CKA Gateway API — migrate Ingress to Gateway and HTTPRoute
On the exam, Gateway holds the listener. HTTPRoute holds the rules. Ingress YAML is the wrong kind.
<!-- hal:authoritative:yaml -->
On the exam, Gateway holds the listener. HTTPRoute holds the rules. Ingress YAML is the wrong kind.
§I — Frame
CKA Services and Networking leftovers after Q12 Ingress include Gateway API. Bootcamp Q11 gives an existing Ingress named web (host, TLS Secret, backend Service) and a preinstalled GatewayClass (often nginx-class). You create Gateway web-gateway and HTTPRoute web-route that preserve HTTPS access and routing. PSA (09-12) and NetworkPolicy (09-09) do not satisfy this stem.
§II — Objective map
| Need | Mechanism |
|---|---|
| Listener + TLS | Gateway with HTTPS listener, hostname, certificateRefs to the same Secret the Ingress used |
| Class | spec.gatewayClassName matching the installed class (stem: nginx-class) |
| Routes | HTTPRoute with parentRefs to the Gateway, matching hostnames and path rules, backendRefs to the Service/port |
| Prove | kubectl get gateway, kubectl get httproute, describe for Accepted / programmed address |
§III — Q11 drill pattern
- Inspect Ingress
web: hosts, TLS secret name, backend Service and port (kubectl describe ingress web). - Inspect Secret (usually
web-tls) and confirm it exists in the same namespace. - Write Gateway
web-gateway: -gatewayClassName: nginx-class(or whatever the stem installs) - listener HTTPS :443, hostnamegateway.web.k8s.local(stem hostname) -tls.mode: TerminateandcertificateRefsto Secretweb-tls - Write HTTPRoute
web-route: -parentRefs: [{name: web-gateway}]- hostnames includegateway.web.k8s.local- path match (often PathPrefix/) andbackendRefsto the Ingress backend Service/port - Apply both.
kubectl get gateway/httproute. Describe until Accepted.
§IV — Exam discriminators
- Kind names are
GatewayandHTTPRoute(not Ingress, not VirtualService). - GatewayClass is usually already installed. Creating a second class is inventing work.
- Copy TLS from the Ingress Secret name; do not mint a new certificate unless asked.
- Q12 Ingress answers fail a Q11 stem. Q11 Gateway answers fail a Q12 stem.
- Hostname typos between Gateway listener and HTTPRoute hostnames prevent attach.
§V — Minimal YAML skeleton (memorize structure)
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata:
name: web-gateway
spec:
gatewayClassName: nginx-class
listeners:
- name: https
protocol: HTTPS
port: 443
hostname: gateway.web.k8s.local
tls:
mode: Terminate
certificateRefs:
- kind: Secret
name: web-tls
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata:
name: web-route
spec:
parentRefs:
- name: web-gateway
hostnames:
- "gateway.web.k8s.local"
rules:
- matches:
- path:
type: PathPrefix
value: /
backendRefs:
- name: web-service
port: 80
Adjust Service name/port from the live Ingress backend. API version may be v1 or v1beta1 per cluster CRDs; prefer what kubectl api-resources | grep gateway shows.
§VI — Study drill
From memory, write Gateway + HTTPRoute for host gateway.web.k8s.local and Secret web-tls. Timebox to 8 minutes. Then run Bootcamp Q11 once without notes.
§VII — Closing
Describe the Ingress first. Mirror TLS and backend into Gateway + HTTPRoute. Prove Accepted before you walk away.
Related
- Ops
- Dev