How ingress works
Kong Mesh provides two features to manage ingress traffic, also known as north/south traffic. Both take advantage of a piece of infrastructure called a gateway proxy, that sits between external clients and your services in the mesh.
- Delegated gateway: allows users to use any existing gateway proxy, like Kong.
- Builtin gateway: configures instances of Envoy to act as a gateway.
Gateways exist within a
Mesh
. If you have multipleMeshes
, eachMesh
requires its own gateway. You can easily connect yourMeshes
together using cross-mesh gateways.
The below visualization shows the difference between delegated and builtin gateways. The blue lines represent traffic not managed by Kong Mesh.
Builtin, with Kong Gateway at the edge:
data:image/s3,"s3://crabby-images/d8aac/d8aacf00f89b660f579ee4ec1ed3390060c8cd28" alt=""
Delegated Kong Gateway:
data:image/s3,"s3://crabby-images/007e7/007e70efb78311783d5e826c7194efb45f7946c6" alt=""