Traefik’s edge routing dominance in 2026
With the retirement of Ingress-nginx in March 2026, Traefik offers a critical migration path via its NGINX Provider. This solution handles 80% of real-world usage patterns, providing a safer alternative to unmaintained controllers for Kubernetes users.
The Ingress-nginx retirement
The Ingress-nginx maintainers retired the project in March 2026. This decision leaves 50% of Kubernetes users without security patches or bug fixes. I view this as a massive operational risk for any organization running production workloads. Running unmaintained software invites configuration injection attacks like the #IngressNightmare vulnerabilities. Traefik provides an immediate fix. Its NGINX Provider handles nginx.ingress.kubernetes.io annotations natively. Most other controllers like F5 NGINX Ingress or HAProxy Ingress force a manual rewrite of every custom annotation. Organizations facing a 120-day deadline with no margin for error should look to Traefik because its compatibility layer handles 80% of real-world usage patterns without requiring a complete rebuild of the ingress layer.
Traefik handles it.
The retirement of Ingress-nginx creates an urgent crisis. In November 2025, the community learned the project would lose all releases and security updates after March 2026. This timeline leaves organizations with little room for error. Using unmaintained software exposes clusters to malicious configuration injection. Traefik offers a different architectural approach. It uses Go instead of C or C++ and relies on static linking and structured parsing. These choices prevent the memory safety and configuration injection attacks that plague NGINX controllers. Traefik has over 3.4 billion downloads and 58,000 GitHub stars. Most other solutions like AWS or AKS only provide migration guides or promote a Gateway API transition rather than providing migration compatibility.
The competition between Traefik and Cilium
Cilium uses a hybrid architecture. It handles Layer 4 traffic with eBPF programs and sends Layer 7 traffic to a user-space Envoy proxy. This design bypasses the kernel TCP stack to achieve high performance. However, upgrading the gateway often requires upgrading the CNI. Traefik focuses on operator ergonomics and dynamic configuration updates. It watches providers and updates routing without the classical configuration reload patterns seen in NGINX. I find the Cilium eBPF model too complex for small teams.
| Feature | Traefik | Cilium Ingress | Cilium Gateway API |
|---|---|---|---|
| NGINX Compatibility | Yes | No | No |
| eBPF Data Plane | No | Yes | Yes |
| Gateway API Support | Yes | Yes | Yes |
| Traffic Splitting | Yes | No | Yes |
Traefik works.
Cilium provides an upgrade path from Ingress to the Gateway API. You can use Cilium Ingress for a drop-in replacement and later transition to the Gateway API without switching vendors or datapaths. Cilium’s implementation supports all Core Gateway API resources and most Extended features. This includes native support for header-based routing, traffic splitting, and cross-namespace routes. The industry is moving toward Envoy-native models like Envoy Gateway and Istio. These tools provide high conformance to the Gateway API specification. Traefik also contributes to the specification and supports version 1.4 in its 3.6 release. High-performance claims for eBPF-based acceleration often come with caveats regarding Layer 7 processing overhead. The NGINX-adapter model faces an impedance mismatch because the highly dynamic nature of the Gateway API fits Envoy better than NGINX.
A strategy for migration
The Kubernetes Gateway API market reached $1.8 billion in 2025 and will grow to $7.2 billion by 2034. This growth stems from microservices proliferation and multi-cluster deployments. I advise you to separate your migration into two distinct phases. First, decommission Ingress-nginx using the Traefik NGINX Provider for drop-in compatibility. Second, plan your Gateway API modernization on your own timeline. Transitioning to Gateway API requires moving all ingress resources to Gateway, GatewayClass, and HTTPRoute objects. You know how much a configuration rewrite hurts.
Who manages the transition?
The Gateway API is a subproject of SIG-Network. It introduces a role-oriented design. It decouples infrastructure from application routing through distinct resources. The GatewayClass is managed by the Platform Provider. The Gateway is managed by the Cluster Operator. The Routes, including HTTPRoute and TLSRoute, are managed by Application Developers. This separation allows developers to control routing logic independently. North America dominated the market in 2025 with a 38.5% revenue share. Europe followed with a 27.2% share, driven by GDPR and DORA requirements. Asia Pacific expects a 18.9% CAGR through 2034. Organizations can use the ingress2gateway tool to automate the conversion of existing Ingress resources into Gateway API resources. Traefik is ready.
I recommend starting with Traefik for immediate stability. Then, adopt the Gateway API when your organizational needs evolve.