Why migrate ingress controllers?¶
In 2026, the policy of best-effort maintenance of the Ingress NGINX Controller ended. Following the announcement of this plan, a considerable amount of discussion has taken place amongst Kubernetes users around the topic of a replacement.
In the near term, 2i2c has decided to migrate to the official NGINX Ingress Controller. This is likely not a “permanent” solution — alongside the Ingress NGINX Controller deprecation, the Kubernetes Ingress API itself is also frozen, with the Kubernetes project recommending the Gateway API instead. Although there has not been an announcement that the Ingress API will become deprecated in future, we may need/want to migrate to the Gateway API down the road.
How to migrate from an existing Controller to another¶
To facilitate zero downtime migration between controllers, we have introduced a new LoadBalancer ingress service. The purpose of this service is to provide a static external IP address that lives independently of the ingress controller. Consequently, we no longer need ingress controllers to create their own LBs — we can use simple clusterIP services.
Switch to another nginx controller¶
Since the DNS records are pointing to the dedicated cluster-entrypoint LB service, we can safely transition to the new ingress service:
Enable the new ingress (in this case
nginx-ingress) service in the support chart withnginx-ingress: # Enable controller enabled: true controller: ingressClass: # Claim the `nginx` ingress class create: trueDisable original controller (in this case
ingress-nginx):ingress-nginx: controller: # Turn off controller replicaCount: 0 # Let go of the `nginx` ingress class ingressClassResource: enabled: falsePoint the
cluster-entrypointLB to the new ingress service (in this casenginx-ingress):clusterEntrypoint: targetController: nginx-ingress*Make sure to modify the
cluster-entrypointservice to conditionally set the correct annotations, depending on which targetController is set.
Switch to Gateway API¶
It should be trivial to migrate to a new ingress controller or Gateway that establishes a clusterIP service. Once a new controller/gateway is introduced, simply point the cluster-entrypoint LB at the new service pods.