# Kubernetes Ingress & Gateway API Updates, with Lior Lieberman Page: https://stenobird.com/podcast/kubernetes-podcast-from-google/kubernetes-ingress-gateway-api-updates-with-lior-lieberman Text version: https://stenobird.com/podcast/kubernetes-podcast-from-google/kubernetes-ingress-gateway-api-updates-with-lior-lieberman.md Podcast: [Kubernetes Podcast from Google](https://stenobird.com/podcast/kubernetes-podcast-from-google) Published: 2025-03-11T18:48:00+00:00 Episode link: https://e780d51f-f115-44a6-8252-aed9216bb521.libsyn.com/kubernetes-ingress-gateway-api-updates-with-lior-lieberman Audio file: https://traffic.libsyn.com/secure/e780d51f-f115-44a6-8252-aed9216bb521/KPod248.mp3?dest-id=3486674 Processing state: processed JSON: https://stenobird.com/v1/public/podcasts/kubernetes-podcast-from-google/episodes/kubernetes-ingress-gateway-api-updates-with-lior-lieberman Duration seconds: 2715 ## Resource The Gateway API is evolving to handle complex networking needs like service mesh capabilities, reducing the need for custom CRDs. This discussion explores the transition from traditional Ingress to the Gateway API and how tools like Ingress2gateway simplify migration. ## Highlights - Main idea: The Gateway API is a core Kubernetes API designed to provide better separation of concerns between infrastructure and application developers - Practical takeaway: Use Ingress2gateway to automate the conversion of legacy Ingress resources and custom annotations into Gateway API resources - Failure mode: Relying on complex, custom-annotated Ingress implementations can lead to fragmented, unmanageable networking configurations - Main idea: Service meshes remain essential for advanced microservices needs like identity-based authorization and request mirroring, even as Gateway API matures - Practical takeaway: For new Kubernetes deployments in 2025, the Gateway API should be the primary choice for ingress and traffic management ## Topics Kubernetes, Gateway API, Ingress, Service Mesh, CNCF, Cloud Native Networking, eBPF, OpenTelemetry ## Chapters - 1:00 — Kubernetes Security News: An overview of Kubescape's move to CNCF Incubation and its role in Kubernetes posture management. - 11:35 — The Gateway API Persona and Structure: Defining the different roles and resources that make the Gateway API more efficient than traditional Ingress. - 14:50 — Simplifying the Migration Path: How Ingress2gateway addresses the complexity of migrating custom annotations and CRDs to the new API. - 21:30 — Gateway API vs. Service Mesh: Analyzing the overlap and the continued necessity of service meshes for observability and security. - 31:25 — Permission Boundaries and Security: The benefits of segregating cluster-level infrastructure permissions from user-level application permissions. - 38:30 — The Future of Ingress Migration: Discussing the impact of major providers like Nginx adopting Gateway API to lower the barrier to entry. ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/kubernetes-podcast-from-google/episodes/kubernetes-ingress-gateway-api-updates-with-lior-lieberman/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/kubernetes-podcast-from-google/kubernetes-ingress-gateway-api-updates-with-lior-lieberman.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.