Enabling Gateway API { #enable-gateway-api_{context} }¶
To route traffic using Gateway API, you must first enable the feature on your cluster. You can enable Gateway API by creating a GatewayClass custom resource, which triggers the Ingress Operator to provision the necessary controller and components.
After you successfully enable Gateway API, you can begin deploying gateways, assigning network addresses, and configuring listeners to control your network traffic flow.
Enabling Gateway API for the Ingress Operator¶
To configure Gateway API for use on your cluster, you must create a GatewayClass resource. During the creation of the GatewayClass resource, the Ingress Operator installs a lightweight Istio control plane, based on Red Hat OpenShift Service Mesh, in the openshift-ingress namespace.
Prerequisites
- You have access to the cluster as a user with the
cluster-adminrole. - You have installed the OpenShift CLI (
oc).
Procedure
-
Create a
GatewayClassobject:-
Create a YAML file,
openshift-default.yaml, that contains the following information:Example GatewayClass CRapiVersion: gateway.networking.k8s.io/v1 kind: GatewayClass metadata: name: openshift-default spec: controllerName: openshift.io/gateway-controller/v1-
metadata.name: The name of yourGatewayClassobject. The name must consist of a maximum of 63 lowercase alphanumeric characters or hyphens (-). The name must also start and end with an alphanumeric character.Warning
The
controllerNamevalue must be exactly as shown for the Ingress Operator to manage it. If you set this field to anything else, the Ingress Operator ignores theGatewayClassobject and all associatedGateway,GRPCRoute, andHTTPRouteobjects. The controller name is tied to the implementation of Gateway API in OpenShift Container Platform, andopenshift.io/gateway-controller/v1is the only controller name allowed.
-
-
Run the following command to create the
GatewayClassresource:
-
Verification
-
Verify that the
GatewayClassCR has been accepted and the controller is successfully installed by running the following command:Example output# ... status: conditions: - lastTransitionTime: "2026-05-15T10:00:00Z" message: The GatewayClass has been accepted reason: Accepted status: "True" type: Accepted - lastTransitionTime: "2026-05-15T10:00:00Z" message: Istio installed successfully reason: Installed status: "True" type: ControllerInstalled - lastTransitionTime: "2026-05-15T10:00:00Z" message: Istio CRDs are being managed by cluster-ingress-operator reason: ManagedByCIO status: "True" type: CRDsReady # ...Inspect the
status.conditionsblock in the output. A healthyGatewayClassCR reports a status ofTruefor theAccepted,ControllerInstalled, andCRDsReadyconditions.