{"id":31173,"date":"2019-10-31T21:39:53","date_gmt":"2019-10-31T18:39:53","guid":{"rendered":"https:\/\/prohoster.info\/blog\/obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes\/"},"modified":"2019-10-31T21:39:53","modified_gmt":"2019-10-31T18:39:53","slug":"obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes","title":{"rendered":"Overview and Comparison of Ingress Controllers for Kubernetes","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"Overview and Comparison of Ingress Controllers for Kubernetes\" src=\"\/wp-content\/uploads\/2019\/04\/3e6d3882a8f5a96a257fab4daaa230f2.png\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nWhen launching a Kubernetes cluster for a specific application, it is important to understand the requirements imposed on this resource by the application itself, the business, and the developers. With this information in hand, one can proceed to make architectural decisions and, in particular, choose a specific Ingress controller, of which there are already many today. To provide a basic understanding of the available options without having to sift through numerous articles\/documentation, we have prepared this overview, including the main (production-ready) Ingress controllers.<\/p>\n<p>We hope this will assist colleagues in making architectural decisions \u2014 at the very least, it will serve as a starting point for obtaining more detailed information and practical experiments. Preliminary research of similar materials online revealed, surprisingly, that there wasn't a single reasonably complete, and most importantly \u2014 structured \u2014 overview. Thus, let's fill this gap!<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Criteria<\/h2>\n<p>\nTo effectively compare and obtain any useful results, it\u2019s necessary to understand not just the subject area but also to have a specific list of criteria that will guide the research direction. Without claiming to analyze all possible use cases of Ingress\/Kubernetes, we have tried to highlight the most common requirements for controllers \u2014 be prepared that the specifics will still need to be researched separately.<\/p>\n<p>But I'll start with the characteristics that have become so commonplace that they are implemented in all solutions and are not debated:<\/p>\n<ul>\n<li> dynamic service discovery;<\/li>\n<li> SSL termination;<\/li>\n<li> working with websockets.<\/li>\n<\/ul>\n<p>\nNow, about the comparison points:<\/p>\n<h3>Supported Protocols<\/h3>\n<p>\nOne of the fundamental criteria for selection. Your software may not operate over standard HTTP or may require operation over multiple protocols simultaneously. If your case is non-standard, be sure to factor this in to avoid having to reconfigure the cluster later. The list of supported protocols varies among all controllers.<\/p>\n<h3>Software at its core<\/h3>\n<p>\nThere are several application options on which the controller is based. Popular ones include nginx, traefik, haproxy, and envoy. Generally, it may not significantly affect how traffic is received and transmitted, but it is always useful to know the potential nuances and characteristics of what is \"under the hood.\"<\/p>\n<h3>Traffic Routing<\/h3>\n<p>\nWhat factors can be used to decide the direction of traffic to a particular service? Generally, this is based on host and path, but there can also be additional options.<\/p>\n<h3>Namespace within a Cluster<\/h3>\n<p>\nA namespace is a way to logically divide resources in Kubernetes (for example, into stage, production, etc.). There are Ingress controllers that need to be installed separately in each namespace (and then it can route traffic <i>only<\/i> in the pods of this namespace). There are those (and they are a clear majority) that work globally across the entire cluster \u2014 in them, traffic is directed to any pod in the cluster, regardless of the namespace.<\/p>\n<h3>Samples for upstreams<\/h3>\n<p>\nHow is traffic directed to healthy instances of applications and services? There are options with active and passive checks, retries, circuit breakers <i>(for more details, see, for example, the <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/438426\/\">article about Istio<\/a><\/noindex>)<\/i>, custom health checks, etc. This is a crucial parameter if you have high availability requirements and timely removal of failed services from load balancing.<\/p>\n<h3>Load Balancing Algorithms<\/h3>\n<p>\nThere are many options here: from traditional <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Round-robin_DNS\">round-robin<\/a><\/noindex> to exotic ones like <noindex><a rel=\"nofollow\" href=\"http:\/\/www.loadbalancer.org\/blog\/load-balancing-windows-terminal-server-haproxy-and-rdp-cookies\/\">rdp-cookie<\/a><\/noindex>, as well as separate options like <noindex><a rel=\"nofollow\" href=\"https:\/\/access.redhat.com\/solutions\/900933\">sticky sessions<\/a><\/noindex>.<\/p>\n<h3>Authentication<\/h3>\n<p>\nWhat authorization schemes does the controller support? Basic, digest, oauth, external-auth \u2014 I believe these options should be familiar. This is an important criterion if multiple environments for developers (and\/or simply closed ones) are used, with access provided through Ingress. <\/p>\n<h3>Traffic Distribution<\/h3>\n<p>\nDoes the controller support commonly used mechanisms for traffic distribution, such as canary releases, A\/B testing, and traffic mirroring\/shadowing? This is a genuinely sensitive topic for applications that require careful and precise traffic management for production testing, debugging product errors without live traffic (or with minimal losses), traffic analysis, etc.<\/p>\n<h3>Paid subscription<\/h3>\n<p>\nIs there a paid option for the controller with enhanced functionalities and\/or technical support?<\/p>\n<h3>Graphical interface (Web UI)<\/h3>\n<p>\nIs there any graphical interface for managing the controller's configuration? Primarily for convenience and\/or for those who need to make changes to the Ingress configuration, as working with 'raw' templates can be cumbersome. It may be useful if developers want to experiment with traffic on the fly.<\/p>\n<h3>JWT validation<\/h3>\n<p>\nThe presence of built-in validation for JSON web tokens for authorization and user validation in the end application.<\/p>\n<h3>Customization options for the config<\/h3>\n<p>\nExtendability of templates in terms of having mechanisms that allow the addition of custom directives, flags, etc. to standard configuration templates.<\/p>\n<h3>Basic DDoS protection mechanisms<\/h3>\n<p>\nSimple rate limit algorithms or more complex options for filtering traffic based on addresses, whitelists, countries, etc.<\/p>\n<h3>Request tracing<\/h3>\n<p>\nMonitoring, tracking, and debugging requests from Ingresses to specific services\/pods, and ideally \u2014 between services\/pods as well.<\/p>\n<h3>WAF<\/h3>\n<p>\nSupport <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/Web_application_firewall\">application firewall<\/a><\/noindex>.<\/p>\n<h2>Ingress controllers<\/h2>\n<p>\nThe list of controllers was formed based on <noindex><a rel=\"nofollow\" href=\"https:\/\/kubernetes.io\/docs\/concepts\/services-networking\/ingress-controllers\/#additional-controllers\">the official Kubernetes documentation<\/a><\/noindex> and <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.google.com\/spreadsheets\/d\/16bxRgpO1H_Bn-5xVZ1WrR_I-0A-GOI6egmhvqqLMOmg\/edit\">this table<\/a><\/noindex>. Some of them were excluded from the review due to their specificity or low prevalence (early development stage). The remaining ones are discussed below. We will start with a general description of the solutions and continue with a summary table.<\/p>\n<h3>Kubernetes Ingress<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/kubernetes\/ingress-nginx\">github.com\/kubernetes\/ingress-nginx<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>This is the official controller for Kubernetes, developed by the community. As the name suggests, it is based on nginx and is enhanced with a variety of Lua plugins used to implement additional features. Due to the popularity of nginx itself and minimal modifications made when used as a controller, this option may be the simplest and most understandable for the average engineer (with web experience).<\/p>\n<h3>NGINX Inc Ingress<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nginxinc\/kubernetes-ingress\">github.com\/nginxinc\/kubernetes-ingress<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>An official product from the nginx developers. It has a paid version based on <noindex><a rel=\"nofollow\" href=\"https:\/\/www.nginx.com\/products\/nginx\/\">NGINX Plus<\/a><\/noindex>The main idea is a high level of stability, constant backward compatibility, absence of any external modules, and a declared increased speed (compared to the official controller), achieved by eliminating Lua. <\/p>\n<p>The free version is significantly limited, especially when compared to the official controller (due to the lack of those same Lua modules). The paid version, however, has a fairly wide range of additional features: real-time metrics, JWT validation, active health checks, and more. An important advantage over NGINX Ingress is full support for TCP\/UDP traffic (even in the community version!). The downside is that <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nginxinc\/kubernetes-ingress\/issues\/464\">the absence of<\/a><\/noindex> features for traffic distribution, which, however, \"has the highest priority for developers\", but requires time for implementation.<\/p>\n<h3>Kong Ingress<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/Kong\/kubernetes-ingress-controller\">github.com\/Kong\/kubernetes-ingress-controller<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>A product developed by Kong Inc. in two versions: commercial and free. Based on nginx, whose capabilities are extended by a large number of Lua modules.<\/p>\n<p>Initially aimed at processing and routing API requests, i.e., as an API Gateway, it has now become a full-fledged Ingress controller. Its main advantages include a multitude of additional modules (including those from third-party developers) that are easy to install and configure, and through which a wide range of additional capabilities can be implemented. However, the built-in functions already offer many features. Configuration is performed using CRD resources.<\/p>\n<p>An important feature of the product is that operating within a single context (instead of cross-namespaced) is a contentious topic: some may see it as a drawback (as it requires creating entities for each context), while others may view it as a feature (providing a<i>higher level of isolation, as if one controller is broken, the problem is confined to that specific context).<\/i>Traefik<\/p>\n<h3>github.com\/containous\/traefik<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/containous\/traefik\">License: MIT<\/a><\/noindex><\/i><br \/>\n<i>License: MIT<\/i><\/p>\n<p>A proxy that was initially designed to handle request routing for microservices and their dynamic environment. Hence many useful features: configuration updates without restarts, support for a wide range of load balancing methods, a web interface, metric forwarding, support for various protocols, REST API, canary releases, and much more. A nice feature is also the out-of-the-box support for Let\u2019s Encrypt certificates. A drawback is that to ensure high availability (HA), the controller will require its own KV storage to be installed and connected.<\/p>\n<h3>HAProxy<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/jcmoraisjr\/haproxy-ingress\">github.com\/jcmoraisjr\/haproxy-ingress<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>HAProxy has long been known as a proxy and traffic balancer. Within the Kubernetes cluster, it offers 'soft' configuration updates (without traffic loss), DNS-based service discovery, and dynamic configuration via API. A full customization of the config template using CM replacement can be appealing, as well as the ability to utilize functions from the Sprig library. Overall, the main focus of the solution is on high performance, its optimization, and efficiency in resource consumption. The controller's advantage is the support for a record number of different load balancing methods.<\/p>\n<h3>Voyager<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/appscode\/voyager\">github.com\/appscode\/voyager<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>A controller based on HAProxy that is positioned as a universal solution supporting wide capabilities across many providers. It offers the ability to balance traffic at L7 and L4, with L4 TCP traffic balancing being one of the key features of the solution.<\/p>\n<h3>Contour<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/heptio\/contour\">github.com\/heptio\/contour<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>This solution is not only based on Envoy: it is developed <i>in collaboration<\/i> with the creators of this popular proxy. An important feature is the ability to separate Ingress resource management through CRD resources IngressRoute. For organizations with multiple development teams using a single cluster, this helps to maximize traffic handling safety in adjacent contours and protects against errors when modifying Ingress resources.<\/p>\n<p>An extended set of load balancing methods is also offered (including request mirroring, auto-retries, request rate limiting and much more), detailed monitoring of traffic flow and failures. Perhaps, for some, the lack of support for sticky sessions will be a significant drawback (although it works... <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/heptio\/contour\/issues\/361\">is already underway<\/a><\/noindex>).<\/p>\n<h3>Istio Ingress<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/istio.io\/docs\/tasks\/traffic-management\/ingress\/\">istio.io\/docs\/tasks\/traffic-management\/ingress<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>A comprehensive service mesh solution that not only acts as an Ingress controller managing incoming external traffic, but also controls all traffic within the cluster. Under the hood, an Envoy sidecar proxy is used for each service. Essentially, it's a powerful tool that \"can do it all,\" with its main idea being maximum manageability, scalability, security, and transparency. With it, you can finely tune traffic routing, service access authorization, load balancing, monitoring, canary releases, and much more. More about Istio can be found in a series of articles titled \"<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/438426\/\">Back to Microservices with Istio<\/a><\/noindex>\u00bb.<\/p>\n<h3>Ambassador<\/h3>\n<p>\n<i>Website: <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/datawire\/ambassador\">github.com\/datawire\/ambassador<\/a><\/noindex><\/i><br \/>\n<i>License: Apache 2.0<\/i><\/p>\n<p>Another Envoy-based solution. It has both free and commercial versions. It is marketed as \"fully native to Kubernetes,\" bringing the corresponding benefits (tight integration with the methods and entities of the K8s cluster).<\/p>\n<h2>Comparison Table<\/h2>\n<p>\nSo, the culmination of this article is this huge table:<\/p>\n<p><noindex><a rel=\"nofollow\" href=\"https:\/\/habrastorage.org\/webt\/ss\/wh\/lj\/sswhljo-rjkms7nadtyewqkxrdi.png\"><img decoding=\"async\" alt=\"Overview and Comparison of Ingress Controllers for Kubernetes\" src=\"\/wp-content\/uploads\/2019\/04\/3a6c552df6b8b7b6a88517046fa7a275.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/p>\n<p>It is clickable for detailed viewing and is also available in <noindex><a rel=\"nofollow\" href=\"https:\/\/docs.google.com\/spreadsheets\/d\/1xjff2AMS6QXSdh8E8ay_uNMoUa2OLIanCallvkDvAy0\/edit#gid=0\">Google Sheets<\/a><\/noindex>.<\/p>\n<h2>In Summary<\/h2>\n<p>\nThe goal of this article is to provide a more complete understanding (though certainly not exhaustive!) of what choice to make in your specific case. As is often the case, each controller has its advantages and disadvantages...<\/p>\n<p>The classic Ingress from Kubernetes is known for its availability and reliability, offering quite rich options \u2014 in most cases, it should be more than sufficient. However, if there are higher demands for stability, feature levels, and development, consider Ingress with NGINX Plus and a paid subscription. Kong has a rich set of plugins (and, accordingly, the capabilities they provide), with even more in the paid version. It has extensive capabilities for functioning as an API Gateway, dynamic configuration based on CRD resources, and basic Kubernetes services.<\/p>\n<p>If you have increased requirements for load balancing and authorization methods, take a look at Traefik and HAProxy. These are Open Source projects, proven over the years, very stable, and actively evolving. Contour has been around for a couple of years now, but still appears too young and has only basic capabilities added on top of Envoy. If there's a need for a WAF in front of the application, consider using Ingress from Kubernetes or HAProxy.<\/p>\n<p>The most feature-rich products are those built on Envoy, particularly Istio. It presents a comprehensive solution that can do 'everything', which, however, translates to a significantly higher entry threshold for configuration, deployment, and administration compared to other solutions.<\/p>\n<p>We have chosen the Ingress from Kubernetes as our standard controller, which still meets 80\u201390% of our needs. It is quite reliable, easy to configure, and extend. In general, in the absence of specific requirements, it should suit most clusters\/applications. Other universal and relatively simple products that can be recommended include Traefik and HAProxy.<\/p>\n<h2>P.S.<\/h2>\n<p>\nAlso read in our blog:<\/p>\n<ul>\n<li> \"Back to Microservices with Istio\": <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/438426\/\">Part 1 (Getting to Know the Main Features)<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/440378\/\">Part 2 (Routing, Traffic Management)<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/443668\/\">Part 3 (Authentication and Authorization)<\/a><\/noindex>;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/445596\/\">Kubernetes tips &amp; tricks: Personalized Error Pages in NGINX Ingress<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/427745\/\">Kubernetes tips &amp; tricks: Access to Dev Environments<\/a><\/noindex>\u00bb.<\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/447180\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 Kubernetes \u0434\u043b\u044f \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f \u0441\u043b\u0435\u0434\u0443\u0435\u0442 \u043f\u043e\u043d\u0438\u043c\u0430\u0442\u044c, \u043a\u0430\u043a\u0438\u0435 \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u0442 \u043a \u044d\u0442\u043e\u043c\u0443 \u0440\u0435\u0441\u0443\u0440\u0441\u0443 \u0441\u0430\u043c\u043e \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u0435, \u0431\u0438\u0437\u043d\u0435\u0441 \u0438 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438. \u041f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u044d\u0442\u043e\u0439 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u0438 \u043c\u043e\u0436\u043d\u043e \u043f\u0440\u0438\u0441\u0442\u0443\u043f\u0430\u0442\u044c \u043a \u043f\u0440\u0438\u043d\u044f\u0442\u0438\u044e \u0430\u0440\u0445\u0438\u0442\u0435\u043a\u0442\u0443\u0440\u043d\u043e\u0433\u043e \u0440\u0435\u0448\u0435\u043d\u0438\u044f \u0438, \u0432 \u0447\u0430\u0441\u0442\u043d\u043e\u0441\u0442\u0438, \u043a \u0432\u044b\u0431\u043e\u0440\u0443 \u043a\u043e\u043d\u043a\u0440\u0435\u0442\u043d\u043e\u0433\u043e Ingress-\u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430, \u043a\u043e\u0438\u0445 \u043d\u0430 \u0441\u0435\u0433\u043e\u0434\u043d\u044f\u0448\u043d\u0438\u0439 \u0434\u0435\u043d\u044c \u0443\u0436\u0435 \u0431\u043e\u043b\u044c\u0448\u043e\u0435 \u043a\u043e\u043b\u0438\u0447\u0435\u0441\u0442\u0432\u043e. \u0427\u0442\u043e\u0431\u044b \u0441\u043e\u0441\u0442\u0430\u0432\u0438\u0442\u044c \u0431\u0430\u0437\u043e\u0432\u043e\u0435 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d\u0438\u0435 \u043e\u0431 \u0438\u043c\u0435\u044e\u0449\u0438\u0445\u0441\u044f \u0432\u0430\u0440\u0438\u0430\u043d\u0442\u0430\u0445 \u0431\u0435\u0437 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u0438 \u0438\u0437\u0443\u0447\u0430\u0442\u044c \u043c\u043d\u043e\u0436\u0435\u0441\u0442\u0432\u043e [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":23140,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-31173","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 Kubernetes \u0434\u043b\u044f.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041e\u0431\u0437\u043e\u0440 \u0438 \u0441\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u043e\u0432 Ingress \u0434\u043b\u044f Kubernetes | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 Kubernetes \u0434\u043b\u044f.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:39:53+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:39:53+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Overview and Comparison of Ingress Controllers for Kubernetes | ProHoster","description":"When launching a Kubernetes cluster for.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041e\u0431\u0437\u043e\u0440 \u0438 \u0441\u0440\u0430\u0432\u043d\u0435\u043d\u0438\u0435 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u043e\u0432 Ingress \u0434\u043b\u044f Kubernetes | ProHoster","og:description":"\u041f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043b\u0430\u0441\u0442\u0435\u0440\u0430 Kubernetes \u0434\u043b\u044f.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/obzor-i-sravnenie-kontrollerov-ingress-dlya-kubernetes","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:39:53+00:00","article:modified_time":"2019-10-31T18:39:53+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"31173","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 04:53:04","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 03:21:32","updated":"2026-01-21 04:53:04","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31173","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=31173"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/31173\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/23140"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=31173"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=31173"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=31173"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}