
- Platform teams often centralize infra components (Gateways, GitOps controllers, policy engines) in a dedicated
infranamespace. - Application teams deploy services and routing objects into team-specific namespaces to isolate quotas, limits, and permissions.
- If cross-namespace routing is not enabled, a central Gateway cannot accept route objects from other namespaces, preventing teams from exposing their applications through the shared Gateway.
- Namespace
infra: Gateways, Argo CD controllers, Kyverno, shared platform resources. - Namespace
team-a,team-b, etc.: Application deployments, Services, Route objects (HTTPRoute, TCPRoute).
allowedRoutes field. There are two primary approaches:
- Allow routes from all namespaces (broad, less restrictive).
- Allow routes only from namespaces that match a label selector (recommended, follows principle of least privilege).
Use the principle of least privilege: prefer a label selector (
Selector) to limit which namespaces can reference the Gateway. Use All only when you have a clear, audited reason to permit routes from every namespace.
Referencing the Gateway from another namespace
When a Route object (for example, an
HTTPRoute) lives in a different namespace than the Gateway, it must explicitly include the Gateway’s namespace in its parentRefs. If you omit the namespace field, the API assumes the parent resides in the same namespace as the Route.
Example HTTPRoute in namespace team-a referencing the gateway in namespace infra:
- Set
allowedRoutes.namespaces.fromtoSelectorwhenever possible and useselector.matchLabelsto limit which namespaces can attach routes to the Gateway. - Ensure each route’s
parentRefs[].namespaceis set to the Gateway’s namespace when routes live outside the Gateway’s namespace. - Apply namespace labels (for example,
team: frontend) consistently to enable selector-based access control. - Audit your Gateways and Route objects periodically to confirm only intended namespaces are allowed.
- Gateway API overview: https://gateway-api.sigs.k8s.io/
- Kubernetes Gateway API docs: https://kubernetes.io/docs/concepts/services-networking/gateway/
- NGINX Gateway Fabric docs: https://docs.nginx.com/nginx-adap/ (refer to your NGINX provider documentation for Fabric-specific behavior)

allowedRoutes and always include the Gateway namespace in parentRefs for cross-namespace routes.