Project Lightning Talk: What's New in k8gb: CNCF's Multicluster Global Balancer - Bradley Andersen

Bradley Andersen

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

In this lightning talk at KubeCon EU, Bradley Andersen, Community Manager for k8gb, provided a comprehensive update on k8gb, a Global Service Load Balancer (GSLB) for Kubernetes. The project addresses the critical need for distributing applications across multiple geographical regions—such as Europe, the United States, or China—to ensure both low latency for users and high availability for services. k8gb distinguishes itself as a cloud-native, Kubernetes-native solution, implemented using the familiar Kubernetes operator pattern and a single GSLB Custom Resource Definition (CRD).

Watch on YouTube

Visual summary for Project Lightning Talk: What's New in k8gb: CNCF's Multicluster Global Balancer - Bradley Andersen by Bradley Andersen
Visual summary for Project Lightning Talk: What's New in k8gb: CNCF's Multicluster Global Balancer - Bradley Andersen by Bradley Andersen

Key moments

  1. 0:00 Introduction to k8gb: Global Service Load Balancer
  2. 1:00 k8gb architecture: Kubernetes operators and DNS updates
  3. 2:20 Core components and cross-cluster synchronization diagram
  4. 3:10 GlobalServiceLoadBalancer CRD and strategy types
  5. 4:00 Project status, incubation efforts, and Q2 roadmap
  6. 4:30 Community involvement and how to contribute to k8gb

Project Lightning Talk: What's New in k8gb: CNCF's Multicluster Global Balancer

Speakers: Bradley Andersen, Community Manager, k8gb

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=YMyrcqZ2sbU

Overview

In this lightning talk at KubeCon EU, Bradley Andersen, Community Manager for k8gb, provided a comprehensive update on k8gb, a Global Service Load Balancer (GSLB) for Kubernetes. The project addresses the critical need for distributing applications across multiple geographical regions—such as Europe, the United States, or China—to ensure both low latency for users and high availability for services. k8gb distinguishes itself as a cloud-native, Kubernetes-native solution, implemented using the familiar Kubernetes operator pattern and a single GSLB Custom Resource Definition (CRD).

Andersen highlighted k8gb's vendor-neutral and environment-agnostic design, emphasizing its unique position as, what they believe, is the only cloud-native Kubernetes GSLB. As a CNCF Sandbox project currently seeking incubation status, k8gb aims to commoditize global load balancing by integrating it seamlessly into the Kubernetes ecosystem, leveraging existing primitives like liveness and readiness probes for health checks and enabling cross-cluster state synchronization. The talk served as both an introduction for newcomers and an update on recent developments and future plans for the growing k8gb community.

Background

▶ Watch: Introduction to k8gb: Global Service Load Balancer (0:00)

The modern application landscape demands global reach and unwavering resilience. Organizations increasingly deploy their services across multiple cloud regions or even hybrid environments to minimize latency for geographically dispersed users and to protect against regional outages. While Kubernetes has revolutionized application deployment and management within a single cluster, orchestrating and load balancing applications across multiple Kubernetes clusters in a globally distributed manner presents a unique set of challenges.

Traditional GSLB solutions often exist outside the Kubernetes ecosystem, requiring complex integrations, separate management interfaces, and bespoke configurations that don't align with the declarative, API-driven nature of Kubernetes. These external solutions can introduce a single point of failure or significant operational overhead, negating some of the benefits of a cloud-native architecture. The problem k8gb seeks to solve is the absence of a truly Kubernetes-native, open-source solution that can intelligently route traffic based on factors like geographic proximity and application health across disparate Kubernetes clusters. k8gb has been under development for approximately five years, spending four of those years as a CNCF Sandbox project, demonstrating a sustained effort to bring this critical capability directly to the cloud-native community.

Key Findings

▶ Watch: Core components and cross-cluster synchronization diagram (2:20)

k8gb's core contribution lies in its innovative approach to integrating global load balancing directly into the Kubernetes control plane. The key findings and design principles presented by Bradley Andersen underscore its distinct advantages:

  • Cloud-Native GSLB: k8gb provides an independent GSLB capability that is entirely Kubernetes-native. It doesn't rely on external, proprietary systems for its core functionality, making it a natural extension of a Kubernetes deployment.
  • No Dedicated Management Cluster: A significant design choice is the absence of a central management cluster, which eliminates a single point of failure. Instead, k8gb's operators, deployed within each participating cluster, are responsible for their local state and communicate directly with each other to achieve global awareness.
  • Kubernetes-Native Health Checks: k8gb leverages familiar Kubernetes mechanisms, specifically liveness and readiness probes, to determine the health of applications. This means developers and operators don't need to learn new health-checking paradigms, simplifying adoption and integration.
  • Cross-Cluster Synchronization: A critical component of k8gb is its ability for operators in different clusters to communicate and synchronize their understanding of the global application state. If an application in one region becomes unhealthy, this status is propagated, allowing other regions to update DNS records accordingly.
  • Vendor-Neutral and Environment Agnostic: The project is designed to operate seamlessly across various cloud providers (e.g., GCP, AWS, Azure) and on-premises environments, offering flexibility without vendor lock-in.
  • Simplified Configuration via GSLB CRD: Global load balancing rules are defined declaratively through a single GSLB CRD, making configuration straightforward and consistent with other Kubernetes resources. This "commoditizes" GSLB by making it as easy as deploying a YAML file.

Technical Deep Dive

▶ Watch: GlobalServiceLoadBalancer CRD and strategy types (3:10)

k8gb’s architecture is built around the fundamental principles of Kubernetes, leveraging its extensibility and declarative nature to deliver a robust global load balancing solution. At its heart, k8gb is implemented as a set of Kubernetes operators. These operators are specialized controllers that continuously monitor the Kubernetes API server for changes to specific custom resources—in this case, the Global Service Load Balancer (GSLB) CRD. When a GSLB resource is created, updated, or deleted, the k8gb operator springs into action, ensuring that the desired global load balancing state is achieved and maintained.

The GSLB CRD is the central configuration point for defining how applications should be globally balanced. Within its spec section, key parameters dictate routing behavior:

  • The kind field specifies the type of Kubernetes networking object that k8gb should monitor and manage. Currently, it supports standard Ingress resources and VirtualService objects (commonly used with service meshes like Istio). Bradley Andersen also mentioned plans for Gateway API integration in the upcoming quarter (Q2), indicating future-proofing and broader compatibility with evolving Kubernetes networking standards.
  • The strategy field is crucial, defining the global traffic distribution logic. k8gb offers several strategies to cater to various use cases:
  • Failover: This strategy designates a primary cluster and one or more secondary clusters. Traffic is directed to the primary as long as it's healthy, failing over to a secondary if the primary becomes unavailable.
  • RoundRobin: Requests are distributed evenly among all healthy clusters, providing a simple and effective load distribution mechanism.
  • WeightedRoundRobin: Allows administrators to assign different weights to clusters, directing a proportional amount of traffic to each based on its specified weight. This is useful for canary deployments, A/B testing, or gradually shifting traffic.
  • GeoIP: Perhaps the most compelling strategy for global deployments, GeoIP routes users to the geographically closest healthy cluster. This minimizes network latency and significantly improves user experience by serving content from a nearby data center.

The operational flow hinges on continuous health monitoring and dynamic DNS updates. Each k8gb operator within a cluster monitors the health of its local applications using standard Kubernetes liveness and readiness probes. If a probe indicates an unhealthy state for a particular application instance or an entire cluster, the local operator records this status.

Crucially, k8gb implements cross-cluster sync polling. This mechanism allows operators in different regions to communicate and share their local health status. If, for instance, a cluster in Region A goes down, the k8gb operator in Region B will be notified of this state change. This distributed awareness ensures that no single cluster makes routing decisions in isolation.

For external DNS management, k8gb integrates with ExternalDNS, which is responsible for enabling zone delegation and updating DNS records in various providers. CoreDNS typically handles internal DNS resolution within the Kubernetes clusters. k8gb supports a range of popular DNS providers, including Route 53 (AWS), Infoblox, and any DNS server compliant with RFC 2136 (Dynamic Updates in the Domain Name System), offering broad compatibility for enterprise environments. When a cluster's applications are deemed unhealthy, the k8gb operators, through ExternalDNS, update the global DNS records to remove the unhealthy cluster from the rotation, ensuring that traffic is only directed to available and performing instances.

Demo / Proof of Concept

▶ Watch: Project status, incubation efforts, and Q2 roadmap (4:00)

While Bradley Andersen's talk was a lightning update and did not feature a live, interactive demonstration, he effectively conveyed k8gb's operational model and configuration simplicity through conceptual walkthroughs and visual aids. A key component of this "proof of concept" was a detailed architectural diagram illustrating the multi-cluster setup. This diagram clearly depicted the k8gb controllers deployed in different geographical regions, highlighting the vital cross-cluster sync polling mechanism that enables operators to share state and make informed global routing decisions. The roles of CoreDNS for internal resolution and ExternalDNS for managing external DNS records were also clearly delineated within this visual representation.

Further emphasizing the ease of use, Andersen presented a snippet of the GSLB CRD YAML. This concrete example showcased the declarative nature of k8gb, allowing attendees to understand how global load balancing rules—including the kind of service (e.g., Ingress) and the chosen strategy (e.g., GeoIP, Failover)—are defined. The speaker stressed that users simply "plop in a YAML file," and the k8gb operator handles the underlying implementation and resource management. This conceptual demonstration effectively communicated how k8gb simplifies the complex task of global traffic management into a familiar Kubernetes workflow, making it accessible even to those new to the project.

Defensive Implications

▶ Watch: Community involvement and how to contribute to k8gb (4:30)

k8gb, while not a traditional security tool, offers significant defensive implications by substantially enhancing the resilience, availability, and fault tolerance of applications deployed on Kubernetes. In an era where application downtime can lead to severe reputational and financial damage, these capabilities are paramount for a robust defensive posture.

Firstly, k8gb dramatically improves disaster recovery capabilities. By distributing application instances across multiple geographically distinct Kubernetes clusters and intelligently routing traffic based on health, it provides an inherent defense against regional outages, natural disasters, or widespread network failures. If an entire cloud region or data center becomes unavailable, k8gb's automatic failover strategies ensure that users are seamlessly directed to healthy instances in other regions, minimizing service disruption. This proactive approach to availability is a critical layer in any comprehensive defense strategy.

Secondly, the continuous and Kubernetes-native health checks, utilizing standard liveness and readiness probes, mean that k8gb is constantly verifying the operational status of applications. This rapid detection of application-level failures, combined with the cross-cluster synchronization and dynamic DNS updates, ensures that traffic is never sent to unhealthy endpoints. This prevents cascading failures and maintains a high level of service availability, which can be seen as a defense against poor user experience and potential business interruption.

Furthermore, the implementation's distributed nature, without a dedicated management cluster, eliminates a single point of failure for the GSLB itself. This architectural choice inherently fortifies the global load balancing mechanism against its own potential outages, ensuring that the system designed to prevent downtime doesn't become a source of it. By offering strategies like GeoIP, k8gb also contributes to a better user experience by reducing latency, which, while not a direct security measure, is a crucial aspect of overall system reliability and can prevent users from seeking out potentially less secure alternatives due to performance issues.

Finally, by "commoditizing" global load balancing within Kubernetes, k8gb simplifies operational complexity. This reduction in management overhead allows platform teams to allocate more resources and focus on core security initiatives, patch management, and threat detection, rather than wrestling with complex, external GSLB integrations. This operational efficiency indirectly strengthens the defensive posture of the entire cloud-native environment.

Key Takeaways

  • k8gb is a cloud-native, Kubernetes-native Global Service Load Balancer designed for high availability and low latency across geo-distributed applications.
  • It leverages Kubernetes operators and a single GSLB CRD for simple, declarative configuration and management of global traffic routing.
  • Key features include cross-cluster synchronization, Kubernetes-native health checks (liveness/readiness probes), and support for various strategies like Failover, RoundRobin, WeightedRoundRobin, and GeoIP.
  • As a CNCF Sandbox project with an active community and plans for incubation, k8gb is a maturing open-source solution for multi-cluster application management.
  • It significantly enhances application resiliency and availability by eliminating single points of failure and automating regional failover based on real-time health data.
  • The project supports a wide range of DNS providers (e.g., Route 53, Infoblox, RFC 2136) and is actively developing integration with the Gateway API.

About the Speaker(s)

Bradley Andersen is identified as a Community Manager for k8gb. His role involves fostering engagement and growth within the k8gb open-source project. This is evident through his emphasis on community involvement, encouraging attendees to star the project on GitHub (currently at 961 stars, aiming for over a thousand), read the documentation, join the Slack channel, and attend regular bi-weekly community meetings. He also highlighted the presence of k8gb maintainers and company adopters at the KubeCon project pavilion, reinforcing his commitment to building and supporting the k8gb community.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This lightning talk provides a solid, no-bullshit update on k8gb, a critical CNCF project addressing global service load balancing for multi-cluster Kubernetes. It details a genuinely cloud-native approach, leveraging Kubernetes primitives for high availability and low latency across distributed applications. For anyone grappling with multi-region deployments, this isn't just theory; it's a practical, well-engineered solution.

Heather Calloway (CISO) — STRONG ACCEPT

k8gb presents a highly relevant and actionable solution for managing critical business risk related to application availability and resilience across multi-cluster Kubernetes deployments. While not a direct security control, its ability to automate global load balancing and failover significantly strengthens an organization's defensive posture against regional outages and ensures business continuity. This directly addresses board-level concerns regarding uptime commitments and operational resilience, making it a valuable tool for any CISO overseeing cloud-native infrastructure.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025