Skip to main content
Version: Next

Configuration File

The APISIX Ingress Controller uses a configuration file config.yaml to define core settings such as log level, leader election behavior, metrics endpoints, and sync intervals.

Configurations are defined in a Kubernetes ConfigMap and mounted into the controller pod as a file at runtime. To apply changes, you can update the ConfigMap and restart the controller Deployment to reload the configurations.

Below are all available configuration options, including their default values and usage:

log_level: "info"                               # The log level of the APISIX Ingress Controller.
# The default value is "info".

controller_name: apisix.apache.org/apisix-ingress-controller # The controller name of the APISIX Ingress Controller,
# which is used to identify the controller in the GatewayClass.
# The default value is "apisix.apache.org/apisix-ingress-controller".
leader_election_id: "apisix-ingress-controller-leader" # The leader election ID for the APISIX Ingress Controller.
# The default value is "apisix-ingress-controller-leader".
leader_election:
lease_duration: 30s # lease_duration is the duration that non-leader candidates will wait
# after observing a leadership renewal until attempting to acquire leadership of a
# leader election.
renew_deadline: 20s # renew_deadline is the time in seconds that the acting controller
# will retry refreshing leadership before giving up.
retry_period: 2s # retry_period is the time in seconds that the acting controller
# will wait between tries of actions with the controller.
disable: false # Whether to disable leader election.

metrics_addr: ":8080" # The address the metrics endpoint binds to.
# The default value is ":8080".

enable_http2: false # Whether to enable HTTP/2 for the server.
# The default value is false.

probe_addr: ":8081" # The address the probe endpoint binds to.
# The default value is ":8081".

secure_metrics: false # The secure metrics configuration.
# The default value is "" (empty).

exec_adc_timeout: 15s # The timeout for the ADC to execute.
# The default value is 15 seconds.

listener_port_match_mode: "off" # Mode for injecting server_port route vars from Gateway listener ports.
# - "off": never inject server_port vars.
# - "auto": inject when parentRefs explicitly target listeners (sectionName/port) or when multiple listener ports are matched.
# - "explicit": inject only when parentRefs explicitly target listeners.
# The default value is "off". APISIX matches server_port against the port it
# accepted the connection on, which is not the port the Gateway listener
# declares, so only enable this when APISIX listens on the declared ports.

namespace_selector: [] # Label selectors of the namespaces whose resources are handled by the controller.
# A namespace is selected when its labels match all entries. Equality and "in"
# requirements on the same key are merged, so the example below selects namespaces
# labeled team=a or team=b that are also labeled env=prod:
# namespace_selector:
# - "team=a"
# - "team=b"
# - "env=prod"
# Only separate entries are merged. Within one entry, comma-separated requirements
# follow the Kubernetes label selector syntax, so "team=a,team=b" matches nothing.
# It applies to Ingress and apisix.apache.org/v2 resources. Gateway API resources are
# not filtered, use the allowedRoutes of the Gateway listeners instead. Resources they
# reference, such as Services, Secrets and GatewayProxies, are read from any namespace.
# When a namespace stops matching, the configuration of its resources is removed
# from the data plane.
# The default value is empty, which selects all namespaces. Empty entries are ignored.

provider:
type: "apisix" # Provider type.
# Value can be "apisix" or "apisix-standalone".

sync_period: 1h # The period between two consecutive syncs.
# The default value is 1 hour, which means the controller will not sync.
# If you want to enable the sync, set it to a positive value.
init_sync_delay: 20m # The initial delay before the first sync, only used when the controller is started.
# The default value is 20 minutes.