Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To expose a Kubernetes Service over HTTP or HTTPS with Ingress, create an Ingress resource that sends requests for a host and path to the Service, then make sure an Ingress controller is installed to implement those rules. The resource alone does not publish an endpoint. Ingress remains supported, but its API is frozen; Kubernetes recommends Gateway API for new development.

What Ingress does—and what it does not do

An Ingress defines rules for routing external HTTP or HTTPS requests to Kubernetes Services, commonly by hostname and URL path. The backend Service provides a stable destination for the application’s Pods; it can remain cluster-internal while the Ingress controller handles the external entry point.

An Ingress object is configuration, not a running proxy or load balancer. A controller must watch the resource and implement its rules, often by configuring a load balancer or another edge frontend. Kubernetes does not provide a controller simply because the cluster accepts an Ingress object. Ingress is for HTTP and HTTPS routing, not arbitrary network protocols.

The Kubernetes Ingress documentation describes the API as generally available and says the project has no plans to remove it. It also states that the API is no longer being developed and will receive no further changes or updates. Use Ingress when it fits an existing cluster or requirement; for new networking work, evaluate Gateway API and confirm that your cluster implementation supports the features you need.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Tecmojo 12U Open Frame Network Rack for IT & AV Gear, AV Rack Floor Standing or Wall Mounted,with 2 PCS 1U Rack Shelves & Mounting Hardware,Network Rack for 19" Networking,Audio and Video Device
  • 【Powerful Load-bearing】12U Network Rack Open Frame is constructed from durable cold rolled steel; Rack shelf supports enhance stability, wall-mounted capacity of 130lbs, the ground-mounted up to 260lbs
  • 【Considerate Designs】Open-frame layout, including a top panel adding space, anti-slip shelf stops fixing devices and compatible racks for stack and expansion to meet requirements of home server rack
  • 【Complete Accessories】A 12U open frame server rack, two ventilated shelves, four shelf stops, four velcro straps and a set of equipment mounting screws
  • 【Versatile Application】Ideal for space-efficient multi-device setups in warehouses, retail, classrooms, offices and more; Excellent choices as AV Rack/IT Rack
  • 【Effortless Setup】 Network Rack includes hardware, a comprehensive manual, mounting hole drilling template and an online assembly video to simplify setup

Check the cluster and backend before creating the Ingress

Confirm an Ingress controller is available

Find out which controller your cluster supports and whether it is already installed. The controller determines how the Ingress rules are implemented, which class to select, how an external address is provided, and which TLS features are available. Installation steps and class names are controller- and environment-specific, so use the current documentation for the implementation you have chosen.

Check the Service and its port

The Ingress backend refers to a Service by name and one of that Service’s ports. Before applying the Ingress, confirm that the Service exists in the same namespace, that the port is correct, and that the Service leads to healthy application endpoints. A valid Ingress rule cannot make a missing Service or unhealthy backend work.

Rank #2
Tecmojo 16U Open Frame Network Rack for IT & AV Gear, AV Rack Floor Standing or Wall Mounted,with 2 PCS 1U Rack Shelves & Mounting Hardware,Network Rack for 19" Networking,Audio and Video Device
  • 【Powerful load-bearing】 Constructed from durable Cold Rolled Steel, Rack Shelf Back Support enhances stability, wall-mounted capacity of 130lbs, the ground-mounted up to 260lbs
  • 【Considerate Designs】Open-frame layout, including a top panel adding space, Anti-Slip Shelf Stops fixing devices and compatible racks for stack and expansion to meet requirements of home server rack
  • 【Complete Accessories】A 16U open frame server rack, two ventilated shelves, four shelf stops, four velcro straps and a set of equipment mounting screws
  • 【Versatile Application】Ideal for space-efficient multi-device setups in warehouses, retail, classrooms, offices and more; Excellent choices as AV Rack/IT Rack
  • 【Effortless Setup】 Network Rack includes hardware, a comprehensive manual, mounting hole drilling template and an online assembly video to simplify setup

Create an Ingress resource

This networking.k8s.io/v1 example routes requests for app.example.com to port 80 on the existing web-service Service. Replace the example class, hostname, Service name, and port with values configured in your cluster. It is a template, not a tested deployment.

apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
  name: web
spec:
  ingressClassName: example-class
  rules:
  - host: app.example.com
    http:
      paths:
      - path: /
        pathType: Prefix
        backend:
          service:
            name: web-service
            port:
              number: 80

The manifest’s important fields are:

  • ingressClassName selects an IngressClass associated with the intended controller. It is not just an arbitrary controller annotation: the field refers to an IngressClass resource, which identifies a controller and may also specify parameters.
  • host restricts this rule to requests for the specified DNS name. The hostname must resolve to the controller’s external endpoint for clients to reach it.
  • path and pathType determine which URL paths match. Every path must specify a path type.
  • backend.service.name and backend.service.port.number identify the destination Service and its port.

See the Ingress v1 API reference for field details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
MOXA NPort 5110-1 Port Serial Device Server, 10/100 Ethernet, RS232, DB9 Male
  • Small size for easy installation
  • Real COM and TTY drivers for Windows, Linux, and macOS
  • Standard TCP/IP interface and versatile operation modes
  • Easy-to-use Windows utility for configuring multiple device servers
  • SNMP MIB-II for network management

Choose the class, host, and path behavior

Select the intended IngressClass

Use the class associated with the controller that should handle this resource. Do not assume an older controller annotation is interchangeable with spec.ingressClassName. A cluster can designate a default IngressClass, but if multiple classes are marked as default, creating a new Ingress without a class is rejected. Setting the intended class explicitly makes the controller selection clear.

Pick the path type that matches your route

  • Exact matches the entire URL path, with case sensitivity.
  • Prefix matches path elements separated by /, with case sensitivity. For example, it treats path segments as boundaries rather than matching any string that merely begins with the same characters.
  • ImplementationSpecific leaves path matching to the selected IngressClass and controller. Use it only when you intend to rely on that implementation’s behavior.

Understand wildcard hosts

A wildcard such as *.example.com covers one DNS label: it can match api.example.com, but not a.api.example.com or the bare example.com. Add rules for those names separately if they are required.

Add TLS when the route should use HTTPS

To configure the common Ingress TLS model, add a TLS section to spec that names a Secret containing tls.crt and tls.key, and list the hostname covered by that certificate. The TLS host should align with the host in the routing rule. The Kubernetes Ingress guide describes this API model as using port 443 and terminating TLS at the ingress point; traffic from there to the Service may be plaintext.

Controller-specific TLS capabilities and configuration can differ. Check the selected controller’s documentation before assuming encryption behavior beyond the common API model.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Apply the manifest and verify traffic

  1. Save the YAML to a file such as web-ingress.yaml.
  2. Apply it in the namespace containing the backend Service: kubectl apply -f web-ingress.yaml.
  3. Inspect the resource, its address, and recent events with kubectl describe ingress web and kubectl get ingress web. If the status address is not present yet, allow for infrastructure provisioning; the wait depends on the controller and environment.
  4. Point the hostname’s DNS record to the published endpoint once the controller provides one. Controller-specific networking or firewall rules may also be needed to make it reachable.
  5. From a network that can reach that endpoint, request the configured hostname and path over HTTP or HTTPS. For example, test https://app.example.com/ if you configured TLS, or use HTTP if you did not.

If the request does not reach the application, check the controller’s events or logs, the Ingress class, the host and path, the Service name and port, the Service’s healthy endpoints, DNS, and the environment’s network rules. The Kubernetes guide’s example shows inspecting the published address and notes that provisioning can take a minute or two in its example context; that timing is not a guarantee for every cluster.

When to use Ingress instead of another exposure method

The right option depends on the routing features you need and the networking implementation available in your environment; no option is universally best.

Option What it provides When to consider it
Ingress HTTP/HTTPS host- and path-based routing through an Ingress controller. When you need these routes and have a suitable controller; keep in mind the API is frozen and Kubernetes recommends Gateway for new development.
Gateway API A forward-looking Kubernetes networking API. For new work when the cluster’s implementation supports the Gateway features you need.
Service type LoadBalancer A simpler, less-configurable way to expose a Service when a supported cloud provider supplies the implementation. When exposing an individual Service is sufficient and the environment supports this Service type.
Service type NodePort A port exposed on each node. For infrastructure setups where the surrounding network can make the node endpoint reachable.

Compare whether you need HTTP/HTTPS routing, whether one or several Services should share an entry point, what the cluster’s controller or Gateway implementation supports, how TLS is handled, and whether the API’s development direction matters for your team. The Kubernetes Service documentation explains Service exposure options.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.