# Networking (/docs/foundation/networking)



Foundation uses several cooperating components to expose services safely and predictably.

## Main roles [#main-roles]

| Component                    | Main role                                                  |
| ---------------------------- | ---------------------------------------------------------- |
| Gateway API (Envoy Gateway)  | primary ingress controller for all HTTP(S) traffic         |
| Infrastructure load balancer | makes the shared gateway reachable from the target network |
| External DNS                 | publishes DNS records for exposed services                 |
| cert-manager                 | manages certificates and TLS lifecycle                     |

## Typical traffic path [#typical-traffic-path]

A common Foundation request path looks like this:

1. a hostname is published through **External DNS**
2. TLS is managed through **cert-manager**
3. traffic reaches the shared gateway through the environment's load-balancer implementation
4. **Gateway API** routes the request based on `HTTPRoute` rules attached to the shared `Gateway` resource
5. the request is forwarded to the target Foundation or higher-layer service

## Gateway API [#gateway-api]

The platform uses [Gateway API (Envoy Gateway)](/docs/foundation/components/gateway-api) as the primary ingress controller. Each platform component defines its own `HTTPRoute` resource that registers its endpoints with a shared `Gateway`.

The routing model has three important properties:

* **HTTPRoute** resources replace `Ingress` resources — routing is defined per-component, not centrally
* **Envoy** is the data plane — the `EnvoyProxy` configuration and `GatewayClass` are managed by the platform
* **Gateway** is a shared cluster resource — all components route through it, with TLS certificates referenced from cert-manager

## Why this matters [#why-this-matters]

The routing model is one of the most visible parts of Foundation because it defines how users, systems, and services reach the platform. It is also one of the main places where network exposure, DNS, TLS, and access control come together.
