# API gateway between namespaces in same cluster?

**URL:** <https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354>\
**Category:** Questions\
**Tags:** kubernetes\
**Created:** [January 21, 2020, 3:43am UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354 "2020-01-21T03:43:34Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![davix](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/davix/32/1642_2.png) [@davix](https://discuss.konghq.com/u/davix)\
**Post date:** [January 21, 2020, 3:43am UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354/1 "2020-01-21T03:43:34Z")

</div>

Hi, usually an API gateway is used for proxying traffic between out-cluster (k8s) and in-cluster. That’s why an ‘ingress’ resource needs to be added, and the routes are configured in the ‘ingress’.

My case here is to proxy traffic between all pods in namespace1 and those in namespace2. For example, pods in namespace1 needs to access services in namespace2 via an API gateway, along with auth/acl/rate-limit/…

Can Kong help in this case? Since no ‘ingress’ resource needed, can kong-ingress-controller work?

Thanks!

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [January 21, 2020, 6:51pm UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354/2 "2020-01-21T18:51:35Z")

</div>

Yes. You are thinking along the lines of an internal API gateway.

You can deploy Kong Ingress Controller, and instead of using an External Load Balancer, use a Service of tyep `ClusterIP`. You can then create Ingress resources to configure Kong. The traffic will not be exposed externally as the Kong Service is internal only.

---

<div class="post-metadata">

**Author:** ![davix](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/davix/32/1642_2.png) [@davix](https://discuss.konghq.com/u/davix)\
**Post date:** [January 22, 2020, 3:01pm UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354/3 "2020-01-22T15:01:30Z")

</div>

> [@hbagdi](#):
>
> You can then create Ingress resources to configure Kong.

Do you mean configure it by admin api?  
Then the CDR way won’t work in this case?

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [January 22, 2020, 5:29pm UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354/4 "2020-01-22T17:29:54Z")

</div>

No. I mean use Ingress and CRDs to configure Kong.  
You can use whatever you are already familiar with for an internal API Gateway for communication between namespaces as well.

---

<div class="post-metadata">

**Author:** ![davix](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/davix/32/1642_2.png) [@davix](https://discuss.konghq.com/u/davix)\
**Post date:** [January 23, 2020, 12:18am UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354/5 "2020-01-23T00:18:24Z")

</div>

But if an ‘ingress’ resource is created, wouldn’t external traffic visit it as well?  
So do you mean both external and internal traffic can use the same ingress? Is there a method to prevent external traffic use it?

---

<div class="post-metadata">

**Author:** ![hbagdi](https://yyz2.discourse-cdn.com/flex036/user_avatar/discuss.konghq.com/hbagdi/32/562_2.png) [@hbagdi](https://discuss.konghq.com/u/hbagdi)\
**Post date:** [January 23, 2020, 4:31pm UTC](https://discuss.konghq.com/t/api-gateway-between-namespaces-in-same-cluster/5354/6 "2020-01-23T16:31:01Z")

</div>

> [@davix](#):
>
> But if an ‘ingress’ resource is created, wouldn’t external traffic visit it as well?

Not necessarily. If Kong is only an internal service and Kong can’t be accessed outside the cluster, then this won’t happen.

> [@davix](#):
>
> So do you mean both external and internal traffic can use the same ingress? Is there a method to prevent external traffic use it?

I’d recommend creating separate ingress resources for external and internal traffic.
