Networking
Service exposure, traffic routing, DNS, certificates, and trust.
Foundation uses several cooperating components to expose services safely and predictably.
Main roles
| Component | Main role |
|---|---|
| Gateway API (Envoy Gateway) | primary ingress controller for all HTTP(S) traffic |
| Infrastructure load balancer | makes the shared gateway reachable from the target network |
| External DNS | publishes DNS records for exposed services |
| cert-manager | manages certificates and TLS lifecycle |
Typical traffic path
A common Foundation request path looks like this:
- a hostname is published through External DNS
- TLS is managed through cert-manager
- traffic reaches the shared gateway through the environment's load-balancer implementation
- Gateway API routes the request based on
HTTPRouterules attached to the sharedGatewayresource - the request is forwarded to the target Foundation or higher-layer service
Gateway API
The platform uses Gateway API (Envoy Gateway) as the primary ingress controller. Each platform component defines its own HTTPRoute resource that registers its endpoints with a shared Gateway.
The routing model has three important properties:
- HTTPRoute resources replace
Ingressresources — routing is defined per-component, not centrally - Envoy is the data plane — the
EnvoyProxyconfiguration andGatewayClassare managed by the platform - Gateway is a shared cluster resource — all components route through it, with TLS certificates referenced from cert-manager
Why this matters
The routing model is one of the most visible parts of Foundation because it defines how users, systems, and services reach the platform. It is also one of the main places where network exposure, DNS, TLS, and access control come together.