On July 7, 2020, the Cloud Native Computing Foundation (CNCF) accepted Contour as an incubating hosted project. The move gave the open-source Kubernetes ingress controller a vendor-neutral community home; it did not mean VMware sold Contour or that CNCF became its commercial support provider. Contour remains listed by CNCF as an incubating project.
What Contour does
Contour is a Kubernetes ingress controller: it translates traffic-routing configuration into rules for Envoy, which it deploys as a reverse proxy and load balancer at the edge of a cluster. Contour acts as the control plane, allowing Envoy configuration to be updated dynamically as Kubernetes resources change. CNCF describes the project on its Contour project page.
Contour supports three configuration paths: the stable Kubernetes Ingress API, Contour’s own HTTPProxy custom resource, and Kubernetes Gateway API, as documented in the project repository. HTTPProxy extends beyond the basic Ingress API and offers controls useful in multi-team clusters, including limits on which namespaces can configure virtual hosts and TLS credentials. The repository is licensed under Apache-2.0.
What happened in the CNCF handoff
The project began at Heptio in 2017. VMware acquired Heptio in 2018, and Contour 1.0 followed in November 2019. On July 7, 2020, CNCF’s Technical Oversight Committee accepted Contour at the incubation level. The announcement framed CNCF hosting as a way to encourage participation from more companies and contributors, rather than leaving the project’s home tied to one vendor. The CNCF announcement records the decision and the contemporaneous rationale.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
That is a governance and project-hosting change. The cited announcement does not establish a separate legal transfer of every trademark or intellectual-property right, nor does it document a commercial support arrangement with CNCF.
Is Contour still maintained?
CNCF continues to list Contour as an incubating project. Its project page currently reports 360 contributors, 138 contributing organizations, and a health score of 44. These are live project-insight metrics, not fixed historical totals; they can change over time. CNCF’s 2020 acceptance announcement separately recorded 329 contributors, 91 committers, 2.3k GitHub stars, 375 forks, and 48 releases at that time.
Project status alone does not establish whether a particular release meets an organization’s support or security requirements. Check the repository’s release activity, documentation, issue handling, and compatibility information before adopting or upgrading it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Contour, Kubernetes Ingress, and Gateway API
Kubernetes has frozen the Ingress API and recommends Gateway API for new development, but Ingress remains supported. The change is not a removal of existing Ingress resources. See the Kubernetes Ingress documentation.
Rank #3
| Option | What it means for a Contour user | Key consideration |
|---|---|---|
| Kubernetes Ingress API | Use the established, stable API that Contour supports. | Suitable for compatibility with existing Ingress manifests; Kubernetes does not recommend it for new API development. |
| Contour HTTPProxy | Use Contour’s custom resource for richer routing and namespace-level controls, including virtual-host and TLS credential delegation. | Contour-specific configuration means weighing its added capabilities against dependence on that controller’s resource model. |
| Kubernetes Gateway API | Use the newer Kubernetes API intended for ongoing traffic-management development; Contour documents support for it. | Check the features and implementation status available in the Contour version you plan to run, and account for migration work from existing manifests. |
These APIs are configuration choices, not interchangeable controller products. To compare Contour with another ingress controller, assess the implementation’s supported API features, Envoy-based traffic handling and observability, team delegation and TLS model, operational complexity, and the effort needed to migrate existing routes. The available evidence does not support a universal performance ranking.
Quick Recap
Rank #4
When the CNCF move matters to an operator
- Governance: CNCF hosting places the project within a vendor-neutral foundation framework and was intended to broaden community participation.
- Technical choice: The move does not change the distinction between Ingress, HTTPProxy, and Gateway API configuration; choose based on compatibility, capabilities, and migration needs.
- Support: CNCF incubation is not, by itself, a commercial support contract. Organizations needing vendor-backed support should verify that separately.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

