Component overview
The ALB Ingress Controller is based on Alibaba Cloud Application Load Balancer (ALB) and provides powerful Ingress traffic management. It is compatible with Nginx Ingress, supports complex business routing and automatic certificate discovery, and handles HTTP, HTTPS, and QUIC protocols. This makes it ideal for cloud-native applications that require high elasticity and large-scale Layer 7 traffic processing.
The ALB Ingress Controller watches the API server for changes to Ingress resources, dynamically generates an AlbConfig, and then creates or updates the required ALB instances, listeners, forwarding rules, and backend server groups. You can deploy this component in your Container Service for Kubernetes (ACK) cluster to manage Ingress traffic by configuring ALB Ingress resources.
Release notes
September 2026
Version number | Modification Time | Changes | Impact |
v3.1.1 | September 3, 2026 | Bug fixes: | This upgrade does not affect your services. |
August 2026
Version number | Modification Time | Changes | Impact |
v3.1.0 | August 10, 2026 | New features: Added Gateway API support for declaratively managing service extensions for Application Load Balancer (ALB) Extended Edition using the AlbServiceExtension resource. These extensions can be referenced in forwarding rules or backend server groups. Added support for configuring Fqdn and IpSegment type backends for ALB Extended Edition using the AlbService resource. These backends can be referenced in an HTTPRoute.
Optimizations: Optimized the update logic for forwarding rules to prevent invalid updates triggered by an inconsistent return order from backend server groups. This issue previously caused dry runs to fail. Fixed an issue where health check status codes were not correctly parsed or delivered according to the health check protocol in some scenarios, which caused dry runs to fail.
Bug fixes: | This upgrade does not affect your services. |
July 2026
Version number | Change time | Change content | Change impact |
v3.0.0 | July 06, 2026 | New features: Added support for creating and managing ALB Extended Edition instances by using the Gateway API. Added support for associating service extension IDs with forwarding rules for ALB Extended Edition instances by using AlbRule. Added support for associating service extension IDs with server groups for ALB Extended Edition instances by using AlbServerGroup. Added support for the AlbInstance custom CRD. This lets you define ALB instance configurations, such as address type, availability zone, logs, and bandwidth packages, by referencing infrastructure.parametersRef in Gateway resources. Some properties take effect only during instance creation. ALB Standard Edition instances created by using the Gateway API have instance managed mode enabled by default. For these instances, listener and forwarding rule configurations cannot be manually modified in the ALB console. This limit applies only to ALB instances created after upgrading to this version. Existing instances are not affected.
Optimizations: Backend persistent connections are now enabled by default when you create a server group using the Gateway API. Existing server groups are not affected. Before upgrading, confirm if this change in behavior affects your services. The Gateway API now uses EndpointSlice instead of Endpoints for endpoint discovery by default. Added support for using multi-port Services with the Gateway API. Added support for using ReadinessGate with the Gateway API. This feature is supported only by the Terway network plugin. The Flannel network plugin is not yet supported.
Bug fixes: Fixed an issue where the Gateway API failed to automatically retry after a service discovery error. Fixed an issue that blocked the deletion of Gateway resources associated with an HTTPRoute. Fixed an issue where a listener was deleted immediately after a certificate error. Instead, the operation is blocked and an error is reported when a certificate error occurs. Fixed an issue where the server group was not cleared promptly after a Service was deleted in Gateway API scenarios.
| This upgrade does not affect your services. |
June 2026
Version | Date | Changes | Impact |
v2.20.1 | June 8, 2026 | Optimizations: Bug fixes: | No impact on services. |
April 2026
Version | Release date | Changes | Impact |
v2.20.0 | April 16, 2026 | New features: Added support for setting accessLogRecordCustomizedHeadersEnabled to false by specifying accessLogRecordCustomizedHeadersAllowDisable: true in the logConfig of ListenerSpec. The webhook now prevents the deletion of a Service or Secret used by an ALB Ingress. A validation check is added to webhooks to ensure that when the path type is Prefix, the path cannot contain the wildcard character *.
Enhancements: Reduces the controller memory footprint. The controller now uses EndpointSlice instead of Endpoints for endpoint discovery by default. Optimized the wait time for asynchronous server group tasks.
Bug fixes: Fixes an issue where changes to the ALB resource group ID in AlbConfig did not take effect. Fixes an issue where an invalid forwarding configuration for a custom forwarding rule could cause the controller to panic.
| This upgrade has no impact on your workloads. |
January 2026
Version | Release date | Changes | Impact |
v2.19.0 | January 7, 2026 | New features: Enhancements: Improved the error message that appears when listener creation fails due to an expired certificate. Improved controller reconciliation performance. Enhanced webhook validation to check the following: The format of the SourceIP field in custom forwarding conditions. Whether the AclType field is black or white. Ingress backends that specify service.name without service.port.
Added a webhook check to determine whether an Ingress is an ALB Ingress.
Bug fixes: | This upgrade has no impact on your workloads. |
July 2025
Version | Release date | Description | Impact |
v2.18.0-aliyun.1 | July 4, 2025 | Instance managed mode is enabled by default. The listener and forwarding rule configurations for ALB instances automatically created by using an AlbConfig can no longer be manually modified in the ALB console. This restriction applies only to new ALB instances created after this upgrade; existing and reused instances are not affected. You can now specify a default certificate in an AlbConfig by using the defaultCertificate field. Optimized the priority sorting logic for forwarding rules and removed the global uniqueness requirement for the order field. Fixed an issue where the controller could panic due to flow control when querying the asynchronous task API. Fixed an issue where an ACL would apply to only one listener when HTTPS and QUIC listeners shared the same port. The readinessGate now uses a fixed interval when waiting for unready pods. Optimized the admission webhook's validation logic for forwarding rules that do not include a terminating action.
| This upgrade will not affect your services. |
March 2025
Version | Release date | Changes | Impact |
v2.17.2-aliyun.1 | March 31, 2025 | Fixed a server group reconciliation failure that caused a port-not-found error when Ingress rules in multiple namespaces pointed to Services with the same name but different ports. Fixed an invalid parameter error when querying IPv4 addresses in an IPv6 dual-stack cluster. Increased the maximum number of security groups that can be added or removed in a single batch API call from 4 to 9. Skipped API calls when no additional tags are required.
| This upgrade does not affect your services. |
v2.17.1-aliyun.1 | March 18, 2025 | | This upgrade does not affect your services. |
v2.16.0-aliyun.1 | March 4, 2025 |
Important Starting from this version, backend persistent connections are enabled by default for new server groups. Existing server groups are unaffected. Before upgrading, confirm if this change affects your services. Enabled persistent connection by default for new server groups. Listeners now support custom tags. Added an option to disable the cross-zone feature for server groups. Improved overall Service reconciliation performance. Improved the timing of ReadinessGate status updates for Pods. The Pod status is updated only after every associated server group update succeeds. Canary releases now require two separate Ingresses or custom forwarding actions. If a canary annotation is incorrectly added to an Ingress, the system reports an error and retains the original forwarding rules.
| This upgrade does not affect your services. |
January 2025
Version | Release date | Changes | Impact |
v2.15.2-aliyun.1 | January 24, 2025 | In a listener's XForwardedForConfig, you can configure XForwardedForProcessingMode to set the processing mode for the X-Forwarded-For header, and set XForwardedForHostEnabled to enable the X-Forwarded-Host request header. Fixed an issue where the component fails to start when ValidatingWebhookConfiguration does not exist. Fixed an issue where Webhook validation fails when alb.ingress.kubernetes.io/healthcheck-httpcode is configured with multiple values. Added a check for forwarding actions that do not include the FinalType type. Optimized the calculation of clientToken when you create an ALB instance.
| |
v2.15.0-aliyun.1 | January 6, 2025 | The ValidatingWebhook is now enabled by default to precheck AlbConfig and Ingress configurations. Supports AScript programmable scripts. The rate-limiting feature now supports fixed responses. The ssl-redirect and rate-limiting features are now compatible. Session persistence for server groups now supports custom cookies. Supports configuring security groups for new ALB instances. (Effective from 00:00:00 on February 25, 2025, UTC+8) Improved error messages for listener conflicts. The controller now sends event notifications for inconsistencies between TLS certificate configurations and forwarding rule certificates. The controller now validates associated resources, such as bandwidth plans. The gRPC protocol now supports certificate configuration in AlbConfig. Fixed an issue where the tag feature in AlbConfig could not be used after the creator tag feature was enabled. Fixed an issue where Service reconciliation continuously reported errors in some scenarios. Fixed an issue where an incorrect AlbConfig configuration caused the component to crash.
| This upgrade does not affect your services. |
May 2024
Version | Release date | Changes | Impact |
v2.13.1-aliyun.1 | May 10, 2024 | The controller now sends an event when an AlbConfig is not associated with an Ingress. Fixed a server group creation failure caused by a namespace starting with a number or a long namespace or service name.
| This upgrade does not affect your services. |