Hedronite · Cert Lesson · Cert-Prep / CNCF · Fri 2026-09-18

CKA Gateway API — migrate Ingress to Gateway and HTTPRoute

On the exam, Gateway holds the listener. HTTPRoute holds the rules. Ingress YAML is the wrong kind.

Lesson Class: Cert-Prep (CKA + Gateway API)
Paired Ops: GKE Gateway API
Paired Dev: Python HTTPRoute census
Grounding: CKA Q11 · Q12 contrast
Inspect
Ingress web TLS + backend first.
Gateway
Listener + certificateRefs.
HTTPRoute
parentRefs + backendRefs.
Describe the Ingress first. Prove Accepted before you walk away.

<!-- hal:authoritative:yaml -->

On the exam, Gateway holds the listener. HTTPRoute holds the rules. Ingress YAML is the wrong kind.

§I — Frame

CKA Services and Networking leftovers after Q12 Ingress include Gateway API. Bootcamp Q11 gives an existing Ingress named web (host, TLS Secret, backend Service) and a preinstalled GatewayClass (often nginx-class). You create Gateway web-gateway and HTTPRoute web-route that preserve HTTPS access and routing. PSA (09-12) and NetworkPolicy (09-09) do not satisfy this stem.

§II — Objective map

NeedMechanism
Listener + TLSGateway with HTTPS listener, hostname, certificateRefs to the same Secret the Ingress used
Classspec.gatewayClassName matching the installed class (stem: nginx-class)
RoutesHTTPRoute with parentRefs to the Gateway, matching hostnames and path rules, backendRefs to the Service/port
Provekubectl get gateway, kubectl get httproute, describe for Accepted / programmed address

§III — Q11 drill pattern

  1. Inspect Ingress web: hosts, TLS secret name, backend Service and port (kubectl describe ingress web).
  2. Inspect Secret (usually web-tls) and confirm it exists in the same namespace.
  3. Write Gateway web-gateway: - gatewayClassName: nginx-class (or whatever the stem installs) - listener HTTPS :443, hostname gateway.web.k8s.local (stem hostname) - tls.mode: Terminate and certificateRefs to Secret web-tls
  4. Write HTTPRoute web-route: - parentRefs: [{name: web-gateway}] - hostnames include gateway.web.k8s.local - path match (often PathPrefix /) and backendRefs to the Ingress backend Service/port
  5. Apply both. kubectl get gateway / httproute. Describe until Accepted.

§IV — Exam discriminators

§V — Minimal YAML skeleton (memorize structure)

apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
  name: web-gateway
spec:
  gatewayClassName: nginx-class
  listeners:
  - name: https
    protocol: HTTPS
    port: 443
    hostname: gateway.web.k8s.local
    tls:
      mode: Terminate
      certificateRefs:
      - kind: Secret
        name: web-tls
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
  name: web-route
spec:
  parentRefs:
  - name: web-gateway
  hostnames:
  - "gateway.web.k8s.local"
  rules:
  - matches:
    - path:
        type: PathPrefix
        value: /
    backendRefs:
    - name: web-service
      port: 80

Adjust Service name/port from the live Ingress backend. API version may be v1 or v1beta1 per cluster CRDs; prefer what kubectl api-resources | grep gateway shows.

§VI — Study drill

From memory, write Gateway + HTTPRoute for host gateway.web.k8s.local and Secret web-tls. Timebox to 8 minutes. Then run Bootcamp Q11 once without notes.

§VII — Closing

Describe the Ingress first. Mirror TLS and backend into Gateway + HTTPRoute. Prove Accepted before you walk away.

Related