Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

Coursera

Gateway API with NGINX Fabric Gateway

KodeKloud via Coursera

Overview

Google, IBM & Meta Certificates – 40% Off
One plan covers every Professional Certificate on Coursera.
Unlock All Certificates
Replace legacy Ingress with modern, production-ready traffic management using NGINX Gateway Fabric. Kubernetes Ingress is on its way out. With NGINX Ingress reaching End-of-Life and the IngressNightmare CVE exposing critical vulnerabilities in legacy approaches, organizations are actively migrating to the Kubernetes Gateway API — a more expressive, extensible, and secure model for managing cluster traffic. This course gives you the hands-on skills to lead that migration. You'll start by understanding exactly why Ingress is being deprecated, how Gateway API's role-oriented architecture separates responsibilities across infrastructure providers, cluster operators, and application developers, and how to deploy your first Gateway using NGINX Gateway Fabric. From there, you'll work through the core Gateway API resources — GatewayClass, Gateway, and HTTPRoute — before moving into advanced traffic management: cross-namespace routing, weight-based traffic splitting for canary deployments, header-based routing for A/B testing, and request and response filters for in-flight traffic manipulation. The course then covers TLS termination, HTTP-to-HTTPS redirect enforcement, and cross-namespace security using ReferenceGrant. The final module focuses on production observability — interpreting Gateway API status conditions, diagnosing common failure scenarios with kubectl, and applying production migration blueprints for safe DNS cutover from legacy Ingress. Who this is for: Kubernetes engineers, platform architects, DevOps engineers, and cloud-native developers responsible for managing cluster networking or migrating away from legacy NGINX Ingress controllers.

Syllabus

  • Introduction & Why Gateway API
    • This module establishes the critical context behind the industry-wide shift from legacy Kubernetes Ingress to the modern Gateway API standard. It explores the operational urgency surrounding the NGINX Ingress deprecation crisis (including its March 2026 End-of-Life and the severe IngressNightmare CVE). Students will be introduced to the Gateway API's decoupled architecture and its role-oriented persona model (Infrastructure Provider, Cluster Operator, and Application Developer). Finally, students will get hands-on experience by deploying their very first working Gateway path using the NGINX Gateway Fabric.
  • Core Gateway API Resources
    • This module performs a deep dive into the foundational building blocks of the Gateway API specification. Students will explore how the GatewayClass resource handles infrastructure provider selection, how the Gateway resource defines entry-point listeners and allowed routing parameters, and how HTTPRoute structures path matches and backend routing definitions. The module culminates in a practical lab where students configure path-based routing for a multi-service application (e.g., coffee/tea services).
  • Advanced Traffic Management
    • This module covers advanced traffic engineering capabilities native to the Gateway API. Students will master cross-namespace routing patterns, weight-based traffic splitting for zero-downtime canary deployments, and HTTP header/method/query parameter matching for A/B testing. Additionally, the module explores built-in request and response filters, enabling advanced operations such as header manipulation, URL rewriting, and live traffic mirroring.
  • TLS and Cross-Namespace Security
    • Security at the cluster edge is critical. This module teaches students how to configure secure HTTPS communication via edge TLS termination, manage certificate secrets, and enforce automated HTTP-to-HTTPS redirects. Crucially, it highlights cross-namespace security mechanics, focusing on how the ReferenceGrant resource is used to safely establish trust and permit secure routing attachments across distinct administrative and namespace boundaries.
  • Troubleshooting and Best Practices
    • Moving workloads to production demands deep observability and structured debugging skills. This module focuses on leveraging the Gateway API's expressive status fields and conditions (Accepted, Programmed, Resolved Refs) to monitor health and diagnose issues. Students will analyze common failure modes (such as unattached routes, TLS handshake issues, and misconfigured weights) through an intensive troubleshooting lab, concluding with real-world migration blueprints, parallel execution strategies, and DNS cutover planning.

Taught by

Mumshad Mannambeth

Reviews

Start your review of Gateway API with NGINX Fabric Gateway

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.