learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Ingress (CKAD)

One public entry point for many Services: host and path rules, TLS, and the controller that makes the rules real.

An interactive Kubernetes lesson: 19 steps, about 30 minutes, on a live simulation in your browser.

Your shop has two Deployments: web serves the pages and api serves the data. Customers need to reach both from the internet.

The tool you already have is a Service of type LoadBalancer. Set it on both and each one gets its own cloud load balancer and its own public IP. It works: watch both streams come back 200.

What you will learn

  1. One door for many Services

    • A load balancer for every Service: A LoadBalancer Service is one public IP for one Service. It forwards connections; it never reads the URL.
    • One door, a list of rules: An Ingress is a routing table for HTTP: host + path in, Service + port out.
    • Call the new address: An Ingress object does nothing by itself. It is a request for routing, waiting for a controller to fulfil it.
  2. Rules need a controller

    • Install an ingress controller: The Ingress is the rulebook. The controller is the proxy that obeys it. Traffic flows internet → controller → Service → pod.
    • IngressClass: which controller?: ingressClassName is the address on the envelope: it names the controller that should read this Ingress. Every other controller ignores it.
    • Break it: the wrong class
  3. Hosts and paths

    • Route by path: The controller picks the most specific rule: the host must match, then the longest matching path wins.
    • Prefix or Exact: Prefix matches a path and everything under it. Exact matches one path. A Prefix / rule catches whatever the others miss.
    • Route by host: Every hostname points at the one controller IP. The Host header in the request decides which rules apply.
  4. 404, 503 and what they mean

    • A host nobody wrote a rule for: A 404 from the ingress means the controller is up and no rule matched. Check the host and the path, character by character.
    • Break it: a backend with no pods
    • Read the symptom, then describe: Refused = no controller. 404 = no rule. 503 = no endpoints. The status code tells you which layer to open.
  5. HTTPS

    • HTTPS before you configure it: No TLS section, no real certificate. The controller answers on 443 with its own fake certificate and clients refuse it.
    • A TLS Secret and a tls block: TLS terminates at the controller. The Ingress names a kubernetes.io/tls Secret in its own namespace; the pods never see the certificate.
    • Drill: create the TLS Secret
  6. At exam speed

    • kubectl create ingress: --rule="host/path*=svc:port": the star makes it Prefix, no star makes it Exact.
    • Drill: one rule, one command
  7. Recap & playground

    • Cheat sheet
    • Playground