nginx-ingress is the default choice. Traefik offers the same ingress capabilities with auto-discovery, a built-in dashboard, and middleware chains — all configurable through Kubernetes CRDs.
Installation
helm install traefik traefik/traefik \
--namespace traefik --create-namespace \
--set dashboard.enabled=true \
--set providers.kubernetesIngress.enabled=true \
--set providers.kubernetesCRD.enabled=trueBasic Routing
Standard Ingress
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: order-api
annotations:
traefik.ingress.kubernetes.io/router.entrypoints: websecure
traefik.ingress.kubernetes.io/router.tls: "true"
spec:
rules:
- host: api.myorg.com
http:
paths:
- path: /orders
pathType: Prefix
backend:
service:
name: order-api
port:
number: 8080
- path: /payments
pathType: Prefix
backend:
service:
name: payment-api
port:
number: 8080IngressRoute (Traefik CRD)
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: order-api
spec:
entryPoints:
- websecure
routes:
- match: Host(`api.myorg.com`) && PathPrefix(`/orders`)
kind: Rule
services:
- name: order-api
port: 8080
- match: Host(`api.myorg.com`) && PathPrefix(`/payments`)
kind: Rule
services:
- name: payment-api
port: 8080
tls:
certResolver: letsencryptIngressRoutes provide more expressive matching: headers, query parameters, and boolean combinations.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →TLS with Let's Encrypt
# Helm values
additionalArguments:
- --certificatesresolvers.letsencrypt.acme.email=admin@myorg.com
- --certificatesresolvers.letsencrypt.acme.storage=/data/acme.json
- --certificatesresolvers.letsencrypt.acme.httpchallenge.entrypoint=webTraefik automatically obtains and renews TLS certificates. No cert-manager needed for basic setups.
Middlewares
Chain processing steps before reaching the backend:
Rate Limiting
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: rate-limit
spec:
rateLimit:
average: 100
burst: 200
period: 1mBasic Auth
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: basic-auth
spec:
basicAuth:
secret: auth-secretStrip Path Prefix
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: strip-api
spec:
stripPrefix:
prefixes:
- /apiHeaders
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: security-headers
spec:
headers:
stsSeconds: 31536000
stsIncludeSubdomains: true
contentTypeNosniff: true
frameDeny: true
browserXssFilter: trueChain Middlewares
apiVersion: traefik.io/v1alpha1
kind: IngressRoute
metadata:
name: api
spec:
routes:
- match: Host(`api.myorg.com`)
kind: Rule
middlewares:
- name: rate-limit
- name: security-headers
- name: strip-api
services:
- name: order-api
port: 8080Requests flow through rate limiting → security headers → path stripping → backend.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Weighted Routing (Canary)
apiVersion: traefik.io/v1alpha1
kind: TraefikService
metadata:
name: order-api-canary
spec:
weighted:
services:
- name: order-api-v1
port: 8080
weight: 90
- name: order-api-v2
port: 8080
weight: 1010% of traffic goes to v2. Increase weight as confidence grows.
Dashboard
# Port-forward the dashboard
kubectl port-forward -n traefik svc/traefik 9000:9000
# Open http://localhost:9000/dashboard/The dashboard shows all routers, services, middlewares, and their health status in real time.
Traefik vs nginx-ingress
| Feature | Traefik | nginx-ingress |
|---|---|---|
| Config reload | Hot reload (no downtime) | Reload nginx process |
| Auto-discovery | Built-in | Manual |
| Dashboard | Built-in | Separate |
| CRD support | IngressRoute | Custom annotations |
| Canary routing | WeightedService | Annotations |
| Built-in TLS | ACME/Let's Encrypt | Needs cert-manager |
| TCP/UDP | Yes | Yes |
| Performance | Good | Slightly better |
Both work well. Traefik is easier to configure. nginx-ingress has marginally better raw performance at very high scale.
---
Ready to go deeper? Master Kubernetes networking with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Kubernetes Services and Ingress
Expose Kubernetes workloads with ClusterIP, NodePort, LoadBalancer services and Ingress controllers. Practical examples.
Kubernetes Ingress Controllers Guide
Configure Kubernetes Ingress for HTTP routing. Nginx controller setup, TLS termination, path-based routing, and rate limiting.
Cilium Service Mesh Kubernetes
Cilium replaces kube-proxy and sidecar service meshes with eBPF. Learn how Cilium handles networking, observability, and security in Kubernetes.
Trivy Container Vulnerability Scanner
Trivy scans container images, filesystems, and IaC for vulnerabilities and misconfigurations. Learn how to integrate Trivy into your CI/CD pipeline.
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
Troubleshoot SELinux AVC Denials
Learn to read SELinux AVC denial logs, use ausearch and sealert, and follow a systematic troubleshooting workflow for RHEL systems.
Explore topics
Browse more articles on the topics covered here.