Skip to main content
Welcome to this lesson on the Gateway API with NGINX Fabric Gateway. I’m Pedro Ignácio, and I’ll guide you through deploying and operating an NGINX Fabric Gateway as a Gateway API data plane for Kubernetes. In modern cloud-native environments, controlling traffic into and within your clusters is essential. The traditional Ingress API has served well, but the Gateway API provides a more expressive, secure, and extensible model for routing, traffic management, and multi-controller use-cases. This lesson explains the Gateway API fundamentals, the control-plane / data-plane persona model, and step-by-step deployment and validation of NGINX Fabric Gateway.
A slide-like screenshot titled "Gateway API" showing a "Control Plane" header with a Kubernetes cluster diagram and a light-blue box labeled "Namespace – nginx-gateway." In the bottom-right is a small circular video thumbnail of a person speaking.
This lesson assumes you have access to a Kubernetes cluster, and that kubectl and helm are installed and configured to target your cluster.
You will need sufficient cluster permissions to create CRDs, namespaces, and install Helm charts (typically cluster-admin or equivalent). If you’re on a shared cluster, coordinate with your cluster administrators.
What you’ll learn
  • Why Gateway API matters: differences from Ingress and the problems it solves.
  • Gateway API resource model: GatewayClass, Gateway, and Routes (HTTPRoute, TCPRoute, gRPCRoute), plus the control-plane vs data-plane persona model.
  • NGINX Fabric Gateway as a data plane: installation, configuration, and operational checks.
  • Advanced traffic management: cross-namespace routing, traffic splitting, header-based routing (A/B tests), request/response filters, and zero-downtime canaries.
  • TLS management and secure cross-namespace references using ReferenceGrant.
  • Troubleshooting: interpreting status fields and debugging common errors.
  • Hands-on labs and an assessment to validate your learning.
Core Gateway API resources (at-a-glance) Getting started — quick verification examples
  • Early checks commonly include looking for Route resources and active pods:
Install Gateway API CRDs (from the NGINX Gateway Fabric repo)
  • Apply the required CRDs for Gateway API extensions used by NGINX Fabric Gateway:
Deploy NGINX Fabric Gateway with Helm
  • Example Helm install for NGINX Fabric Gateway using NodePort listeners for ports 80 and 443:
Validate the NGINX Fabric Gateway deployment
  • Check pods and services in the nginx-gateway namespace. Pods may show 0/1 while images download or init jobs run; they should quickly converge to 1/1:
  • Confirm the gateway service exists:
Hands-on labs and example workloads
  • The labs included with this lesson walk through deploying example services (coffee and tea) and configuring Gateway and HTTPRoute resources for routing, traffic splitting, and canary deployments.
TLS, ReferenceGrant, and cross-namespace security
  • You will configure TLS termination on the Gateway, enable HTTPS redirects, and use ReferenceGrant objects to authorize controlled cross-namespace references (for example, allowing a Gateway in namespace A to reference a secret in namespace B). This explicit grant model improves security and auditability.
Troubleshooting and best practices
  • Learn to read and interpret the status fields on Gateway API resources to diagnose issues.
  • Common failure modes include:
    • Gateway controller not reconciling (check controller logs).
    • Route selection mismatches (ensure gatewayRef and selectors match).
    • Secret or ReferenceGrant misconfigurations for TLS (verify ReferenceGrant allows the specific resource kinds and namespaces).
  • Debugging tips:
    • Use kubectl describe on Gateway, GatewayClass, and Routes to inspect conditions.
    • Check controller pod logs for errors or rejected configurations.
    • Use kubectl get events -A to spot API-level errors.
Assessment and next steps
  • The course concludes with an assessment to validate your knowledge and recommended next steps:
    • Explore advanced features like Filters in Routes, BackendTLSPolicies, and policy integration.
    • Read the Gateway API specification and NGINX Fabric Gateway documentation for advanced configuration patterns.
Links and references Community and support
  • At KodeKloud, we foster a hands-on community for questions and learning. Share your configurations, ask for help, and collaborate on real-world Gateway API scenarios.

Watch Video