We would like to inform you of an upcoming platform change relating to the retirement of the current NGINX‑based ingress controller, 3rd party software that is used within our Kubernetes environments. This update is part of our ongoing work to ensure the platform remains secure, reliable, and aligned with industry‑standard technologies.
Why is this change happening
The upstream NGINX ingress controller is reaching end‑of‑life and will no longer receive regular updates from March 2026. While the solution has been stable and widely used for many years, its retirement means that ongoing updates will stop.
It’s important to emphasize:
- There is no immediate customer action.
- NGINX ingress has been long‑established and dependable.
- In line with best practice, the Kubernetes cluster and therefore the Ingress should be deployed behind network‑level protections (e.g., firewalls and application gateways), further reducing exposure.
However, to maintain long‑term security, supportability, and compliance across our environments, we are transitioning to a modern alternative ingress technology.
What are we moving to
We are introducing a new, fully supported ingress solution that offers:
- Ongoing maintenance and security updates
- Strong alignment with Kubernetes standards
- Broad community and industry adoption
- A smooth migration path from existing configurations
- Compatibility with our long‑term platform direction
The replacement will continue to provide the same core capabilities as today’s ingress controller, while ensuring long‑term stability and compliance.
Given that all external communication with the application flows through the ingress, extensive testing is required of the new solution to ensure there is a seamless transition with no unexpected impacts.
How the Transition Will Work
The migration will be carried out carefully and gradually and is intended to minimize any disruption.
IFS Cloud Service
The switch to the new ingress controller is intended to be as seamless and transparent as possible to Cloud Service customers.
There are broadly two main steps:
- Platform update: The new ingress software will be applied in parallel with the existing ingress software, in a future maintenance window. Customers do not need to take any action in this phase.
- An IFS Cloud application middle-tier (container) update, to add the required configuration for the new ingress. This will be delivered as part of a Service Update (SU) for the IFS Middle-tier. As this is expected to be a middle-tier only update, customers will not need to apply a full service-update to avail of the change. Rather, once the future Service Update containing the new ingress rules is released, a delivery created in the build-place following this release will contain the new ingress rules. The update will then be applied through the normal delivery deployment process, at which point, it is intended tthat he new ingress will be activated for the environment.
This process will ensure the update is applied in a seamless and controlled manner through non-production environment(s) first, then eventually through to production.
IFS Remote Customers
There will be two main parts to the Ingress migration:
- A platform update to apply the new ingress software to the Kubernetes environment. This will be an update to the base MicroK8S remote solution.
- An IFS Cloud application middle-tier (container) update, to add the required configuration for the new ingress. This will be delivered as part of a Service Update (SU) for the IFS Middle-tier. As this is expected to be a middle-tier only update, customers will not need to apply a full service-update to avail of the change. Rather, once the future Service Update containing the new ingress rules is released, a delivery created in the build-place following this release will contain the new ingress rules and have the ability to switch to use the new ingress
Customer Action Required
To proceed with the Ingress Controller migration, all Use Place (UP) and Build Place (BP) environments must be running a supported IFS Cloud release track and minimum supported Middle Tier (MT) Framework version.
Supported IFS Cloud Release tracks & Minimum Framework Version
| IFS Cloud Release | Minimum Supported MT Framework Version |
| IFS Cloud 24R2 | 24.2.19 or later |
| IFS Cloud 25R1 | 25.1.13 or later |
| IFS Cloud 25R2 | 25.2.7 or later |
| IFS Cloud 26R1 | 26.1.1 or later |
Please note that different IFS Cloud tracks require different minimum framework versions for the Ingress Controller migration (above mentioned). Following the migration, if an environment is required to be upgraded to a newer IFS Cloud track, the framework version must also be upgraded to the minimum supported version for that track. For example, an upgrade from 25R1 to 25R2 requires the framework version to be updated to 25.2.7 or later.
Further details are provided below:
1. Use Place (UP)
- Customers should update their UAT and Production environments to the minimum supported IFS Cloud release and Framework version listed above by 6 November 2026.
- All remaining non-production environments should be updated to the minimum supported Framework versions by 31 January 2027.
- Customers running IFS Cloud releases earlier than 24R2 must upgrade to a supported IFS Cloud release and the corresponding minimum supported Framework version listed above.
- Customers already running IFS Cloud 24R2 or later must update to the applicable minimum supported Framework version listed above if they are currently below that level.
- Please note that all new customer environments provisioned on IFS Cloud 26R1 SU4 (26.1.4) or later will be deployed with the new ingress controller by default.
2. Build Place (BP)
- Customers must update their Build Place environments to the minimum IFS Cloud release and Framework versions listed above by 6 November 2026.
Migration Timeline
IFS Support will perform the ingress controller migration during the November Planned Maintenance Window, as outlined in KB0054982 – IFS Cloud Service Planned Maintenance, for customers who meet the migration prerequisites.
Customers who do not meet the migration prerequisites are requested to complete the required actions at the earliest possible time and raise a support ticket with IFS Support to complete the planned migration.
Risk and Impact of Delayed Customer Action
Customers who do not meet the ingress controller migration prerequisites will not be included in the planned migration and remain using an unsupported version without support, security updates, or bug fixes. Therefore, customers are strongly encouraged to complete the required IFS Cloud release and Framework (SU) upgrades within the timelines specified above.
Additional Documentation
Please refer to the KBA article below for guidance on upgrading the Middle Tier Framework version to the latest available update.