⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 42 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering Service Mesh & Networking Networking
🎯 Target Role / Context: Senior Platform Engineer designing cluster ingress, traffic routing, and perimeter security architectures.

Q: Why is Kubernetes Gateway API replacing the standard Ingress resource in modern platform engineering, and how do you design GatewayClass, Gateway, and HTTPRoute hierarchies to enable self-service routing while maintaining perimeter security?

Architectural transition from legacy Ingress resources to Kubernetes Gateway API, separating infrastructure provisioning from application routing across platform teams.

#Gateway API #Kubernetes #Envoy Gateway #Cilium #Ingress #Platform Engineering
🎙️ Candidate Opening & Architectural Context
"The legacy Kubernetes Ingress API suffered from rigid specifications, vendor-specific annotation sprawl, and lack of RBAC role separation. Gateway API introduces role-oriented resources that cleanly decouple cluster infrastructure management (Platform Admins) from route definitions (App Developers)."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Define Role-Oriented API Boundaries

Establish clear boundaries: Infrastructure providers define GatewayClass (e.g., Envoy Gateway, Cilium); Platform Engineers provision the Gateway resource managing public/private load balancers, TLS certificates (via cert-manager), and allowed namespace listeners; Application Developers own HTTPRoute resources specifying path matching, canaries, and rewrites.

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: internal-gateway
  namespace: platform-ingress
spec:
  gatewayClassName: cilium
  listeners:
  - name: https
    protocol: HTTPS
    port: 443
    tls:
      certificateRefs:
      - name: wildcard-tls-cert
    allowedRoutes:
      namespaces:
        from: Selector
        selector:
          matchLabels:
            ingress-enabled: 'true'
2

Cross-Namespace Route Attachment and Guardrails

Configure AllowedRoutes on the Gateway's listeners using namespace label selectors (namespaces.from: Selector). This ensures developer teams in specific namespaces can bind their HTTPRoutes to the shared perimeter Gateway without granting them access to alter edge TLS certificates or listener ports.

apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: order-routing
  namespace: team-orders
spec:
  parentRefs:
  - name: internal-gateway
    namespace: platform-ingress
  rules:
  - matches:
    - path:
        type: PathPrefix
        value: /orders
    backendRefs:
    - name: order-service
      port: 8080
Advertisement
3

Self-Service Advanced Traffic Management

Enable developers to independently configure progressive canary rollouts, header-based routing, URL rewrites, and request mirroring directly through native HTTPRoute spec without needing ingress controller custom CRDs or annotations.

backendRefs:
- name: order-service-v1
  port: 8080
  weight: 90
- name: order-service-v2
  port: 8080
  weight: 10
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Kubernetes Gateway API replaces annotation-heavy Ingress with role-oriented resources (GatewayClass, Gateway, HTTPRoute), decoupling central TLS and load-balancer provisioning from developer application routing."
⚡ 60-Second Elevator Pitch Talking Points
  • Traditional Ingress forced developers and platform engineers to fight over fragile vendor annotations.
  • Gateway API establishes clean role boundaries: platform teams manage Gateway listeners and edge TLS certs, while developers manage self-service HTTPRoutes.
  • This provides native canary weights, header routing, and zero risk of tenant misconfigurations breaking central cluster ingress.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →