We had a use case to expose Kubernetes Gateway API from a multi-tenant AKS cluster through Azure Application Gateway. The integration wasn't straightforward—health probes failed, backends showed unhealthy, and traffic wouldn't flow. This post details a solution that addresses these integration challenges.
Since this solution and POC is based on K8s Gateway API on AKS, as a bonus this approach aligns well with the broader Kubernetes ecosystem direction. With Ingress-NGINX being retired in March 2026 and Ahmed Sabbour, Principal PM Lead for Azure Kubernetes Service, confirming that AKS Application Routing will be powered by Istio and Gateway API in H1 2026, adopting Gateway API now positions you well for the future.
I have developed a POC to demonstrate how to set up K8s Gateway API on AKS and solve the integration challenges when exposing it via Azure Application Gateway in a multi-tenant environment. The complete solution is available at Github
The Challenge
Integrating Kubernetes Gateway API with Azure Application Gateway in a multi-tenant AKS cluster isn't as straightforward as it should be. When I attempted this integration, I encountered several issues:
- Health probes failing - Application Gateway couldn't verify backend health
- Backends marked unhealthy - Despite pods running correctly
- Connection timeouts - Traffic wouldn't flow through the expected path
- No clear documentation - Limited guidance for this specific architecture
This POC documents the solution to these challenges, providing a working reference architecture for teams facing similar requirements.
The POC Solution
The POC deploys two sample applications (app1 and app2) in an AKS cluster, exposed via Kubernetes Gateway API and accessed through Azure Application Gateway.
| Component | Description |
|---|---|
| sample-app-1 | Nginx pod returning "Hello from App 1" on path /app1 |
| sample-app-2 | Nginx pod returning "Hello from App 2" on path /app2 |
| health-responder | Dedicated pod for Application Gateway health probes on /healthz |
| Istio Gateway | Shared Gateway resource implementing K8s Gateway API |
| HTTPRoutes | Per-path routing rules in application namespaces |
Each application has its own HTTPRoute in its namespace, demonstrating the self-service routing model where application teams manage their own routes while sharing a common gateway infrastructure.
Note: To keep this POC simple and focused on the Azure integration challenges, app1 and app2 simulate applications running in two separate tenants inside the AKS cluster. I am planning a separate blog post on how to set up multi-tenancy on Kubernetes with Capsule and K8s Gateway API.

