Skip to content

Migration

From Ingress NGINX to Traefik

This guide will help you migrate your Kubernetes cluster from using Ingress NGINX as the ingress controller to using Traefik.

For a comprehensive, official guide with detailed instructions and troubleshooting, refer to the Traefik documentation on migrating from ingress-nginx.

Prerequisites

  • Kubernetes cluster with ingress-nginx installed
  • kubectl configured to access your cluster
  • kubectl-ns plugin installed
  • Access to DNS manager

Install Traefik

Add the Traefik Helm repository:

task add-repos

Install Traefik:

task install-traefik

Check that Traefik is running:

kubectl get pods -n traefik

Ensure traefik is the new default.

kubectl get ingressclass traefik -o jsonpath='{.metadata.annotations.ingressclass\.kubernetes\.io/is-default-class}'

List the service.

kubectl get svc -n traefik

Note that the Treafik service has a different external IP address.

traefik_service_ip=$(kubectl get svc -n traefik traefik -o jsonpath='{.status.loadBalancer.ingress[0].ip}')

Update Ingress Resource

You can chose to this before or after updating the DNS entries.

Switch to namespace with ingress:

kubectl-ns

Patch the ingress resource:

kubectl patch ingress $name -p '{"spec":{"ingressClassName":"traefik"}}'

::: danger Services linked to this ingress resource won't be accessable until DNS propagates the new ip. :::

Verify the patch:

kubectl get ingress $name -o yaml | grep -A1 ingressClassName

Verify that your application is accessible through Traefik:

curl -I -H "Host: app.example.com" http://$traefik_service_ip

You can also update all ingress resources at once.

kubectl get ingress --all-namespaces

Patch all ingresses to use Traefik:

kubectl get ingress --all-namespaces -o jsonpath='{range .items[*]}{.metadata.name}{" "}{.metadata.namespace}{"\n"}{end}' | while read name namespace; do kubectl patch ingress "$name" -n "$namespace" -p '{"spec":{"ingressClassName":"traefik"}}'; done

To route it externally we need to update the application's DNS entry.

Update DNS

Update DNS entries of your applications to point to the new Treafik IP.

Ensure the new IP address is resolved.

nslookup app.example.com 9.9.9.9

Verify that your applications is routed correctly:

curl -I https://app.example.com

Upgrade Cluster Issuer

If you deployed a cluster issuer, update the release:

kubectl-ns cert-manager
task upgrade-release cluster-issuer $values

Uninstall ingress-nginx

Once you've verified that Traefik is working correctly, you can uninstall ingress-nginx:

kubectl-ns ingress-nginx
task uninstall-release ingress-nginx