How To Gateway With Ingress - 140 Days InGate - Marco Ebert & James Strong
Marco Ebert, James Strong
KubeCon + CloudNativeCon Europe 2025 · Session
This talk, "How To Gateway With Ingress - 140 Days InGate," delivered by Marco Ebert and James Strong, delves into the critical juncture facing the widely adopted Kubernetes Ingress NGINX controller and introduces its strategic successor, Ingate. The speakers, both long-standing maintainers of the Ingress NGINX project, candidly address the significant security vulnerabilities that recently plagued the controller, including a critical unauthenticated remote code execution (RCE) flaw. Beyond immediate security patches, the presentation outlines a profound shift for the Ingress NGINX project, signaling its transition into a maintenance-only mode and eventual archiving.
AI review
This session delivered a critical update on the Kubernetes Ingress NGINX controller, revealing severe RCE vulnerabilities (CVSS 9.8) that demand immediate patching. More importantly, it announced the project's transition to maintenance-only mode and introduced Ingate, a next-generation, Gateway API-based successor designed to address the legacy controller's architectural flaws and security debt. The speakers, as project maintainers, provided an unvarnished look at the challenges, the critical feature gap, and a clear call to action for the community, making this a pivotal discussion for…