AWS Load Balancer Controller Ships Kubernetes Gateway API Support

AWS has officially launched General Availability (GA) support for the Kubernetes Gateway API within its Load Balancer Controller, marking a significant advancement in load balancing technology.

3 min readInfoQ
AWS Load Balancer Controller Ships Kubernetes Gateway API Support

AWS just made Kubernetes networking a lot less fragile, and that matters for anyone running production workloads on EKS. The Load Balancer Controller's GA support for the Kubernetes Gateway API replaces the old annotation-based configuration with type-safe Custom Resource Definitions that include proper validation. This is a meaningful step forward, not because annotations were unusable, but because they were error-prone and opaque. When your ingress configuration is a string buried in a YAML annotation, mistakes are hard to catch until traffic breaks. Moving to structured CRDs means the API server can reject invalid configuration before it ever reaches a load balancer.

For teams managing multiple services across namespaces, the cross-namespace routing support is the feature that will change how you design your clusters. Previously, sharing a single ALB across teams required cluster-admin permissions or complex workarounds. Now you can define a Gateway in one namespace and attach HTTPRoutes from other namespaces without escalating privileges. That is a practical win for platform engineering teams who want to give application teams self-service access without handing out the keys to the entire cluster. The role separation baked into the Gateway API spec aligns with how mature organizations actually operate: infrastructure teams own the Gateway, application teams own their Routes.

The automatic certificate discovery through AWS Certificate Manager also removes a common friction point. Instead of manually attaching certificates to each listener or writing custom controllers to watch for certificate rotations, the controller handles that lifecycle automatically. For L4 workloads, the NLB support through the Gateway API means you get the same type-safe configuration for TCP and UDP traffic that you now get for HTTP and gRPC. That consistency across protocol layers reduces the mental overhead of switching between configuration models depending on whether you are routing web traffic or database connections.

What this release does not do is solve every networking problem in Kubernetes. Gateway API is still evolving, and AWS's implementation covers a specific set of features. But the direction is clear: annotation-based configuration is becoming legacy, and structured, validated CRDs are the standard. If you are still managing ingress through annotations, this is the moment to start planning your migration. The tooling is mature enough to adopt today, and the long-term maintenance savings justify the upfront effort.

From InfoQ

AWS shipped GA support for Kubernetes Gateway API in its Load Balancer Controller, dumping annotation-based configuration for type-safe CRDs with proper validation. The release handles both L4 (TCP/UDP via NLB) and L7 (HTTP/gRPC via ALB) routing through the Gateway API spec. Teams get cross-namespace routing, automatic certificate discovery, and role separation without cluster-admin permissions.

Read the original at InfoQ