Ingress-NGINX Retirement

Ingress-NGINX's Retirement and What It Means

Ingress-NGINX 19,459 (github.com/kubernetes/ingress-nginx (https://github.com/kubernetes/ingress-nginx 19,459 )) began as the project's example controller and ran in over 40% of clusters, maintained for years by one or two volunteers. Its flexibility, above all "snippet" annotations that inject raw NGINX 75 configuration, became security debt: CVE-2025-1974 (CVSS 9.8, March 2025) let anything on the Pod network inject configuration through its admission webhook and, since the controller reads every Secret, often take over the cluster.

On 11 November 2025 SIG Network and the Security Response Committee announced its retirement. The last releases, controller v1.15.1 and chart 4.15.1, shipped on 19 March 2026, and the repository is now archived. Existing installations keep working and the images stay downloadable, but there will be no bug or security fixes; the README says not to deploy it anew. F5's NGINX Ingress Controller and NGINX Gateway Fabric 1,169 are separate, maintained projects, so check the image name. The official check, and ingress2gateway (Apache-2.0, from SIG Network), which translates Ingresses and common ingress-nginx annotations into Gateway API objects:

Checking for ingress-nginx and translating an Ingress with ingress2gateway 1.2.0Shell
kubectl get pods -A --selector app.kubernetes.io/name=ingress-nginx
REL=https://github.com/kubernetes-sigs/ingress2gateway/releases/download/v1.2.0
curl -sL $REL/ingress2gateway_Linux_x86_64.tar.gz | sudo tar xz -C /usr/local/bin ingress2gateway
kubectl annotate ingress shop nginx.ingress.kubernetes.io/rewrite-target=/ >/dev/null
ingress2gateway print --providers=ingress-nginx --ingress-nginx-ingress-class=cloud-provider-kind \
  2>/dev/null | yq -N 'select(.kind == "HTTPRoute") | .spec.rules[] |
  .matches[0].path.type + " " + .matches[0].path.value + " + " + .filters[0].type'
Output
No resources found
RegularExpression (?i)/api.* + URLRewrite
RegularExpression (?i)/.* + URLRewrite

With rewrite-target, ingress-nginx silently treated every path, even /, as a case-insensitive regular expression, and the translation says so. Its warnings (on stderr) list what it could not carry over. Test before moving traffic.