Load Balancing Add-on
The Load Balancing add-on lets your cluster expose workloads through the VPC gateway using standard Kubernetes resources. When enabled, NetActuate installs and operates a controller that turns a LoadBalancer Service into a Layer 4 load balancer and an Ingress into a Layer 7 load balancer on the gateway, giving your pods a public entry point without you configuring the gateway by hand. This add-on is available only on in-VPC clusters, because it drives the VPC gateway.
Enable the add-on
- Navigate to Infrastructure -> Kubernetes and open your in-VPC cluster.
- Open the Managed Add-ons tab.
- Enable Load Balancing and confirm.
NetActuate installs the controller and moves the add-on to ready when installation or reconciliation completes. If it reports degraded or failed, use Repair on the same tab.
The add-on state field does not report controller pod health today. Monitor the Kubernetes controller workload and the resulting gateway load balancer, not the add-on state alone.
Layer 4: LoadBalancer Services
Expose a TCP or UDP service by creating a Service of type: LoadBalancer and opting in with the NetActuate load balancer class. The class is a required opt-in: the controller only acts on Services that set spec.loadBalancerClass to netactuate.com/vpc-lb, so a plain type: LoadBalancer Service without the class is left untouched.
apiVersion: v1
kind: Service
metadata:
name: web
spec:
type: LoadBalancer
loadBalancerClass: netactuate.com/vpc-lb
selector:
app: web
ports:
- port: 443
targetPort: 8443
loadBalancerSourceRanges:
- 203.0.113.0/24
- Assigned VIP. Once provisioned, the public virtual IP is reported back on the Service at
status.loadBalancer.ingress[].ip. Read it withkubectl get service weband use it as the address for the service. - Source ranges. The add-on accepts
spec.loadBalancerSourceRangesand creates a gateway firewall rule for the Service with annke-lb:svc:<id>tag. Traffic filtering from this field is not active today, so do not rely on it to restrict access to the VIP.
Layer 7: Ingress
Expose HTTP and HTTPS routes by creating an Ingress that uses the NetActuate ingress class. Set the IngressClass to netactuate so the add-on programs a Layer 7 load balancer on the gateway for the Ingress rules.
HTTP route
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: web
spec:
ingressClassName: netactuate
rules:
- host: web.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: web
port:
number: 80
This shape creates an HTTP route for web.example.com.
Platform-managed ACME certificate
Use the same Ingress rule shape for platform-managed ACME certificates. The hostname in the Ingress rule must resolve publicly to the Ingress VIP before a certificate can issue.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: web
spec:
ingressClassName: netactuate
rules:
- host: web.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: web
port:
number: 80
Do not add spec.tls for platform-managed ACME. The platform reads the hostnames from the Ingress rules and manages certificate issuance and renewal.
Bring-your-own certificate
Kubernetes supports spec.tls, but the Load Balancing add-on does not read it today.
apiVersion: networking.k8s.io/v1
kind: Ingress
metadata:
name: web
spec:
ingressClassName: netactuate
rules:
- host: web.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: web
port:
number: 80
tls:
- hosts:
- web.example.com
secretName: web-tls
This shape does not attach the web-tls Secret to the gateway load balancer today. Bring-your-own certificates through Ingress spec.tls are not supported yet. Use platform-managed ACME certificates for HTTPS routes.
Where it appears
Load balancers created through the add-on are provisioned on the VPC gateway and surface on the Load Balancing tab of the VPC in the portal, alongside any load balancers you created directly. This lets you see the gateway-level result of a LoadBalancer Service or an Ingress next to your other VPC load balancers. See Load Balancing for the VPC Load Balancing tab.
Gateway firewall
Gateway firewall rules control traffic at the same VPC gateway used by this add-on. Manage them from the VPC Firewall tab, or through the v3 gateway firewall endpoints:
GET /vpcs/{vpcId}/gateway/rules/firewallPOST /vpcs/{vpcId}/gateway/rules/firewallDELETE /vpcs/{vpcId}/gateway/rules/firewall/{firewallRuleId}PATCH /vpcs/{vpcId}/gateway/rules/firewall/{firewallRuleId}POST /vpcs/{vpcId}/gateway/rules/firewall/apply-changesGET /vpcs/{vpcId}/gateway/rules/firewall/ipv4GET /vpcs/{vpcId}/gateway/rules/firewall/ipv6
See VPC Firewall and the API v3 Reference.
Need Help?
Contact support@netactuate.com or open a support ticket from the portal.