Zalando
Read post

Rejecting Invalid Ingress Routes at Apply Time

Zalando runs Skipper as a Kubernetes ingress controller across 250+ clusters handling up to 2M RPS. Because Kubernetes cannot validate Skipper-specific filters and predicates, invalid route configurations were silently accepted and only discovered at runtime. The solution was to run Skipper itself as a Kubernetes validating admission webhook, so that on every kubectl apply, the webhook uses Skipper's own filter registry and predicate specs to answer 'would Skipper accept this route?' rather than just checking syntax. Invalid routes are now rejected immediately with actionable error messages. The rollout was treated as a control-plane change: metrics were added first, the feature was gated behind a flag, and it was deployed tier by tier across clusters. The implementation is open-source in Skipper v0.24.18.

    #kubernetes#platform-engineering
Apr 09•6m read time•From engineering.zalando.com
Post cover image
Table of contents
How Skipper sees a routeLetting Skipper validate SkipperWhat happens during kubectl apply nowUseful errors at applied timeRollout strategyOperational outcome
901 Impressions
Zalando's image
Zalando

Zalando Tech Blog is a platform where Zalando's engineering team shares insights, experiences, and b...

56 Followers

•

377 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard