This page helps you choose the most suitable API for
deploying load balancers to distribute traffic across a fleet of
Google Kubernetes Engine (GKE) clusters.

You can attach a load balancer to your fleet of GKE clusters in
the following ways:

1. Use the Multi Cluster Ingress APIs
   such as the [Multi Cluster Ingress](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/multi-cluster-ingress#multiclusteringress_resource)
   and
   [MultiClusterService](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/multi-cluster-ingress#multiclusterservice_resources)
   resources.

2. Use the Gateway APIs
   ([GatewayClass](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/gateway-api#gatewayclass),
   [Gateway](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/gateway-api#gateway),
   [HTTPRoute](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/gateway-api#httproute),
   [Policy](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/gateway-api#policy),
   [ServiceExport](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/deploying-multi-cluster-gateways#mcs),
   and
   [ServiceImport](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/deploying-multi-cluster-gateways#mcs)
   resources).

3. Set up the [Application Load Balancer](https://docs.cloud.google.com/load-balancing/docs/application-load-balancer)
   using Google Cloud console, gcloud CLI, API, Terraform, Config Connector and attach
   [Standalone NEGs](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/standalone-neg) to the
   user-managed backend services.

The following table lists the different ways in which you can attach a
load balancer to your fleet of GKE clusters. Any features listed
in the [Load balancer feature comparison](https://docs.cloud.google.com/load-balancing/docs/features) page
that aren't listed in the following table should work with a
user-managed load balancer with Standalone NEGs, instead of relying on
the Kubernetes-native API for load balancing.

| **Solution** | **Multi Cluster Ingress** | **Multi-cluster Gateway** | **User-managed load balancer with Standalone NEGs** |
| **GKE platform support** |   |   |   |
|---|---|---|---|
| [Product launch stage](https://cloud.google.com/products#section-22) | GA | GA | GA |
| [Cluster mode](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/types-of-clusters) | Standard / Autopilot | Standard / Autopilot | Standard / Autopilot |
| GKE Version | 1.18 and later | GKE 1.24 and later for Standard and 1.26 and later for Autopilot | 1.18 and later |
| Google-managed Kubernetes controller | Yes | Yes |   |
| Controller | [GKE Multi Cluster Ingress controller](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/multi-cluster-ingress#architecture) | [GKE Gateway controller](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/gateway-api#gateway_controller) | - |
| Controller location | Off-cluster (Google Cloud infrastructure) | Off-cluster (Google Cloud infrastructure) | - |
| API | Kubernetes-native API | Kubernetes-native API | Google Cloud API (gcloud CLI) |
| API resources | MultiClusterIngress, MultiClusterService | GatewayClass, Gateway, HTTPRoute, \*Policy | - |
| API launch stage | GA (v1) | GA (v1) | - |
| API enablement on GKE | Cluster setting on Autopilot / Standard | Default on Autopilot Cluster setting on Standard | - |
| Multi-cluster Services (MCS) required | Yes | Yes |   |
| MCS API version | [networking.gke.io/v1](http://networking.gke.io/v1) | [net.gke.io/v1](http://net.gke.io/v1) | - |
| Resource type | MultiClusterService | ServiceExport | - |
| License | Proprietary | Open source | - |
| Automated frontend IP address management | Yes | Yes |   |
| Automated Cloud Load Balancer management - Forwarding rule - Target proxy - URL map - Backend services - Health checks | Yes | Yes |   |
| Automated Network Endpoint Groups (NEGs) management | Yes ([Zonal NEGs](https://docs.cloud.google.com/load-balancing/docs/negs/zonal-neg-concepts#gce-vm-ip-port) only) | Yes ([Zonal NEGs](https://docs.cloud.google.com/load-balancing/docs/negs/zonal-neg-concepts#gce-vm-ip-port) only) | Yes ([Zonal NEGs](https://docs.cloud.google.com/load-balancing/docs/negs/zonal-neg-concepts#gce-vm-ip-port) only, annotation required on the Kubernetes Service) |
| Cloud NGFW management | Yes ([VPC firewall rules](https://docs.cloud.google.com/firewall/docs/firewalls) only, [Managed rules](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/firewall-rules#ingress-fws)) | Yes ([VPC firewall rules](https://docs.cloud.google.com/firewall/docs/firewalls) only, [Managed rules](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/firewall-rules#gateway-fws)) |   |
| Clusters and fleet (Hub) in the host project | Yes | Yes | Yes |
| Clusters and fleet (Hub) in the same service project | Yes ([with firewall rules permissions in host project](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/ingress#shared_vpc)) | Yes (with firewall rules permissions in host project) | Yes |
| Clusters and fleet (Hub) in different projects |   |   | Yes (with[cross-project Service referencing](https://docs.cloud.google.com/load-balancing/docs/https#cross-project)) |
| [Application load balancers](https://docs.cloud.google.com/load-balancing/docs/application-load-balancer) |   |   |   |
| Classic | Yes | Yes | Yes |
| Global external |   | Yes | Yes |
| Regional external |   | Yes | Yes |
| Regional internal |   | Yes | Yes |
| Cross-region internal |   |   | Yes |
| [Proxy Network Load Balancers](https://docs.cloud.google.com/load-balancing/docs/proxy-network-load-balancer) |   |   |   |
| Classic |   |   | Yes |
| Global external |   |   | Yes |
| Regional external |   |   | Yes |
| Internal (Always regional) |   |   | Yes |
| [Passthrough Network Load Balancers](https://docs.cloud.google.com/load-balancing/docs/passthrough-network-load-balancer) |   |   |   |
| External (Always regional) |   |   |   |
| Internal (Always regional) |   |   |   |
| HTTP, HTTPS, HTTP/2 | Yes | Yes | Yes |
| [WebSocket](https://docs.cloud.google.com/load-balancing/docs/https#websocket-support) | Yes | Yes | Yes |
| HTTP/3 (based on IETF QUIC) |   |   | Yes |
| SSL (TLS) or TCP |   |   | Yes |
| Pods (Zonal NEGs) | Yes | Yes | Yes |
| Virtual Machines (including GKE nodes) | Yes ([Not recommended](https://docs.cloud.google.com/kubernetes-engine/docs/concepts/ingress#container-native_load_balancing)) |   | Yes |
| Other backends: - Cloud Storage - Public external endpoints (Internet NEGs) - Private external endpoints (Hybrid NEGs) - Private Service Connect (PSC NEGs) - Cloud Run (Serverless NEGs) |   |   | Yes |
| HTTP, HTTPS, HTTP/2 (One of) | Yes | Yes | Yes |
| [WebSocket](https://docs.cloud.google.com/load-balancing/docs/https#websocket_support) | Yes | Yes | Yes |
| SSL (TLS) or TCP (One of) |   |   | Yes |
| Dynamic IP address assignment | Yes | Yes | Yes |
| Static IP address assignment | Yes | Yes | Yes |
| Same IP address for multiple ports (HTTP, HTTPS) | Yes | Yes | Yes |
| IPv6 | Yes (Load balancer-to-backend traffic remains IPv4) | Yes (Load balancer-to-backend traffic remains IPv4) | Yes (Load balancer-to-backend traffic remains IPv4) |
| Global access |   | Yes | Yes |
| Cross-project load balancing |   |   | Yes |
| Host/Path routing | Yes (Prefix, Exact match) | Yes (Prefix, Exact match) | Yes |
| Header-based routing |   | Yes (Exact match) | Yes |
| Path redirects |   | Yes | Yes |
| URL rewrites |   | Yes | Yes |
| Traffic splitting |   | Yes | Yes |
| Traffic mirroring |   | Yes | Yes |
| Traffic cut over |   | Yes | Yes |
| Traffic-based autoscaling |   | Yes | Yes |
| Custom request headers | Yes | Yes | Yes |
| Custom response headers |   | Yes | Yes |
| Cross-namespace routing |   | Yes | Yes |
| SSL policy | Yes | Yes | Yes |
| HTTP-to-HTTPS redirect | Yes | Yes | Yes |
| Multiple TLS certificates support | Yes | Yes | Yes |
| Kubernetes Secrets-based certificates | Yes | Yes |   |
| Self-managed SSL certificates | Yes | Yes | Yes |
| Google-managed SSL certificates | Yes | Yes | Yes |
| Certificate Manager support |   | Yes | Yes |
| Connection draining timeout | Yes | Yes | Yes |
| Session affinity | Yes | Yes | Yes |
| HTTP access logging configuration | Yes | Yes | Yes |
| Backend service timeout | Yes | Yes | Yes |
| Custom load balancer health check configuration | Yes [(BackendConfig)](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/ingress-configuration#configuring_ingress_features_through_backendconfig_parameters) | Yes [(HealthCheckPolicy)](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/configure-gateway-resources#configure_health_check) | Yes [(gcloud CLI / Google Cloud console / Terraform)](https://docs.cloud.google.com/load-balancing/docs/health-checks) |
| TLS to backend services | Yes | Yes | Yes |
| Custom default backend |   | Yes | Yes |
| [Cloud CDN](https://docs.cloud.google.com/cdn/docs/overview) | Yes Not all features: signed cookies, dynamic compression, and private origin authentication are not supported | Yes Not all features: signed URLs and dynamic compression are not supported | Yes All features |
| [Identity-Aware Proxy (IAP)](https://docs.cloud.google.com/iap/docs/concepts-overview) | Yes | Yes | Yes |
| [Google Cloud Armor security policy](https://docs.cloud.google.com/armor/docs/security-policy-concepts) | Yes | Yes | Yes |

## What's next

- [Set up multi-cluster Ingress](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/multi-cluster-ingress-setup).
- [Deploying Ingress across clusters](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/multi-cluster-ingress).
- [Enable multi-cluster Gateway](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/enabling-multi-cluster-gateways).
- [Deploy multi-cluster Gateways](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/deploying-multi-cluster-gateways).
- [Container-native load balancing through standalone zonal NEGs](https://docs.cloud.google.com/kubernetes-engine/docs/how-to/standalone-neg).