- referencing a
GatewayClass(the implementation/controller), - hosting listeners (attachment points for Routes),
- accepting and routing
Routeobjects, - hosting TLS certificates when terminating TLS,
- and exposing a routable IP address.
Gateways are implementation-specific. The
GatewayClass you reference determines controller behavior, supported features, and how TLS or protocols are implemented. See the Gateway API docs for controller-specific details.Example Gateway manifest
Here is a minimal Gateway manifest that references aGatewayClass named nginx and creates an HTTP listener for *.example.com on port 80:
gatewayClassName— references theGatewayClassobject providing the implementation (the controller).listeners— describe how the Gateway accepts traffic and whereRoutekinds can attach. Thehttplistener above listens on port80for HTTP requests and accepts hostnames that match*.example.com.
Listener protocols
Listener protocols supported by the Gateway API include:
Note: Controller implementations vary in feature support. Check your controller’s documentation for exact behavior and extensions.
Advanced listener settings
Listeners include several advanced options to control which Routes may attach and how they are matched.allowedRoutescontrols which Route kinds and which namespaces are permitted to reference a listener.- Namespace selection options:
from: All— allow Routes from any namespace.from: Same— allow Routes only from the Gateway’s namespace.from: Selector— allow Routes only from namespaces matching a label selector.
allowedRoutes namespace options
TLS modes: Terminate vs Passthrough
The Gateway API supports two primary TLS handling modes. Choose the one that fits your security and routing requirements.Choose
terminate when the Gateway needs to inspect HTTP for routing or perform TLS offload. Choose passthrough when your application must handle TLS termination or client certificate validation end-to-end.
Quick reference and next steps
- Create a
GatewayClass(controller) first, then create one or moreGatewayresources. - Define listeners for protocol, port, and hostname matching.
- Use
allowedRoutesto scope which namespaces and Route kinds can attach. - Decide whether the Gateway should
terminateTLS orpassthroughencrypted connections. - Consult your controller’s documentation for implementation-specific features (certificate management, re-encryption to backends, etc.).
- Gateway API specification: https://gateway-api.sigs.k8s.io/
- Kubernetes Networking concepts: https://kubernetes.io/docs/concepts/services-networking/
- Controller-specific docs (example): check your controller’s Helm chart or provider documentation for TLS and listener extensions.