Create an Ingress¶
In a Kubernetes cluster, Ingress exposes services from outside the cluster to inside the cluster HTTP and HTTPS ingress. Traffic ingress is controlled by rules defined on the Ingress resource. Here's an example of a simple Ingress that sends all traffic to the same Service:
Ingress is an API object that manages external access to services in the cluster, and the typical access method is HTTP. Ingress can provide load balancing, SSL termination, and name-based virtual hosting.
Prerequisites¶
- Container management module connected to Kubernetes cluster or created Kubernetes, and can access the cluster UI interface.
- Completed a namespace creation, user creation, and authorize the user as NS Editor role, for details, refer to Namespace Authorization.
- Completed Create Ingress Instance, Deploy Application Workload, and have created the corresponding Service
- When there are multiple containers in a single instance, please make sure that the ports used by the containers do not conflict, otherwise the deployment will fail.
Create ingress¶
-
After successfully logging in as the NS Editor user, click Clusters in the upper left corner to enter the Clusters page. In the list of clusters, click a cluster name.

-
In the left navigation bar, click Container Network -> Ingress to enter the service list, and click the Create Ingress button in the upper right corner.

Note
It is also possible to Create from YAML .
-
Open Create Ingress page to configure. There are two protocol types to choose from, refer to the following two parameter tables for configuration.
Create HTTP protocol ingress¶
Enter the following parameters:

| Field | Subfield | Description | Required |
|---|---|---|---|
| Ingress Name | – | Enter the name of the new ingress | Required |
| Namespace | – | Select the namespace where the new service is located. For more information about namespaces, refer to the namespace overview. | Required |
| Set Routing Rules | Domain Name | Use the domain name to provide external access services. The default is the domain name of the cluster. | Required |
| Protocol | Refers to the protocol that authorizes inbound access to the cluster service, and supports HTTP (no identity authentication required) or HTTPS (identity authentication needs to be configured). | Required | |
| Forwarding Policy | Specify the access policy of the Ingress | Optional | |
| Path | Specify the URL path for service access. The default is the root path. | Optional | |
| Target Service | The name of the service to be routed | Required | |
| Target Service Port | The port exposed by the service | Required | |
| Load Balancer Type | Platform-level Load Balancer | In the same cluster, share the same Ingress instance, where all Pods can receive requests distributed by the load balancer | Required |
| Tenant-level Load Balancer | The Ingress instance belongs exclusively to the current namespace, or exclusively to a certain workspace that includes the current namespace, and all Pods can receive distributed requests | Required | |
| Ingress Class | – | Select the corresponding Ingress instance, and after selection, traffic is directed to the specified instance. When it is None, DefaultClass is used | Optional |
| Session Persistence | Session persistence is divided into L4 source address hash / Cookie Key / L7 Header Name. Once enabled, session persistence is performed according to the rules. | Optional | |
| Session Persistence | L4 Source Address Hash | When enabled, by default the following is added to the Annotation: nginx.ingress.kubernetes.io/upstream-hash-by: "$binary_remote_addr" | Optional |
| Cookie Key | When enabled, connections from a specific client will be passed to the same Pod. Default Annotation: nginx.ingress.kubernetes.io/affinity: "cookie" , nginx.ingress.kubernetes.io/affinity-mode: persistent | Optional | |
| L7 Header Name | When enabled, default Annotation: nginx.ingress.kubernetes.io/upstream-hash-by: "$http_x_forwarded_for" | Optional | |
| Path Rewriting | – | rewrite-target, used for URL rewriting when the URL exposed by the backend service differs from the Ingress path | Optional |
| Redirect | – | permanent-redirect, permanent redirection. After entering the rewrite path, access will be redirected to that address | Optional |
| Traffic Distribution | Based on Weight | After setting the weight, Annotation: nginx.ingress.kubernetes.io/canary-weight: "10" | Optional |
| Based on Cookie | After the Cookie rules are set, traffic is distributed according to the Cookie conditions | Optional | |
| Based on Header | After the Header rules are set, traffic is distributed according to the Header conditions | Optional | |
| Labels | – | Add labels to the ingress | Optional |
| Annotations | – | Add annotations to the ingress | Optional |
Create HTTPS protocol ingress¶
Enter the following parameters:

Note
Note: Unlike the Set Routing Rules of the HTTP protocol, you additionally need to select a certificate by secret; other configurations are basically the same.
- Protocol : Required. Refers to the protocol that authorizes inbound access to the cluster service, and supports the HTTP (no identity authentication required) or HTTPS (identity authentication needs to be configured) protocol. Here select the ingress of the HTTPS protocol.
- Secret : Required. HTTPS TLS certificate, Create Secret.
Create ingress successfully¶
After configuring all the parameters, click the OK button to return to the ingress list automatically. On the right side of the list, click ┇ to modify or delete the selected ingress.
