gateway-system, while application resources (Services, Secrets, Deployments, Routes) live in separate application namespaces. By default, cross-namespace references are denied — ReferenceGrant is the explicit mechanism to permit them securely.
Learn more about the Gateway API: https://learn.kodekloud.com/user/courses/gateway-api-with-nginx-fabric-gateway
Why ReferenceGrant exists
A Gateway running in one namespace (the source namespace) may need to reference resources (Services, Secrets) in another namespace (the referent namespace). ReferenceGrant makes that access explicit and auditable, preventing accidental or unrestricted cross-namespace references. Common scenario:- Gateway controller and Gateways:
gateway-system - Application Service and TLS Secret:
backendTo allow Gateways ingateway-systemto referenceServiceandSecretobjects inbackend, create a ReferenceGrant in thebackendnamespace.
Important rules and behavior
ReferenceGrant YAML example
Note: Replace theapiVersion with the Gateway API version installed on your cluster (for example gateway.networking.k8s.io/v1beta1 or another supported version).
- The ReferenceGrant resource is created in the
backendnamespace (the namespace containing the Service and Secret). fromidentifies the allowed source type and source namespace (Gateways ingateway-system).tolists the allowed target kinds — hereService(any Service inbackend) and a specificSecretnamedtls-secret.
Always create the ReferenceGrant in the target resource’s namespace (the namespace of the Service/Secret/etc.). Creating it in the gateway namespace will not enable cross-namespace access.
When to use name restrictions
- Allow every Service in
backend: omit thenamefield in thetoentry forService. - Allow only a specific Secret: include the
nameproperty (e.g.tls-secret) for theSecrettoentry. - Use name restrictions to minimize blast radius and follow least-privilege principles.
Quick implementation steps
- Identify the referent namespace that contains the resources to be referenced (e.g.
backend). - Create a ReferenceGrant in that referent namespace.
- In the ReferenceGrant
fromsection, specify the sourcegroup,kind, andnamespace(e.g. Gateways ingateway-system). - In the
tosection, list targetkinds and optional targetnames to restrict access. - Ensure your Gateway controller’s service account has RBAC permissions to read the referenced resources.
Troubleshooting tips
- No effect after creating ReferenceGrant: check that the ReferenceGrant is in the same namespace as the target resource.
- Reference denied with no helpful error: confirm the Gateway API version and the
apiVersionfield in your YAML match the installed Gateway API. - Permission errors when reading resources: verify RBAC rules for the controller’s service account.
Summary
- Cross-namespace references are denied by default in the Gateway API.
- Use ReferenceGrant, created in the referent namespace, to explicitly permit references from specific sources to specific target kinds or names.
- ReferenceGrant enables references but does not replace RBAC — controllers still need appropriate permissions.
- Gateway API course (KodeKloud): https://learn.kodekloud.com/user/courses/gateway-api-with-nginx-fabric-gateway
- Gateway API main docs: https://gateway-api.sigs.k8s.io/