Mary Writes

Get off the never-ending vulnerability piñata that is Ingress NGINX

The Stack

March 19, 2026

"There is no number of maintainers of dedicated engineers that can safely and sanely keep Ingress NGINX online."

Mary Branscombe's avatar
Mary Branscombe
2w

if you're running one of the half of all Kubernetes clusters that's still running Ingress NGINX (I *really* hope that figure has changed already!) then this is the month to get off what @tabbysable.bsky.social memorably describes as a neverending vulnerability piñata because it's officially retiring

NGINX: what happened and where should companies turn next

NGINX: what happened and where should companies turn next

"There is no number of maintainers of dedicated engineers that can safely and sanely keep Ingress NGINX online."


https://www.thestack.technology/ingress-nginx-retires-what-next-gateway-api/
Mary Branscombe's avatar
Mary Branscombe
2w

@strongjz.bsky.social @kat.lol @breakawaybilly.bsky.social Nico Vibert from @isovalent.bsky.social @ofirc.com from Wiz: everyone I talked to said it's time to get off Ingress NGINX. They didn't all agree on what you should use instead, but that Gateway API is clearly the future and why migrate twice

NGINX: what happened and where should companies turn next

NGINX: what happened and where should companies turn next

"There is no number of maintainers of dedicated engineers that can safely and sanely keep Ingress NGINX online."


https://www.thestack.technology/ingress-nginx-retires-what-next-gateway-api/
Mary Branscombe's avatar
Mary Branscombe
2w

I wanted to understand if this was the familiar under-resourced open source project story. in some ways it is: @strongjz.bsky.social was clear about how long Ingress INGINX had been asking for help and not getting long term community support. But the *real* problem is the fragility of annotations

NGINX: what happened and where should companies turn next

NGINX: what happened and where should companies turn next

"There is no number of maintainers of dedicated engineers that can safely and sanely keep Ingress NGINX online."


https://www.thestack.technology/ingress-nginx-retires-what-next-gateway-api/
Mary Branscombe's avatar
Mary Branscombe
2w

those annotations are what will make your migration harder or easier and they're what makes not just Ingress NGINX but the Ingress project itself unsustainable; Gateway API takes a different approach but the community still needs to engage so it covers the breadth of what annotations did, safely

NGINX: what happened and where should companies turn next

NGINX: what happened and where should companies turn next

"There is no number of maintainers of dedicated engineers that can safely and sanely keep Ingress NGINX online."


https://www.thestack.technology/ingress-nginx-retires-what-next-gateway-api/
  • Kubernetes

  • networking

  • migration

  • platform engineering

  • security

  • open source

  • burnout

Subscribe to Mary Writes
to get updates in Reader, RSS, or via Bluesky Feed
Copa: 'The missing piece' for automating patching containers at scale
All my posts about Temporal

The Stack