Networking
Load balancing
27 / 69

The controller turns Ingress, Service and Gateway objects into real AWS load balancers.

It is installed as an add-on or Helm chart and uses Pod Identity or IRSA to call AWS APIs.

Ingress or Serviceyou apply YAMLLB Controllerwatches, calls AWS APIsALBHTTP, HTTPS, gRPC, L7 rulesNLBTCP, UDP, TLS, L4, static IPsIP target mode: straight to Pod IPs(instance mode goes via NodePort)

IP target mode

Skips the extra node hop, keeps client IPs and balances per Pod. Works because Pods have VPC IPs. Preferred over instance mode.

Pod readiness gates

Label the namespace elbv2.k8s.aws/pod-readiness-gate-inject: enabled so rollouts wait for targets to be healthy and avoid dropped requests.

Share load balancers

Use IngressGroups to put many Ingresses behind one ALB. One ALB per Service gets expensive.