M3 · Gateway and ingress
Worked example
21 / 61

One HTTPS listener can route checkout and catalog by path

The platform Gateway accepts shopwave.example on 443. The application HTTPRoute sends /checkout and /catalog to separate Services.

Gateway listener

HTTPS on 443 with an allowed route namespace policy.

Certificate map

Certificate Manager supplies the frontend certificate through GKE policy integration.

HTTPRoute rules

PathPrefix matches keep application routing readable and versioned.

Backends

Services expose ports; NEGs keep only healthy Pods in rotation.

Keep the route portable and isolate certificate and security policy in provider-specific resources.