# Exhaustive Gateway reference (gateway.networking.k8s.io/v1). # A Gateway is the entry door: it owns listener ports/protocols/hostnames and # delegates actual routing to Route objects (HTTPRoute, TCPRoute, ...), which # attach via parentRefs. One Gateway usually fronts many Routes. apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: name: example namespace: example labels: app: example annotations: description: "exhaustive gateway example" spec: # gatewayClassName: which controller implements this Gateway # (kubectl get gatewayclass). The controller only touches Gateways naming # its own class; anything else stays Ignored. gatewayClassName: example-class # addresses: VIPs/hostnames to request for the Gateway. Most controllers # (including cloud LBs) allocate and fill status.addresses automatically; # setting this pins a static IP. Omit for auto-assignment. # addresses: # - type: IPAddress # value: 203.0.113.10 # - type: Hostname # value: lb.example.com # infrastructure: controller-specific settings for the provisioned data # plane (labels/annotations propagated to it). RARE - most setups never # need it. # infrastructure: # labels: # environment: prod # annotations: # example.com/keep: "true" listeners: # Each listener = one port + protocol + optional hostname + TLS + which # Routes may attach. Listener names are referenced by Route parentRefs # via sectionName. - name: http # port: 1-65535. Must be free on the data plane (controllers often # require 80/443 to match their own entrypoints, otherwise the # listener is marked Invalid/Conflicted). port: 80 # protocol: HTTP, HTTPS, TLS, TCP, UDP. protocol: HTTP # hostname: restrict this listener to one DNS name. Omit to accept all # (Routes then narrow via their own hostnames). Listener hostname and # Route hostnames must intersect or the Route is rejected. hostname: app.example.com # allowedRoutes: which Routes may bind here. allowedRoutes: namespaces: # from: Same (only this namespace), All (any namespace), or # Selector (namespaces matching the selector below). from: Same # selector: used only with from: Selector. # selector: # matchLabels: # shared-gateway-access: "true" # kinds: restrict by Route kind. Default allows whatever the # listener protocol supports (HTTPRoute on HTTP, etc.). kinds: - kind: HTTPRoute - name: https port: 443 protocol: HTTPS hostname: app.example.com # tls: termination settings for HTTPS/TLS listeners. tls: # mode: Terminate (decrypt here, default) or Passthrough (forward # encrypted bytes to the backend - the backend holds the key). mode: Terminate # certificateRefs: TLS Secrets (or other kinds) in the SAME namespace # (cross-namespace needs a ReferenceGrant). SNI picks among them. certificateRefs: - name: app-prod-tls # kind/group default to Secret / core. Other kinds (e.g. a # cert-manager Certificate via a plugin) set kind + group. kind: Secret group: "" # options: controller-specific TLS knobs, referenced by name # (cipher suites, min version). RARE. # options: # name: tls-options - name: tcp port: 2222 protocol: TCP allowedRoutes: namespaces: from: Same kinds: - kind: TCPRoute - name: udp port: 3478 protocol: UDP allowedRoutes: namespaces: from: Same kinds: - kind: UDPRoute