Lesson 4: Ingress Controllers & Traffic Routing
🧠 The Concept (Explain Like I'm 5)
Your Kubernetes cluster is a walled fortress.
An Ingress Controller is the fortress gatekeeper. When internet traffic arrives at the gate asking for api.company.com/v1, the gatekeeper reads the map and sends the traffic to the correct internal building (Pod).
🏢 The Enterprise Context
- AWS Load Balancer Controller: Instead of deploying NGINX inside the cluster, this controller talks to the AWS API and provisions a native AWS Application Load Balancer (ALB) outside the cluster.
- Ingress vs Gateway API: K8s Ingress is legacy. The new enterprise standard is the Kubernetes Gateway API, which splits routing rules into separate roles (Cluster Operator vs App Developer).
🗺️ Visual Architecture: Traffic Flow (AWS ALB Controller)
flowchart TD
User["🌍 Internet User"] --> Route53["DNS (Route53)"]
Route53 --> ALB["AWS ALB<br/>(Managed by K8s Controller)"]
subgraph K8s ["Kubernetes Cluster"]
TargetGroup["Target Group / NodePort"]
subgraph AppA ["Auth Service"]
PodA1["Pod 1"]
PodA2["Pod 2"]
end
subgraph AppB ["Payment Service"]
PodB["Pod 1"]
end
end
ALB -->|/auth| PodA1
ALB -->|/auth| PodA2
ALB -->|/pay| PodB