AWS ALB Controller Now Supports Kubernetes Gateway API with OIDC JWT Validation
AWS has announced general availability of Load Balancer Controller support for the Kubernetes Gateway API, along with new custom resource definitions for managing ELB listeners and target rules declaratively. The setup enables developers to secure public EKS cluster endpoints using OIDC authorization and JWT token validation handled entirely on the AWS side. Keycloak serves as the OIDC identity provider in this configuration, with Cloud-IAM offering a free managed Keycloak instance suitable for testing. Envoy is deployed minimally to proxy the Kubernetes API at Layer 4, while all authentication and validation responsibilities remain with AWS infrastructure. The approach is deployable via FluxCD and provisioned using Terraform or OpenTofu, with full working examples available for reference.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in