manages external access to the services in a cluster, typically HTTP • Typically, services and pods have IPs only routable by the cluster network. All traffic that ends up at an edge router is either dropped or forwarded elsewhere • An Ingress Gateway describes a load balancer operating at the edge of the mesh receiving incoming or outgoing HTTP/TCP connections