Ingress (CKAD)
One public entry point for many Services: host and path rules, TLS, and the controller that makes the rules real.
An interactive Kubernetes lesson: 19 steps, about 30 minutes, on a live simulation in your browser.
Your shop has two Deployments: web serves the pages and api serves the data. Customers need to reach both from the internet.
The tool you already have is a Service of type LoadBalancer. Set it on both and each one gets its own cloud load balancer and its own public IP. It works: watch both streams come back 200.
What you will learn
One door for many Services
- A load balancer for every Service: A LoadBalancer Service is one public IP for one Service. It forwards connections; it never reads the URL.
- One door, a list of rules: An Ingress is a routing table for HTTP: host + path in, Service + port out.
- Call the new address: An Ingress object does nothing by itself. It is a request for routing, waiting for a controller to fulfil it.
Rules need a controller
- Install an ingress controller: The Ingress is the rulebook. The controller is the proxy that obeys it. Traffic flows internet → controller → Service → pod.
- IngressClass: which controller?: ingressClassName is the address on the envelope: it names the controller that should read this Ingress. Every other controller ignores it.
- Break it: the wrong class
Hosts and paths
- Route by path: The controller picks the most specific rule: the host must match, then the longest matching path wins.
- Prefix or Exact: Prefix matches a path and everything under it. Exact matches one path. A Prefix / rule catches whatever the others miss.
- Route by host: Every hostname points at the one controller IP. The Host header in the request decides which rules apply.
404, 503 and what they mean
- A host nobody wrote a rule for: A 404 from the ingress means the controller is up and no rule matched. Check the host and the path, character by character.
- Break it: a backend with no pods
- Read the symptom, then describe: Refused = no controller. 404 = no rule. 503 = no endpoints. The status code tells you which layer to open.
HTTPS
- HTTPS before you configure it: No TLS section, no real certificate. The controller answers on 443 with its own fake certificate and clients refuse it.
- A TLS Secret and a tls block: TLS terminates at the controller. The Ingress names a kubernetes.io/tls Secret in its own namespace; the pods never see the certificate.
- Drill: create the TLS Secret
At exam speed
- kubectl create ingress: --rule="host/path*=svc:port": the star makes it Prefix, no star makes it Exact.
- Drill: one rule, one command
Recap & playground
- Cheat sheet
- Playground