Skip to main content

Ingress NGINX retired 2026-03-24

Move traffic without rediscovering hidden behavior in production.

Ingress NGINX no longer receives releases, bug fixes, or security patches. We inventory the behavior your applications depend on, recommend a viable target, and design a cutover with a real rollback path.

Current controller Ingress NGINX v1.15.1 Final release. No future patches.
annotations snippets auth + TLS TCP / UDP canaries rate limits observability rollback
Target controller Selected after inventory Gateway API or another controller that fits the actual constraints.
Retired

The Kubernetes project retired Ingress NGINX on March 24, 2026.

Kubernetes source
No drop-in target

Kubernetes warned that available alternatives require planning and engineering time.

Steering statement
Translation is free

F5 already maps annotations and produces suggested YAML. We sell accountable risk reduction.

Free analyzer

The real migration surface

The manifest is only the visible layer.

The failure-prone work lives in controller defaults, annotation interactions, raw NGINX snippets, and the traffic behavior your tests may not currently describe.

RISK 01 / REQUEST PATH

Rewrites, regex paths, and upstream protocol

Path matching, slash preservation, gRPC, WebSockets, buffering, and body limits can change even when generated YAML looks plausible.

RISK 02 / POLICY

Authentication, TLS, and source identity

External auth subrequests, mTLS, forwarded headers, source-IP trust, and allowlists need end-to-end validation.

RISK 03 / TRAFFIC CONTROL

Canaries, stickiness, and limits

Traffic splitting, session affinity, rate limits, connection limits, and retry behavior rarely share identical semantics across targets.

RISK 04 / OPERATIONS

Metrics, logs, failure, and rollback

Dashboards and alerts must survive the move. So must the ability to stop a cutover and restore the old path without improvisation.

Fixed migration assessment

Know what can break before choosing the replacement.

This is a bounded assessment, not an open-ended architecture engagement and not paid YAML conversion.

  • Controller, annotation, snippet, TCP/UDP, auth, TLS, canary, rate-limit, and observability inventory
  • Prioritized behavior and migration risk register
  • Target recommendation tied to your actual requirements
  • Phased dual-run, validation, cutover, and rollback plan
  • Fixed implementation quote with explicit scope

Three founding-client slots

$2,500

Fixed, one-time assessment

The full assessment fee is credited when implementation is booked within 14 days.

Book the assessment

Optional follow-on

Implementation stays scoped and separately priced.

Migration implementation

From $7,500

Target configuration, staged dual-run or canary traffic, behavior validation under load, cutover, and a defined rollback window.

Post-migration care

From $1,500/month

Optional monitoring, upgrades, security response, and configuration review with explicit capacity and boundaries.

Start with the assessment

Continue to secure checkout.

Payment confirms the fixed scope. You receive kickoff instructions by email immediately after Stripe confirms the purchase.

What happens next

We contact you within one business day to schedule the kickoff and send a secure inventory checklist.

No kubeconfigs, tokens, private keys, or secrets should be emailed.

assessment -> risk register -> target decision -> cutover plan

Larger or urgent scope

Apply for implementation.

Use this path when you already have budget and a live migration mandate. We qualify fit and timing; target selection and bespoke architecture begin with the paid assessment.

Good fit

A production ingress-nginx deployment, accountable owner, defined timeline, and willingness to stage and validate before cutover.

Not a fit: free migration design, commodity hourly troubleshooting, or a request to choose a controller from a manifest alone.

Before you book

Questions and boundaries.

Is this a YAML conversion service?

No. Free tools can translate many annotations. The paid work identifies behaviors that may not transfer, recommends a target based on your requirements, and defines validation, cutover, and rollback.

Which controller will you migrate us to?

We do not prescribe a controller before inventorying your requirements. The assessment compares the viable targets against your auth, traffic, policy, observability, support, and operational constraints.

What do you need from our clusters?

We begin with controller versions, Helm values, Ingress resources, ConfigMaps, TCP and UDP mappings, and observability configuration. Do not email kubeconfigs, tokens, private keys, or other secrets. We agree on a secure transfer path when needed.

How long does the assessment take?

The schedule is confirmed after the kickoff and inventory review. Most single-team environments should expect a focused assessment, not an open-ended consulting engagement.

What happens after the assessment?

You receive the risk register, target recommendation, cutover and rollback plan, and a fixed implementation quote. If implementation is booked within 14 days, the $2,500 assessment fee is credited against it.