End of life means the project will receive no security patches, bug fixes, or new features. Plan migrations or alternatives well before March 2026.
Immediate recommendations:
- Audit clusters for Ingress-NGINX usage and prioritize high-exposure environments.
- Identify Ingress resources and map them to equivalent Gateway API resources (Gateways, HTTPRoutes, TCPRoutes).
- Evaluate Gateway API–capable controllers from your preferred vendors to minimize disruption.
- Ingress-NGINX historically served a large portion of the Kubernetes ecosystem. According to public guidance, an estimated 40% of clusters used it, increasing the potential blast radius for vulnerabilities.
- On March 24, 2025, the community disclosed several critical vulnerabilities in Ingress-NGINX that could expose Kubernetes secrets and allow attackers to access cluster resources. The community implemented rapid mitigations, but the incident accelerated the move away from legacy Ingress implementations.

- Composable routing primitives (Gateways, HTTPRoutes, TCPRoutes, UDPRoute, etc.) that model complex topologies.
- Better separation of responsibilities: clear roles for infrastructure operators and application owners.
- Improved validation and isolation to reduce configuration-related security risks.
- Vendor neutrality: multiple controllers and vendors support the same Gateway API resources.
Migration considerations
You can migrate from Ingress-NGINX to a Gateway API–capable controller without abandoning your preferred vendor. Popular alternatives and Gateway-capable implementations include HAProxy-based controllers and service meshes like Istio — but moving to another Ingress-only solution won’t provide Gateway API benefits.
Practical next steps
- Inventory: List clusters running Ingress-NGINX and count Ingress resources.
- Prioritize: Rank workloads by exposure and sensitivity (public endpoints, secrets).
- Prototype: Deploy a Gateway API controller in a non-production cluster and translate a sample Ingress to
Gateway+HTTPRoute. - Migrate: Convert Ingress objects incrementally, validate behavior, and roll out progressively.
- Monitor & audit: Ensure observability, RBAC, and policy checks remain functional after migration.

- Gateway API: https://gateway-api.sigs.k8s.io/
- Ingress-NGINX: https://kubernetes.github.io/ingress-nginx/
- Kubernetes Ingress documentation: https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/
- Kubernetes SIG-Network: https://github.com/kubernetes/community/tree/master/sig-network