What to Use After Kubernetes Ingress-Nginx EOL in 2026?

0
15
Asked By CactusViper42 On

With ingress-nginx set to reach end-of-life in March 2026, many of us are looking for alternatives. I've looked into a few options and Traefik seems promising, but I'm concerned about replicating the WAF feature that relies on the OWASP Core Rule Set with ModSecurity since there doesn't seem to be a direct replacement. How is everyone planning to handle this transition?

5 Answers

Answered By CodeSorcerer24 On

Since we use AKS, we're probably going to transition to Azure FrontDoor along with WAF. We might wait a few months while assessing the risk before fully committing, but my intuition says there might be some pushback about the retirement, and hopefully, the K8s team will consider continuing support.

Answered By BlazingFalcon99 On

I switched to Envoy Gateway using the Coraza WASM as a filter. Just a heads-up, you might face increased memory usage and higher latency though.

Answered By GaleForce87 On

I went with the Airlock WAF since it offers a community version with reasonable limits. This way, I can utilize GatewayAPI and ensure solid enterprise-level WAF capabilities.

Answered By SmoothOperator21 On

I've moved everything to Envoy Gateway as the architecture allows for extensive customization. For instance, I created my own "extproc" service that leverages Coraza's Go library. Although I can get major memory issues with the WASM filter, I'm finding that my performance is actually better than with ingress-nginx.

Answered By TechMaven78 On

You could try the Coraza plugin with its middleware on Traefik; it's available for free. It could really serve those of us wanting to stick with Ingress objects.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.