Kubernetes Announces Retirement of Ingress NGINX by March 2026
The Kubernetes SIG Network and Security Response Committee have officially announced the retirement of Ingress NGINX, a widely used ingress controller for Kubernetes clusters. This decision aims to prioritize ecosystem safety and security, addressing long-standing maintenance challenges and technical debt. Best-effort maintenance will continue until March 2026, after which the project will cease all releases, bug fixes, and security updates. Existing deployments will remain functional, and installation artifacts like Helm charts and container images will stay available for reference, though GitHub repositories will become read-only. The announcement highlights that insufficient maintainer support and evolving security standards, particularly regarding flexible configuration options now deemed vulnerabilities, made the project unsustainable. Users are strongly advised to migrate to alternatives, with the Gateway API recommended as the modern replacement for Ingress. Other community-developed or vendor-specific ingress controllers are also viable options. This move marks a significant shift in Kubernetes networking strategies, urging the community to adopt more secure and maintainable solutions for traffic management within their clusters.
Wire timeline
Kubernetes Announces Retirement of Ingress NGINX by March 2026
The Kubernetes SIG Network and Security Response Committee have officially announced the retirement of Ingress NGINX, a widely used ingress controller for Kubernetes clusters. This decision aims to prioritize ecosystem safety and security, addressing long-standing maintenance challenges and technical debt. Best-effort maintenance will continue until March 2026, after which the project will cease all releases, bug fixes, and security updates. Existing deployments will remain functional, and installation artifacts like Helm charts and container images will stay available for reference, though GitHub repositories will become read-only. The announcement highlights that insufficient maintainer support and evolving security standards, particularly regarding flexible configuration options now deemed vulnerabilities, made the project unsustainable. Users are strongly advised to migrate to alternatives, with the Gateway API recommended as the modern replacement for Ingress. Other community-developed or vendor-specific ingress controllers are also viable options. This move marks a significant shift in Kubernetes networking strategies, urging the community to adopt more secure and maintainable solutions for traffic management within their clusters.
Kubernetes Blog