Ingress NGINX is retiring — how we cut over to Envoy Gateway in 3 days (without downtime)
Most organizations do not have an ingress strategy. They have NGINX controllers that grew with the cluster — snippet annotations, oauth2-proxy in front of internal tools, cert-manager secrets in app namespaces — and a March 2026 deadline that is not on anyone's roadmap yet.
At Resizes, we migrated production traffic on EKS from Ingress NGINX to Envoy Gateway: dual-run, canary DNS per hostname, NGINX left up until each host was proven on Envoy.
Three days is the DNS cutover window, not the full program. Platform design, Envoy Gateway rollout, and our migration toolkit came first. Those three days were lane conversion, GitOps merges, and moving ~50 hostnames — no user-visible outage, no DNS rollback, no incidents filed in our change log. We scaled NGINX down about a week later, after soak.
