Community Ingress NGINX retirement: what it means for your Kubernetes strategy.

Community Ingress NGINX retirement: what it means for your Kubernetes strategy.

Kubernetes SIG Network and the Security Response Committee have announced the retirement of the Community Ingress NGINX Controller — a decision that will impact a large part of the Kubernetes ecosystem. 

“Best effort” maintenance will continue until March 2026. After that, the project will no longer receive updates, bug fixes, or security patches. 

While existing deployments will continue to run, they will do so without any security or support guarantees — raising important questions for organizations relying on it in production. 

What is changing — and why it matters.

 

Ingress NGINX has long been a core component for exposing Kubernetes applications. 

From March 2026 onward, the Community Ingress NGINX project will no longer receive: 

  • security patches  
  • vulnerability remediation (CVE fixes)  
  • functional updates  

Kubernetes SIG Network recommends starting a migration now, either toward the Gateway API or another supported Ingress controller. 

From a security and governance perspective, continuing to run an unmaintained component introduces increasing risk over time. 

No immediate disruption — but increasing risk.

 

It’s important to clarify:
applications will not suddenly stop working in March 2026. 

However, the situation will evolve progressively: 

  • no future vulnerabilities will be fixed  
  • compatibility with future Kubernetes versions becomes uncertain  
  • security teams lose visibility and control  

For critical, exposed, or regulated environments, this quickly becomes a strategic decision — not just a technical one. 

What are your options?

 

Organizations essentially have two main paths. 

  1. Move to the Kubernetes Gateway API

The Gateway API is the long-term direction recommended by Kubernetes. It brings: 

  • role-oriented architecture  
  • standardized APIs  
  • improved portability  

Many implementations already exist: https://gateway-api.sigs.k8s.io/implementations/ 

That said, this is a significant architectural shift, which can be complex for existing environments. 

  1. Adopt a supported Ingress alternative

Community Ingress NGINX is not the only Ingress Controller available. 

Several actively maintained alternatives exist, including those listed by Kubernetes: https://kubernetes.io/docs/concepts/services-networking/ingress-controllers/ 

For teams already using NGINX, F5 NGINX Ingress Controller (OSS) offers a natural and sustainable evolution: 

  • open source (Apache 2.0)  
  • actively maintained  
  • technological continuity  
  • compatible with future Gateway API adoption  

A pragmatic approach to migration.

 

There is no one-size-fits-all path. 

In practice, successful migrations are: 

  • progressive  
  • controlled  
  • aligned with business and security priorities  

Most organizations benefit from stabilizing their current environments first, securing them properly, and then planning a gradual transition. 

What should you do next?

 

If you are: 

  • running Kubernetes or OpenShift in production  
  • evaluating Gateway API  
  • or looking to reduce your security exposure  

Now is the right time to assess your situation and define a clear migration strategy. 

e-Xpert Solutions’ SOC Achieves ISAE 3000 Attestation.

e-Xpert Solutions’ SOC Achieves ISAE 3000 Attestation.

e-Xpert Solutions’ SOC Achieves ISAE 3000 Attestation.

We are proud to announce that we has obtained the ISAE 3000 attestation for its Security Operations Center (SOC), issued by Deloitte. This independent assurance confirms that the SOC operates with robust, continuously applied controls across critical domains, from governance and technical security to client isolation, access management, traceability, documentation, and operational quality.

What ISAE 3000 Means

Unlike typical certifications, ISAE 3000 requires auditors to verify real operational evidence—not just policies or intentions—any day within the past 12 months. The audit focuses on consistent, daily execution of controls, making this attestation a true reflection of operational excellence, not a one-time achievement. e-Xpert Solutions is currently the only SOC in Western Switzerland to hold this level of assurance.

The Scope of the Attestation

The SOC successfully demonstrated 19 critical controls, covering areas that matter most to CISOs:

  • Access governance: strict and traceable controls over user access
  • SOC/client isolation: verified and automated separation between internal and client systems
  • Monitoring and detection: advanced tools, including custom attack simulations and new IDS sensors
  • Operational quality and processes: resilient internal processes, continuous improvement, and thorough documentation
  • Traceability and recording: full visibility into all SOC and client activities

Achieving this required a combination of deep technical upgrades, rigorous process management, and meticulous documentation.

What This Means for you, Our Clients

For clients, the ISAE 3000 attestation provides an unprecedented level of transparency and assurance. It validates that the SOC doesn’t just define security practices—it executes them, maintains them, and proves them every day.

The Teams Behind the Achievement

This milestone would not have been possible without the dedication, expertise, and perseverance of the SOC team, supported by compliance, HR, technical, and management colleagues. Every individual’s contribution—from designing and implementing technical controls to ensuring documentation, reporting, and quality—was essential.

Thank you to all involved. This attestation reflects your work, your rigor, and your commitment to operational excellence.

The Managed SOC Service “At-Defense” by e-Xpert Solutions

The Managed SOC Service “At-Defense” by e-Xpert Solutions

Cybersecurity is no longer a luxury – it’s a vital necessity. In Switzerland, cyberattacks are on the rise: over 2,700 companies were targeted by ransomware in a single year, and one-third of SMEs suffered attacks in 2021. In response to this growing threat, Geneva-based cybersecurity specialist e-Xpert Solutions, with over 20 years of experience, offers a proactive defense solution: AT-Defense, a managed Security Operations Center (SOC) designed to meet today’s challenges.

Why choose AT-Defense ?

24/7 Continuous Monitoring

Thanks to a dedicated team of security experts, AT-Defense provides real-time threat detection, immediate incident response, and full crisis management. The service operates around the clock, with a guaranteed response time of under one hour in 24/7 mode.

Offensive and Defensive Expertise

The SOC is powered by a certified multidisciplinary team (GCIH, GCFA, GREM), with expertise in incident response, forensic analysis, threat hunting, and vulnerability research. e-Xpert Solutions’ experts are also key contributors to the cybersecurity community (MITRE ATT&CK, publications, etc.).

Turnkey Managed Service

With rapid deployment (2 days on-site), intuitive dashboards via Splunk, centralized log management, honeypots, darknet leak detection, and weekly reports, AT-Defense is designed for simplicity and efficiency. The service includes a strict quality control process (false positive review, four-eyes principle).

Reduced Operational Burden

By outsourcing security monitoring, organizations free themselves from operational complexity while maintaining full control through a personalized monitoring portal.

ISO 27001 Certified Solution

Our SOC has been ISO 27001 certified since 2021 – a guarantee of compliance with the highest international information security standards.

Cutting-Edge Technology, Proven Expertise

AT-Defense leverages top-tier technologies: real-time SIEM correlation, attacker-trapping honeypots, advanced sensors, threat hunting capabilities, and more.

Behind the infrastructure, a team of 10 certified security experts (GCIH, GCFA, GREM) ensures high-level monitoring, backed by their experience in both offensive and defensive security, and their recognized contributions (MITRE ATT&CK, publications, conferences…).

Fast, Agile, and Tailored Response

✔️ Deployed in just 2 days with on-site assistance
✔️ Responsive SLA with under 1-hour reaction time (24×7 mode)
✔️ Easy integration into client environments
✔️ Scalable services: IRaaS, managed XDR, advanced threat detection, etc.

Why choose e-Xpert Solutions?

Founded in 2001, e-Xpert Solutions is an independent Swiss company recognized for the quality of its services and its commitment to cybersecurity. AT-Defense is a clear reflection of this vision: a reliable, expert-driven, quickly deployed solution with controlled costs, low internal impact, and a high level of protection.

[ VIDEO ] Course aux 0Days, au secours !!

[ VIDEO ] Course aux 0Days, au secours !!

[ VIDEO ] Course aux 0Days, au secours !!

Face aux 0Days, les équipes de cybersécurité sont bien souvent limitées et peuvent parfois se sentir démunies devant l’ampleur du phénomène qui ne fait que s’amplifier depuis ces dernières années.

Dans cette vidéo, notre expert Michael Molho, va vous donner 5 conseils pour atteindre un bon niveau de sécurité et vous aider à gérer au quotidien les 0days.

[ Vulnérabilité #Log4J ] Formation, Synthèse & Information par nos experts.

[ Vulnérabilité #Log4J ] Formation, Synthèse & Information par nos experts.

[ Vulnérabilité #Log4J ] Formation, Synthèse & Information par nos experts.

Depuis jeudi 9 décembre, le tremblement de terre Log4j déclenche un vent de panique et de messages plus ou moins fiables dans notre quotidien professionnel.

Après quelques jours d’échanges avec nos fournisseurs, clients et partenaires, nous réalisons que cette crise est non seulement majeure mais surtout que son impact est encore mal apprécié.
Nos experts sont mobilisés 24h / 24h depuis vendredi dernier pour assister notre clientèle dans cette compréhension, l’élaboration de plan d’action et le développement d’outils logiciels de “threat hunting”.

D’où vient-elle ? Quels sont les composants impactés ? Comment se protéger ? Comment la détecter ? Que faire en cas de compromission ?
Autant d’interrogations auxquelles un de nos experts vous répond de la manière la plus claire et complète possible. Vous comprendrez notamment pourquoi les systèmes non exposés sur Internet sont concernés par cette attaque au même titre que les systèmes frontaux.

[ Vulnérabilité #Log4J ] Formation, Synthèse & Information par nos experts.

[ Log4Shell ] At-Defense Research

[ Log4Shell ] At-Defense Research

Dear All,

These last days were marked by the “Most sensitive vulnerability ever published on Internet” aka Log4j. Our team of researchers and SOC analysts worked hard since friday to create detections rules and prevent exploitation for our SOC customers.

Due to the criticity of this vulnerability we decided to publish our detections tools and some of signatures to help the community facing this huge issue.

You can find them on :

https://github.com/e-XpertSolutions/atdefense-research/tree/master/log4shell

This repository contains: – Updated IOC – Threat Hunting tool developped for both Linux & Windows to identify potentially impacted servers, and compromissions For the windows version it also supports large scale deployments – IDS (Intrusion Detection System) rules fully developped by e-Xpert researchers with a new (and unseen approach). Indeed, all published rules will collect flood of external attacks (impossible to differentiate from sucess one) and so are not of great interest…

These new rules used a completely different approach relying on the detection of ingoing/outgoing external LDAP trafic used in >90% of exploitation attempts.

If you did not consider this vulnerability you should use our tools quickly.

We hope that you will enjoy, keep safe.

AT-Defense SOC Team
e-Xpert Solutions.

en_GB