A GatewayClass is cluster-scoped and names a controller, like an IngressClass. A Gateway asks that controller for an entry point with listeners (port, protocol, optional hostname and TLS). A Route attaches to a Gateway through parentRefs and maps matches to backendRefs. BookNest gets one Gateway with HTTP and HTTPS listeners, and one HTTPRoute:
apiVersion: gateway.networking.k8s.io/v1
kind: Gateway
metadata: { name: booknest, labels: { app: booknest } }
spec:
gatewayClassName: cloud-provider-kind
listeners:
- { name: http, protocol: HTTP, port: 80, hostname: books.example.com }
- name: https
protocol: HTTPS
port: 443
hostname: books.example.com
tls: { mode: Terminate, certificateRefs: [{ name: books-tls }] }
---
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata: { name: booknest, labels: { app: booknest } }
spec:
parentRefs: [{ name: booknest }]
hostnames: [books.example.com]
rules:
- matches:
- path: { type: PathPrefix, value: /api }
- path: { type: Exact, value: /version }
backendRefs: [{ name: api, port: 3000 }]
- backendRefs: [{ name: web, port: 80 }]A rule's matches are ORed, and a rule with none matches everything. The controller reports in status: the Gateway's Accepted and Programmed conditions and address, and the Route's Accepted and ResolvedRefs per parent, the first place to look when traffic does not arrive. Routes from other namespaces attach only if the listener's allowedRoutes permits, and a backendRef into another namespace needs a ReferenceGrant there.