ALB Ingress Controller

Updated at:

The ALB Ingress Controller uses Alibaba Cloud Application Load Balancer (ALB) to manage Ingress traffic. This topic provides an overview of the component, usage instructions, and release notes.

Component overview

The ALB Ingress Controller is based on Alibaba Cloud Application Load Balancer (ALB) and provides powerful Ingress traffic management. It is compatible with Nginx Ingress, supports complex business routing and automatic certificate discovery, and handles HTTP, HTTPS, and QUIC protocols. This makes it ideal for cloud-native applications that require high elasticity and large-scale Layer 7 traffic processing.

The ALB Ingress Controller watches the API server for changes to Ingress resources, dynamically generates an AlbConfig, and then creates or updates the required ALB instances, listeners, forwarding rules, and backend server groups. You can deploy this component in your Container Service for Kubernetes (ACK) cluster to manage Ingress traffic by configuring ALB Ingress resources.

Usage instructions

For instructions on using the ALB Ingress Controller, see Manage ALB Ingresses.

Release notes

September 2026

Version number

Modification Time

Changes

Impact

v3.1.1

September 3, 2026

Bug fixes:

  • Fixed a bug where the Application Load Balancer (ALB) OpenAPI incorrectly used public network endpoints, causing controllers in non-public VPCs and some regions to fail.

This upgrade does not affect your services.

August 2026

Version number

Modification Time

Changes

Impact

v3.1.0

August 10, 2026

New features:

  • Added Gateway API support for declaratively managing service extensions for Application Load Balancer (ALB) Extended Edition using the AlbServiceExtension resource. These extensions can be referenced in forwarding rules or backend server groups.

  • Added support for configuring Fqdn and IpSegment type backends for ALB Extended Edition using the AlbService resource. These backends can be referenced in an HTTPRoute.

Optimizations:

  • Optimized the update logic for forwarding rules to prevent invalid updates triggered by an inconsistent return order from backend server groups. This issue previously caused dry runs to fail.

  • Fixed an issue where health check status codes were not correctly parsed or delivered according to the health check protocol in some scenarios, which caused dry runs to fail.

Bug fixes:

  • Fixed an issue where a Service might not be promptly reconciled after a node change if externalTrafficPolicy is set to Local mode.

This upgrade does not affect your services.

July 2026

Version number

Change time

Change content

Change impact

v3.0.0

July 06, 2026

New features:

  • Added support for creating and managing ALB Extended Edition instances by using the Gateway API.

  • Added support for associating service extension IDs with forwarding rules for ALB Extended Edition instances by using AlbRule.

  • Added support for associating service extension IDs with server groups for ALB Extended Edition instances by using AlbServerGroup.

  • Added support for the AlbInstance custom CRD. This lets you define ALB instance configurations, such as address type, availability zone, logs, and bandwidth packages, by referencing infrastructure.parametersRef in Gateway resources. Some properties take effect only during instance creation.

  • ALB Standard Edition instances created by using the Gateway API have instance managed mode enabled by default. For these instances, listener and forwarding rule configurations cannot be manually modified in the ALB console. This limit applies only to ALB instances created after upgrading to this version. Existing instances are not affected.

Optimizations:

  • Backend persistent connections are now enabled by default when you create a server group using the Gateway API. Existing server groups are not affected. Before upgrading, confirm if this change in behavior affects your services.

  • The Gateway API now uses EndpointSlice instead of Endpoints for endpoint discovery by default.

  • Added support for using multi-port Services with the Gateway API.

  • Added support for using ReadinessGate with the Gateway API. This feature is supported only by the Terway network plugin. The Flannel network plugin is not yet supported.

Bug fixes:

  • Fixed an issue where the Gateway API failed to automatically retry after a service discovery error.

  • Fixed an issue that blocked the deletion of Gateway resources associated with an HTTPRoute.

  • Fixed an issue where a listener was deleted immediately after a certificate error. Instead, the operation is blocked and an error is reported when a certificate error occurs.

  • Fixed an issue where the server group was not cleared promptly after a Service was deleted in Gateway API scenarios.

This upgrade does not affect your services.

June 2026

Version

Date

Changes

Impact

v2.20.1

June 8, 2026

Optimizations:

  • Increased the wait time and retry count for asynchronous tasks.

Bug fixes:

  • Fixed a bug where clusters running version 1.20 or earlier failed to fall back from EndpointSlice to Endpoints for endpoint discovery.

No impact on services.

April 2026

Version

Release date

Changes

Impact

v2.20.0

April 16, 2026

New features:

  • Added support for setting accessLogRecordCustomizedHeadersEnabled to false by specifying accessLogRecordCustomizedHeadersAllowDisable: true in the logConfig of ListenerSpec.

  • The webhook now prevents the deletion of a Service or Secret used by an ALB Ingress.

  • A validation check is added to webhooks to ensure that when the path type is Prefix, the path cannot contain the wildcard character *.

Enhancements:

  • Reduces the controller memory footprint.

  • The controller now uses EndpointSlice instead of Endpoints for endpoint discovery by default.

  • Optimized the wait time for asynchronous server group tasks.

Bug fixes:

  • Fixes an issue where changes to the ALB resource group ID in AlbConfig did not take effect.

  • Fixes an issue where an invalid forwarding configuration for a custom forwarding rule could cause the controller to panic.

This upgrade has no impact on your workloads.

January 2026

Version

Release date

Changes

Impact

v2.19.0

January 7, 2026

New features:

  • Supports hot reloading of the secret specified in defaultCertificate.

  • Supports configuring an ingress with rate limiting + fixed response/redirect + forward actions.

Enhancements:

  • Improved the error message that appears when listener creation fails due to an expired certificate.

  • Improved controller reconciliation performance.

  • Enhanced webhook validation to check the following:

    • The format of the SourceIP field in custom forwarding conditions.

    • Whether the AclType field is black or white.

    • Ingress backends that specify service.name without service.port.

  • Added a webhook check to determine whether an Ingress is an ALB Ingress.

Bug fixes:

  • Fixed an issue where tags were not removed from an ALB instance when the tags field was deleted from AlbConfig.

  • Fixed a rare controller panic on service deletion.

This upgrade has no impact on your workloads.

July 2025

Version

Release date

Description

Impact

v2.18.0-aliyun.1

July 4, 2025

  • Instance managed mode is enabled by default. The listener and forwarding rule configurations for ALB instances automatically created by using an AlbConfig can no longer be manually modified in the ALB console. This restriction applies only to new ALB instances created after this upgrade; existing and reused instances are not affected.

  • You can now specify a default certificate in an AlbConfig by using the defaultCertificate field.

  • Optimized the priority sorting logic for forwarding rules and removed the global uniqueness requirement for the order field.

  • Fixed an issue where the controller could panic due to flow control when querying the asynchronous task API.

  • Fixed an issue where an ACL would apply to only one listener when HTTPS and QUIC listeners shared the same port.

  • The readinessGate now uses a fixed interval when waiting for unready pods.

  • Optimized the admission webhook's validation logic for forwarding rules that do not include a terminating action.

This upgrade will not affect your services.

March 2025

Version

Release date

Changes

Impact

v2.17.2-aliyun.1

March 31, 2025

  • Fixed a server group reconciliation failure that caused a port-not-found error when Ingress rules in multiple namespaces pointed to Services with the same name but different ports.

  • Fixed an invalid parameter error when querying IPv4 addresses in an IPv6 dual-stack cluster.

  • Increased the maximum number of security groups that can be added or removed in a single batch API call from 4 to 9.

  • Skipped API calls when no additional tags are required.

This upgrade does not affect your services.

v2.17.1-aliyun.1

March 18, 2025

  • Added support for Gateway API v1.1.0 and later.

This upgrade does not affect your services.

v2.16.0-aliyun.1

March 4, 2025

Important

Starting from this version, backend persistent connections are enabled by default for new server groups. Existing server groups are unaffected. Before upgrading, confirm if this change affects your services.

  • Enabled persistent connection by default for new server groups.

  • Listeners now support custom tags.

  • Added an option to disable the cross-zone feature for server groups.

  • Improved overall Service reconciliation performance.

  • Improved the timing of ReadinessGate status updates for Pods. The Pod status is updated only after every associated server group update succeeds.

  • Canary releases now require two separate Ingresses or custom forwarding actions. If a canary annotation is incorrectly added to an Ingress, the system reports an error and retains the original forwarding rules.

This upgrade does not affect your services.

January 2025

Version

Release date

Changes

Impact

v2.15.2-aliyun.1

January 24, 2025

  • In a listener's XForwardedForConfig, you can configure XForwardedForProcessingMode to set the processing mode for the X-Forwarded-For header, and set XForwardedForHostEnabled to enable the X-Forwarded-Host request header.

  • Fixed an issue where the component fails to start when ValidatingWebhookConfiguration does not exist.

  • Fixed an issue where Webhook validation fails when alb.ingress.kubernetes.io/healthcheck-httpcode is configured with multiple values.

  • Added a check for forwarding actions that do not include the FinalType type.

  • Optimized the calculation of clientToken when you create an ALB instance.

v2.15.0-aliyun.1

January 6, 2025

  • The ValidatingWebhook is now enabled by default to precheck AlbConfig and Ingress configurations.

  • Supports AScript programmable scripts.

  • The rate-limiting feature now supports fixed responses.

  • The ssl-redirect and rate-limiting features are now compatible.

  • Session persistence for server groups now supports custom cookies.

  • Supports configuring security groups for new ALB instances. (Effective from 00:00:00 on February 25, 2025, UTC+8)

  • Improved error messages for listener conflicts.

  • The controller now sends event notifications for inconsistencies between TLS certificate configurations and forwarding rule certificates.

  • The controller now validates associated resources, such as bandwidth plans.

  • The gRPC protocol now supports certificate configuration in AlbConfig.

  • Fixed an issue where the tag feature in AlbConfig could not be used after the creator tag feature was enabled.

  • Fixed an issue where Service reconciliation continuously reported errors in some scenarios.

  • Fixed an issue where an incorrect AlbConfig configuration caused the component to crash.

This upgrade does not affect your services.

May 2024

Version

Release date

Changes

Impact

v2.13.1-aliyun.1

May 10, 2024

  • The controller now sends an event when an AlbConfig is not associated with an Ingress.

  • Fixed a server group creation failure caused by a namespace starting with a number or a long namespace or service name.

This upgrade does not affect your services.