual reverse proxy software. Ingress requires two components: the declarative API rule and an active controller running in the cluster."
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
The Three Discrete Layers (Resource vs Controller vs Service)
Understanding the separation of concerns:
📄 Ingress Resource
A Kubernetes API object (YAML) that defines routing rules: hostnames, URL path prefixes (/api, /auth), and TLS certificate secrets.
⚙️ Ingress Controller
The actual running proxy application (Ingress-NGINX, Traefik, AWS Load Balancer Controller, or Azure AGIC) that reads Ingress resources and dynamically reconfigures its routing table.
🔌 Kubernetes Service
An internal ClusterIP abstraction that provides a stable virtual IP and tracks healthy Pod IPs via Endpoints/EndpointSlices.
2️⃣
End-to-End Traffic Flow (Internet to Application)
How an HTTP request traverses the layers:
Client DNS Request→Cloud Load Balancer (ALB/AGIC)→Ingress Controller Pods→Bypass kube-proxy (Endpoints)→Target Pod IP
- 1. User accesses
https://api.example.com/checkout. - 2. DNS resolves to the Cloud Load Balancer (AWS ALB, Azure App Gateway, or NLB).
- 3. Load balancer forwards traffic to the Ingress Controller Pods running in the cluster.
- 4. The Ingress Controller evaluates its in-memory routing table: matches host
api.example.comand path/checkout. - 5. The Performance Secret: Modern ingress controllers (like NGINX) bypass the
kube-proxyClusterIP NAT hop and route directly to the backend Pod IP discovered via the Kubernetes Endpoints API.
3️⃣
Production Add-Ons: TLS & Security
Essential components paired with Ingress Controllers in enterprise setups:
- Cert-Manager: Automates Let's Encrypt / enterprise PKI SSL certificate issuance and renewal into Kubernetes TLS secrets.
- IngressClass: Decouples cluster from specific controllers, allowing multiple ingress controllers (e.g. internal vs public) in one cluster.
- WAF & Rate Limiting: Ingress controllers inject annotations for rate-limiting (
limit-rps), IP whitelisting, and WAF protection.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"An Ingress Resource is just a passive config manifest. Without an active Ingress Controller pod listening to the Kubernetes API, your ingress rules do nothing. High-performance controllers route directly to Pod IPs via EndpointSlices rather than bouncing through kube-proxy."
⚡ 60-Second Elevator Pitch Talking Points
- Ingress Resource is the YAML routing specification (hosts, paths, TLS secrets).
- Ingress Controller is the active reverse proxy daemon (NGINX, Traefik, Envoy, AWS ALB Controller) executing the rules.
- Service is the backend abstraction; the Ingress Controller watches Service Endpoints to stream traffic directly to container IPs.
- Client -> Cloud LB -> Ingress Controller Pod -> Evaluates Host/Path Rules -> Direct connection to target Pod IP.
Advertisement