# ingress-nginx

Published articles for ingress-nginx.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Cilium 1.20: Gateway API ExternalAuth, TCPRoute/UDPRoute, ENI IPAM for IPv6, and more

DevFeed: [Cilium 1.20: Gateway API ExternalAuth, TCPRoute/UDPRoute, ENI IPAM for IPv6, and more](<https://devfeed.tech/articles/cilium-1-20-gateway-api-externalauth-tcproute-udproute-eni-ipam-for-ipv6-and-more-17374.md>)

Original publisher: [Read original article](<https://www.cncf.io/blog/2026/09/14/cilium-1-20-gateway-api-externalauth-tcproute-udproute-eni-ipam-for-ipv6-and-more/>)

Author: Nico Vibert and Donia Chaiehloudj, Cilium

Published: 2026-09-14T10:45:49Z

Content type: article

Language: en

Sources: [Cloud Native Computing Foundation](<https://devfeed.tech/sources/cloud-native-computing-foundation.md>)

Topics: [Cilium](<https://devfeed.tech/topics/cilium.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [API](<https://devfeed.tech/topics/api.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [eBPF](<https://devfeed.tech/topics/ebpf.md>), [VPC](<https://devfeed.tech/topics/vpc.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [api](<https://devfeed.tech/tags/api.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [authorization](<https://devfeed.tech/tags/authorization.md>), [aws](<https://devfeed.tech/tags/aws.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cni](<https://devfeed.tech/tags/cni.md>), [ebpf](<https://devfeed.tech/tags/ebpf.md>), [google](<https://devfeed.tech/tags/google.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [ipv4](<https://devfeed.tech/tags/ipv4.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>)

### AI overview

Cilium 1.20 expands Gateway API support with ExternalAuth, CORS filters, ListenerSets, TCPRoute, and UDPRoute. The release also introduces extensible datapath plugins, advances networking standardization with Kubernetes, and adds beta IPv6 support for AWS ENI IPAM.

### Source excerpt

Cilium 1.20, the second major open source Cilium release of 2026 after Cilium 1.19, is finally here. Three themes stand out in this release: Thank you to every contributor, reviewer and maintainer who made Cilium 1.20...

## Technology Short Take 193

DevFeed: [Technology Short Take 193](<https://devfeed.tech/articles/technology-short-take-193-10927.md>)

Original publisher: [Read original article](<https://blog.scottlowe.org/2026/04/03/technology-short-take-193/>)

Author: Scott Lowe

Published: 2026-04-03T14:00:00Z

Content type: article

Language: en

Sources: [Scott's Weblog](<https://devfeed.tech/sources/scott-s-weblog.md>)

Topics: [datacenter](<https://devfeed.tech/topics/datacenter.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Security](<https://devfeed.tech/topics/security.md>), [GitHub Actions](<https://devfeed.tech/topics/github-actions.md>), [GitOps](<https://devfeed.tech/topics/gitops.md>), [ingress-nginx](<https://devfeed.tech/topics/ingress-nginx.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [litellm](<https://devfeed.tech/topics/litellm.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [blog-post](<https://devfeed.tech/tags/blog-post.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cni](<https://devfeed.tech/tags/cni.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cri-o](<https://devfeed.tech/tags/cri-o.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [github-actions](<https://devfeed.tech/tags/github-actions.md>), [gitops](<https://devfeed.tech/tags/gitops.md>), [go](<https://devfeed.tech/tags/go.md>), [iac](<https://devfeed.tech/tags/iac.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [litellm](<https://devfeed.tech/tags/litellm.md>), [networking](<https://devfeed.tech/tags/networking.md>), [oci](<https://devfeed.tech/tags/oci.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>)

### AI overview

Technology Short Take 193 is a curated roundup of data center technology links covering networking, IPv4 address space, consumer-router regulation, servers and hardware, security incidents involving Trivy and software supply chains, Ingress-NGINX migration, GitOps, local LLMs, and infrastructure management.

### Source excerpt

Welcome to Technology Short Take #193! I know it has only been a couple weeks since the last Tech Short Take, but I am guessing that readers won't really mind another one. Here is my latest collection of articles and posts about data center-related technologies. Enjoy! Networking Brian Linkletter shares his 2026 list of network simulators and emulators. (Hat tip to Ivan P. for the link.) Emmanuel Vitus brings to light a battle over IPv4 address space and the control of the regional internet registries. Doug Dawson discusses the recent FCC ban on consumer-grade routers and the potential impacts to industry and ISPs. Servers/Hardware RIP Mac Pro. I had a "classic Mac Pro" (2012 era) for a long time, and I loved that system. (I even ran Linux on it for a while.) It is a shame to see it go. I mentioned on social media (Mastodon/Bluesky) that I recently purchased all the hardware for a new PC build. It'll be part PC/part home server, as I look to expand the type and scope of services that I self-host. Don't be surprised if a few articles emerge out of this. Security Trivy's GitHub Actions were compromised by attackers, leading to the exposure of CI/CD secrets. This post on the Socket blog has more details, and Rose Security has a write-up that provides more details on how a typosquatted domain and a fake version tag were involved. At least one other software supply chain exploit has been tracked back to the Trivy compromise: the Python litellm module on PyPI steals credentials. The Docker side of the Trivy compromise is shared in detail in this Docker blog post. Cloud Computing/Cloud Management Looking for some help in migrating away from Ingress-NGINX? This announcement of Ingress2Gateway 1.0 might be just what you are seeking. The FluxCD team published a post discussing Morgan Stanley's "Stairway to GitOps" presentation, which describes the firm's five-year journey from push-based pipelines to a self-service GitOps platform. Although I am not an AI fanboy, I do recogni

## Fork Yeah: We're keeping ingress-nginx alive

DevFeed: [Fork Yeah: We're keeping ingress-nginx alive](<https://devfeed.tech/articles/fork-yeah-we-re-keeping-ingress-nginx-alive-13135.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/keeping-ingress-nginx-alive>)

Published: 2025-12-22T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [nginx](<https://devfeed.tech/topics/nginx.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Maintainers](<https://devfeed.tech/topics/maintainers.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-emeritoss](<https://devfeed.tech/tags/chainguard-emeritoss.md>), [chainguard-open-source](<https://devfeed.tech/tags/chainguard-open-source.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [github](<https://devfeed.tech/tags/github.md>), [ingress](<https://devfeed.tech/tags/ingress.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [ingress-nginx-retirement](<https://devfeed.tech/tags/ingress-nginx-retirement.md>), [kubeapps](<https://devfeed.tech/tags/kubeapps.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [maintainers](<https://devfeed.tech/tags/maintainers.md>), [migration](<https://devfeed.tech/tags/migration.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Chainguard is maintaining a fork of ingress-nginx through its EmeritOSS program after the upstream project announced retirement and planned archiving in March 2026. It offers CVE-free container images, remediation SLAs, and FIPS versions while users evaluate migration options such as the Gateway API or other ingress controllers.

### Source excerpt

Chainguard is keeping ingress-nginx alive through EmeritOSS, providing security-focused maintenance so teams can migrate safely without risk.

## Introducing Chainguard EmeritOSS: Sustainable stewardship for mature open source

DevFeed: [Introducing Chainguard EmeritOSS: Sustainable stewardship for mature open source](<https://devfeed.tech/articles/introducing-chainguard-emeritoss-sustainable-stewardship-for-mature-open-source-13110.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/introducing-chainguard-emeritoss>)

Published: 2025-12-16T00:00:00Z

Content type: release

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Open Source](<https://devfeed.tech/topics/open-source.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>), [maintenance](<https://devfeed.tech/topics/maintenance.md>), [ingress-nginx](<https://devfeed.tech/topics/ingress-nginx.md>), [kaniko](<https://devfeed.tech/topics/kaniko.md>), [kubeapps](<https://devfeed.tech/topics/kubeapps.md>)

Tags: [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers-open-source](<https://devfeed.tech/tags/chainguard-containers-open-source.md>), [chainguard-emeritoss](<https://devfeed.tech/tags/chainguard-emeritoss.md>), [chainguard-open-source](<https://devfeed.tech/tags/chainguard-open-source.md>), [emeritoss](<https://devfeed.tech/tags/emeritoss.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [kaniko](<https://devfeed.tech/tags/kaniko.md>), [kubeapps](<https://devfeed.tech/tags/kubeapps.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-maintenance](<https://devfeed.tech/tags/open-source-maintenance.md>)

### AI overview

Chainguard announces EmeritOSS, a program for preserving and securely maintaining mature, unmaintained open source projects. The program starts with Kaniko, Kubeapps, and ingress-nginx.

### Source excerpt

EmeritOSS is a stability-focused program that preserves and secures mature, unmaintained open source projects, starting with Kaniko, Kubeapps, and ingress-nginx.

## Ingress NGINX Retirement: What You Need to Know

DevFeed: [Ingress NGINX Retirement: What You Need to Know](<https://devfeed.tech/articles/ingress-nginx-retirement-what-you-need-to-know-17593.md>)

Original publisher: [Read original article](<https://www.kubernetes.dev/blog/2025/11/12/ingress-nginx-retirement/>)

Author: The Kubernetes Authors

Published: 2025-11-12T17:00:00Z

Content type: release

Language: en

Sources: [Kubernetes Contributors Blog](<https://devfeed.tech/sources/kubernetes-contributors-blog.md>)

Topics: [ingress-nginx](<https://devfeed.tech/topics/ingress-nginx.md>), [ingress nginx retirement](<https://devfeed.tech/topics/ingress-nginx-retirement.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [alternatives](<https://devfeed.tech/tags/alternatives.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [ingress-nginx-retirement](<https://devfeed.tech/tags/ingress-nginx-retirement.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>)

### AI overview

Kubernetes SIG Network and the Security Response Committee announce the upcoming retirement of Ingress NGINX. Best-effort maintenance will continue until March 2026; afterward, the project will receive no further releases, bug fixes, or security updates. Existing deployments and installation artifacts will remain available, and users are encouraged to migrate to alternatives such as Gateway API.

### Source excerpt

To prioritize the safety and security of the ecosystem, Kubernetes SIG Network and the Security Response Committee are announcing the upcoming retirement of Ingress NGINX . Best-effort maintenance will continue until March 2026. Afterward, there will be no further releases, no bugfixes, and no updates to resolve any security vulnerabilities that may be discovered. Existing deployments of Ingress NGINX will continue to function and installation artifacts will remain available. We recommend migrating to one of the many alternatives. Consider migrating to Gateway API , the modern replacement for Ingress. If you must continue using Ingress, many alternative Ingress controllers are listed in the Kubernetes documentation . Continue reading for further information about the history and current state of Ingress NGINX, as well as next steps. About Ingress NGINX Ingress is the original user-friendly way to direct network traffic to workloads running on Kubernetes. (Gateway API is a newer way to achieve many of the same goals.) In order for an Ingress to work in your cluster, there must be an Ingress controller running. There are many Ingress controller choices available, which serve the needs of different users and use cases. Some are cloud-provider specific, while others have more general applicability. Ingress NGINX was an Ingress controller, developed early in the history of the Kubernetes project as an example implementation of the API. It became very popular due to its tremendous flexibility, breadth of features, and independence from any particular cloud or infrastructure provider. Since those days, many other Ingress controllers have been created within the Kubernetes project by community groups, and by cloud native vendors. Ingress NGINX has continued to be one of the most popular, deployed as part of many hosted Kubernetes platforms and within innumerable independent users' clusters. History and Challenges The breadth and flexibility of Ingress NGINX has caused maint

## Ingress-nginx-controller: Nightmare on CVE Street

DevFeed: [Ingress-nginx-controller: Nightmare on CVE Street](<https://devfeed.tech/articles/ingress-nginx-controller-nightmare-on-cve-street-13103.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/ingress-nginx-controller-nightmare-on-cve-street>)

Published: 2025-04-02T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [nginx](<https://devfeed.tech/topics/nginx.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [chainguard containers](<https://devfeed.tech/topics/chainguard-containers.md>), [chainguard os](<https://devfeed.tech/topics/chainguard-os.md>), [chainguard](<https://devfeed.tech/topics/chainguard.md>)

Tags: [availability](<https://devfeed.tech/tags/availability.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [chainguard-os](<https://devfeed.tech/tags/chainguard-os.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ingress](<https://devfeed.tech/tags/ingress.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [remote-code-execution](<https://devfeed.tech/tags/remote-code-execution.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [wiz](<https://devfeed.tech/tags/wiz.md>)

### AI overview

The article describes several critical remote code execution vulnerabilities affecting the Ingress-nginx-controller, including risks to Kubernetes cluster secrets, service availability, privileges, and security controls. It also explains how Chainguard reviewed its infrastructure, identified affected Chainguard Containers, and prepared patches using Chainguard OS's continuous update model.

### Source excerpt

Chainguard was able to quickly respond to and handle the recent ingress-nginx-controller CVEs that were discovered by Wiz. See the actions we have taken.

## Ingress-nginx CVE-2025-1974: What It Is and How to Fix It

DevFeed: [Ingress-nginx CVE-2025-1974: What It Is and How to Fix It](<https://devfeed.tech/articles/ingress-nginx-cve-2025-1974-what-it-is-and-how-to-fix-it-29.md>)

Original publisher: [Read original article](<https://blog.abhimanyu-saharan.com/posts/ingress-nginx-cve-2025-1974-what-it-is-and-how-to-fix-it>)

Author: Abhimanyu Saharan

Published: 2025-03-25T00:00:00Z

Content type: article

Language: en

Sources: [Abhimanyu Saharan](<https://devfeed.tech/sources/abhimanyu-s-blog.md>)

Topics: [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [cve](<https://devfeed.tech/tags/cve.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [rce](<https://devfeed.tech/tags/rce.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains CVE-2025-1974, known as IngressNightmare, a critical remote code execution vulnerability in ingress-nginx that affects more than 40% of clusters. It covers how to detect and patch the flaw.

### Source excerpt

CVE-2025-1974 (IngressNightmare) is a critical RCE flaw in ingress-nginx affecting 40%+ of clusters. Learn how to detect and patch it.

## Iterating Towards a More Scalable Ingress

DevFeed: [Iterating Towards a More Scalable Ingress](<https://devfeed.tech/articles/iterating-towards-a-more-scalable-ingress-1459.md>)

Original publisher: [Read original article](<https://shopify.engineering/iterating-towards-more-stable-ingress>)

Author: Francisco Mejia

Published: 2018-08-31T18:00:00Z

Content type: article

Language: en

Sources: [Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering.md>), [Shopify Engineering - Shopify Engineering](<https://devfeed.tech/sources/shopify-engineering-shopify-engineering.md>)

Topics: [Shopify](<https://devfeed.tech/topics/shopify.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Production Engineering](<https://devfeed.tech/topics/production-engineering.md>)

Tags: [ingress-nginx](<https://devfeed.tech/tags/ingress-nginx.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [load-balancer](<https://devfeed.tech/tags/load-balancer.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [optimization](<https://devfeed.tech/tags/optimization.md>), [performance](<https://devfeed.tech/tags/performance.md>), [production-engineering](<https://devfeed.tech/tags/production-engineering.md>), [shopify](<https://devfeed.tech/tags/shopify.md>)

### AI overview

Shopify describes scaling its Kubernetes infrastructure and migrating cluster ingress from Google Cloud Load Balancer Controller to ingress-nginx. The article focuses on optimizing ingress-nginx dynamic configuration to reduce NGINX reloads and improve performance during frequent deployments.

### Source excerpt

Shopify, the leading cloud-based, multi-channel commerce platform, is growing at an incredibly fast pace. Since the beginning of 2016, the number of merchants on the platform increased from 375,000 to 600,000+. As the platform scales, we face new and exciting challenges such as implementing Shopify's Pod architecture and future proofing our cloud storage usage. Shopify's infrastructure relies heavily on Kubernetes to serve millions of requests every minute.