Skip to content
Copy
View as Markdown Suggest changes
Add Docs MCP
Setup guide

Migration Plan for Wallarm NGINX Ingress Controller Customers

In November 2025, the Kubernetes community announced the retirement of the Community Ingress NGINX project, with best-effort maintenance ending in March 2026. This page outlines how this change affects Wallarm's NGINX-based Ingress deployment artifact and the available migration paths.

Support timeline for the Community-based controller

To align with the upstream project's lifecycle, the following support plan applies to the Community‑based Wallarm Ingress Controller (Wallarm Node 6.x):

  • Wallarm actively supported this controller, including new feature releases, until March 2026.

  • Since March 2026:

    • The controller remains functional.
    • Wallarm no longer actively develops it — no new features are added.
    • Wallarm may still deliver limited fixes and minor updates.
    • Because the upstream Community Ingress NGINX project has been retired, the controller no longer receives upstream security patches.

Alternative deployment options

Wallarm provides several alternatives to the Community-based Wallarm Ingress Controller, covering the most common ingress models:

F5 NGINX Ingress Controller (available now, Wallarm Node 7.x)

Wallarm Node 7.x delivers a reworked Ingress Controller Helm chart based on the F5 NGINX Ingress Controller with integrated Wallarm services.

Istio/Envoy connector (available now)

Wallarm offers an Istio/Envoy-based connector.

This is not a direct replacement for the NGINX Ingress Controller and may require architectural changes in how traffic enters and flows through the cluster.

It is a suitable option for customers who are already using, or planning to adopt, Envoy-based ingress gateways or service-mesh-style architectures.

Wallarm Node deployment compatible with the Kubernetes Gateway API (coming soon)

Wallarm will also introduce a new deployment artifact compatible with the Kubernetes Gateway API, the modern, Kubernetes-recommended standard for traffic ingress.

  • Availability: coming soon

  • Recommended for: customers adopting Gateway API in their clusters or moving toward modern Kubernetes networking patterns

This artifact will integrate Wallarm traffic processing into clusters through the Gateway API's extensible, role-oriented model.

Next steps for customers

Although your existing clusters keep running, Wallarm recommends migrating rather than postponing it. Wallarm Node 7.x is production-ready and is set to become the latest stable version, replacing 6.x. In addition, the Community-based controller is no longer actively supported, and the retired upstream project no longer receives security patches.

Choose one of the following options:

  • To keep using an NGINX-based Ingress controller, upgrade to the F5-based controller by following the migration guide.

  • If your organization is already using or planning to transition to Envoy-based or service-mesh architectures, adopt the Istio/Envoy-based connector.

  • If you are adopting the Kubernetes Gateway API, plan for the Wallarm artifact compatible with the Gateway API (coming soon).