---
title: "Ingress"
description: "the Gateway API implementation in front of the API gateway, one copy per machine sharing certificates through secrets"
section: concepts
address: /concepts/ingress
contract: 0476e35e6e275db5
---

# Ingress

the Gateway API implementation in front of the API gateway, one copy per machine sharing certificates through secrets

[figure: Ingress is a definition at platform scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | platform |
| key | its name |
| store | postgres |
| family | network |



## Fields


| field | type | required | note |
|---|---|---|---|
| `implementation` | `text` | yes | Envoy Gateway recommended |
| `routes` | [Route](/concepts/route) | yes |  |
| `copies` | `count` | yes | one per machine |
| `trusted_proxies` | `[address]` | yes | only the load balancer |
| `connection_limits` | [ConnectionLimits](/concepts/connectionlimits) | yes |  |



## Routes that use it
No route takes or returns Ingress directly. The record holds it, and the objects that point at it reach it.
