Dev iconDevSep 15, 2026 ~1 min source read

Protect Kubernetes Services with OAuth2 Proxy, Gateway API, Traefik, and Pocket ID

That controller is being retired, and Gateway API is the direction Kubernetes recommends for new traffic management work. My previous guide used ingress-nginx annotations to put internal Kubernetes services behind OAuth2 Proxy.

Protect Kubernetes Services with OAuth2 Proxy, Gateway API, Traefik, and Pocket ID

Share this story

Send the public story page.

Useful takeaways from this story.

My previous guide used ingress-nginx annotations to put internal Kubernetes services behind OAuth2 Proxy.

Gateway API standardizes Gateway and HTTPRoute, but it does not standardize browser-based OIDC login or an external-auth filter.

That controller is being retired, and Gateway API is the direction Kubernetes recommends for new traffic management work.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

My previous guide used ingress-nginx annotations to put internal Kubernetes services behind OAuth2 Proxy. That controller is being retired, and Gateway API is the direction Kubernetes recommends for new traffic management work. This post rebuilds the same authentication flow with Gateway API, Traefik, OAuth2 Proxy, and Pocket ID.

How it works

  • Gateway API standardizes Gateway and HTTPRoute, but it does not standardize browser-based OIDC login or an external-auth filter.
  • With Envoy Gateway, Kong, Cilium, or another implementation, the Gateway API resources can stay, but the authentication adapter must change.
  • What we are building This setup exposes three HTTPS hostnames below one domain: pocket-id.k8s.example.com is the Pocket ID UI and OIDC issuer.
  • One parent domain lets OAuth2 Proxy use a narrowly scoped shared session cookie, such as.k8s.example.com.
  • Do not set the cookie domain to a wider parent domain when unrelated applications use it.

What to take from it

sequenceDiagram autonumber participant B as Browser participant T as Traefik Gateway participant O as OAuth2 Proxy participant P as Pocket ID participant S as whoami B->>T: GET whoami.k8s.example.com T->>O: ForwardAuth /oauth2/auth O-->>T: 401 (no session) T-->>B: 302 /oauth2/sign_in?rd=...

Details worth keeping

This setup uses Traefik's Middleware CRD for those pieces. auth.k8s.example.com serves OAuth2 Proxy endpoints. whoami.k8s.example.com is a protected demo service.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app