GKE Gateway
The Gateway API is the Kubernetes standard for describing load balancers as cluster objects, and GKE's Gateway controller turns those objects into Google Cloud load balancers. The GCP Web App Blueprint exposes its API to the internet and ArgoCD to the internal network this way, so the routes live in Git next to the application they serve.
What it does
A GatewayClass names the kind of load balancer; a Gateway asks for one instance with its listeners and addresses; an HTTPRoute attaches hostnames and paths to Kubernetes Services. GKE adds policy objects that target a Gateway or a Service: GCPGatewayPolicy (for example the SSL policy), GCPBackendPolicy (Cloud Armor, timeout, logging) and HealthCheckPolicy (the load balancer's health check). The controller programs container-native load balancing, sending traffic straight to pod IPs through network endpoint groups.
How BuiltForProd uses it
The gke unit enables the Gateway API on each stage cluster (standard channel) and keeps the HTTP load-balancing add-on, which runs the controller; see Google Kubernetes Engine.
The API edge. The application chart in acme-gcp-blueprint-webapp-gitops owns the in-cluster objects, so ArgoCD reconciles them with the release:
| Chart template | Object | What it sets |
|---|---|---|
gateway.yaml | Gateway gke-l7-global-external-managed | HTTPS listener on 443, the reserved address, the certificate map annotation |
gateway.yaml | GCPGatewayPolicy | The SSL policy (MODERN, TLS 1.2 minimum) |
httproute.yaml | HTTPRoute | blueprint-api.<stage>.company.com, path prefix /, to the Service on 8080 |
backendpolicy.yaml | GCPBackendPolicy | The Cloud Armor policy, a 30-second timeout, logging of every request |
backendpolicy.yaml | HealthCheckPolicy | HTTP check of /health every 15 seconds |
The cloud resources those objects name are created outside the cluster by the api-gateway unit and published to Parameter Manager: api--gateway-address, api--certificate-map, api--security-policy and api--ssl-policy. Each stage's values file carries those names. With the Gateway enabled, the chart refuses to render without the address, the certificate map and the security policy. The resulting load balancer is described in Cloud Load Balancing, its certificate in Certificate Manager and its rules in Google Cloud Armor.
DNS. No one writes the API's A record by hand: the public external-dns release watches HTTPRoutes and writes the hostname into the stage zone, pointing at the Gateway's address.
ArgoCD. The argocd unit creates its own Gateway of class gke-l7-rilb, a regional internal Application Load Balancer, on a reserved internal address in the stage's nodes subnet. Its HTTPS listener serves argocd.<stage>.internal.company.com with the certificate argocd-tls from the internal certificate authority, an HTTPRoute sends traffic to argocd-server, and a HealthCheckPolicy probes /healthz on port 8080. The internal external-dns release publishes the hostname in internal.company.com.
Network policy. The chart's default-deny NetworkPolicy admits TCP 8080 only from Google's front-end and health-check ranges 130.211.0.0/22 and 35.191.0.0/16.
Terms you will see
| Term | Meaning |
|---|---|
| GatewayClass | The load balancer type, such as gke-l7-global-external-managed. |
| HTTPRoute | Hostnames and paths routed to a Service. |
| GCPBackendPolicy | GKE's policy for the backend service: Cloud Armor, timeout, logging. |
| HealthCheckPolicy | The health check the load balancer runs against the pods. |
gke-l7-rilb | The class of a regional internal Application Load Balancer. |
Where to read more
- GCP Web App Blueprint overview for the request path.
- Cloud Load Balancing for the load balancers the controller builds.
- ArgoCD for how the chart's objects reach the cluster.