The Kubernetes project retired Ingress NGINX on March 24, 2026.
Kubernetes sourceIngress NGINX retired 2026-03-24
Move traffic without rediscovering hidden behavior in production.
Ingress NGINX no longer receives releases, bug fixes, or security patches. We inventory the behavior your applications depend on, recommend a viable target, and design a cutover with a real rollback path.
Kubernetes warned that available alternatives require planning and engineering time.
Steering statementF5 already maps annotations and produces suggested YAML. We sell accountable risk reduction.
Free analyzerThe real migration surface
The manifest is only the visible layer.
The failure-prone work lives in controller defaults, annotation interactions, raw NGINX snippets, and the traffic behavior your tests may not currently describe.
Rewrites, regex paths, and upstream protocol
Path matching, slash preservation, gRPC, WebSockets, buffering, and body limits can change even when generated YAML looks plausible.
Authentication, TLS, and source identity
External auth subrequests, mTLS, forwarded headers, source-IP trust, and allowlists need end-to-end validation.
Canaries, stickiness, and limits
Traffic splitting, session affinity, rate limits, connection limits, and retry behavior rarely share identical semantics across targets.
Metrics, logs, failure, and rollback
Dashboards and alerts must survive the move. So must the ability to stop a cutover and restore the old path without improvisation.
Fixed migration assessment
Know what can break before choosing the replacement.
This is a bounded assessment, not an open-ended architecture engagement and not paid YAML conversion.
- Controller, annotation, snippet, TCP/UDP, auth, TLS, canary, rate-limit, and observability inventory
- Prioritized behavior and migration risk register
- Target recommendation tied to your actual requirements
- Phased dual-run, validation, cutover, and rollback plan
- Fixed implementation quote with explicit scope
Three founding-client slots
$2,500
Fixed, one-time assessment
The full assessment fee is credited when implementation is booked within 14 days.
Book the assessmentOptional follow-on
Implementation stays scoped and separately priced.
Migration implementation
From $7,500Target configuration, staged dual-run or canary traffic, behavior validation under load, cutover, and a defined rollback window.
Post-migration care
From $1,500/monthOptional monitoring, upgrades, security response, and configuration review with explicit capacity and boundaries.
Start with the assessment
Continue to secure checkout.
Payment confirms the fixed scope. You receive kickoff instructions by email immediately after Stripe confirms the purchase.
What happens next
We contact you within one business day to schedule the kickoff and send a secure inventory checklist.
No kubeconfigs, tokens, private keys, or secrets should be emailed.
assessment -> risk register -> target decision -> cutover plan
Larger or urgent scope
Apply for implementation.
Use this path when you already have budget and a live migration mandate. We qualify fit and timing; target selection and bespoke architecture begin with the paid assessment.
Good fit
A production ingress-nginx deployment, accountable owner, defined timeline, and willingness to stage and validate before cutover.
Not a fit: free migration design, commodity hourly troubleshooting, or a request to choose a controller from a manifest alone.
Before you book
Questions and boundaries.
Is this a YAML conversion service?
No. Free tools can translate many annotations. The paid work identifies behaviors that may not transfer, recommends a target based on your requirements, and defines validation, cutover, and rollback.
Which controller will you migrate us to?
We do not prescribe a controller before inventorying your requirements. The assessment compares the viable targets against your auth, traffic, policy, observability, support, and operational constraints.
What do you need from our clusters?
We begin with controller versions, Helm values, Ingress resources, ConfigMaps, TCP and UDP mappings, and observability configuration. Do not email kubeconfigs, tokens, private keys, or other secrets. We agree on a secure transfer path when needed.
How long does the assessment take?
The schedule is confirmed after the kickoff and inventory review. Most single-team environments should expect a focused assessment, not an open-ended consulting engagement.
What happens after the assessment?
You receive the risk register, target recommendation, cutover and rollback plan, and a fixed implementation quote. If implementation is booked within 14 days, the $2,500 assessment fee is credited against it.