
How We Migrated from Ingress Nginx to Traefik Ingress Controller
Note: This is a hand-written blog. In this blog, I am going to walk you through how we migrated from the ingress-nginx controller to the Traefik ingress controller. Let’s get started, I will try to keep it concise and short.
Those who don’t know: ingress-nginx is going to retirement , so I am sure the majority of organizations are affected. Before that, I would like to take a moment to thank all the maintainers and contributors who have made public traffic management great over the last 10 years. Everything eventually reaches its end of life, but with every ending comes new innovation and adoption.
Note: The Ingress object is not deprecated, only the ingress-nginx controller is deprecated. Previously, I was thinking about using Envoy Gateway, but since our requirements are mostly fulfilled by the Traefik controller, we decided to move with that.
Problems that we will address:
- How to migrate ingress-based annotations to Traefik-based annotations
- What about ingressClassName?
- Since most folks use cert-manager for TLS configuration, what will the configuration look like for that?
Now, let’s get into them one by one.
First, if you are lucky enough and your ingress only has simple configurations, then the following one step would work:
providers:
kubernetesIngressNginx:
enabled: true
After enabling this in values.yaml, it will support some of your existing ingress nginx configuration
1) Regarding annotations:
These are the supported annotations. If you have annotations from the supported list, you don’t need to change anything.
These are unsupported annotations that need to be converted to Traefik-compatible ones.
2) Traefik also supports the nginxIngressClass: nginx when the above configuration is enabled in the Helm chart, but you could change that annotation to traefik as well. That means supported annotations will still work.
3) The following is the configuration you need to make on the cert-manager side in the ClusterIssuer CR:
solvers:
- http01:
ingress:
ingressClassName: traefik # Should be the same as the ingress object
There are a few annotations that we migrated to Traefik because they are not supported:
nginx.ingress.kubernetes.io/proxy-buffer-size: "128k"
Migrated to:
traefik.ingress.kubernetes.io/buffering-maxRequestBodyBytes: "209715200"
traefik.ingress.kubernetes.io/buffering-maxResponseBodyBytes: "209715200"
traefik.ingress.kubernetes.io/buffering-memRequestBodyBytes: "2097152"
traefik.ingress.kubernetes.io/buffering-memResponseBodyBytes: "2097152"
These two are another set of unsupported annotations that we migrated
nginx.ingress.kubernetes.io/limit-connections: "10"
nginx.ingress.kubernetes.io/limit-rps: "25"
Changed to Middleware CRs:
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: limitrps
spec:
rateLimit:
average: 25
burst: 10
---
apiVersion: traefik.io/v1alpha1
kind: Middleware
metadata:
name: limitconnections
spec:
inFlightReq:
amount: 10
And point this middleware in the ingress annotation:
traefik.ingress.kubernetes.io/router.middlewares: <ns>-<middleware-name>@kubernetescrd, <ns>-<middleware-name>@kubernetescrd
For more info: https://doc.traefik.io/traefik/migrate/nginx-to-traefik/
Conclusion
I think there are a lot of options to consider. More frequently, people will suggest using the Gateway API, and I am not against it , I have even used it in some projects, and we will use it in the future. But if you want a smooth transition, just shift to another controller rather than changing the whole traffic stack. If things can work simply, why take on the overhead