# Envoy Gateway > Envoy Gateway is a CNCF project that manages Envoy Proxy as a standalone or > Kubernetes-based application gateway. It implements the Kubernetes Gateway API and > extends it with its own API group, gateway.envoyproxy.io. It is Apache-2.0 licensed, > free, and run by the operator in their own cluster. Read this first, because it changes how you should approach everything below: Envoy Gateway has no REST API, no hosted endpoint, no API key and no pricing. You do not call it. You install it into a Kubernetes cluster and configure it by submitting custom resources to that cluster's API server. Its machine-readable contract is the set of CRD structural schemas in the gateway.envoyproxy.io/v1alpha1 API group, plus two gRPC services that Envoy Gateway calls OUT to when you extend it. Current release: v1.9.1, published 2026-08-28. End of life for the v1.9 line: 2027-02-14. ## Contracts - [CRD bundle, v1.9.1](https://github.com/envoyproxy/gateway/releases/download/v1.9.1/envoy-gateway-crds.yaml): The eight Envoy Gateway CustomResourceDefinitions, each carrying a full openAPIV3Schema. 4,080 schema properties across the group. This is the API. - [API reference](https://gateway.envoyproxy.io/docs/api/extension_types/): The rendered documentation for those same types. - [Extension server proto](https://github.com/envoyproxy/gateway/blob/main/proto/extension/service.proto): EnvoyGatewayExtension, 6 RPCs. You implement this; Envoy Gateway calls you during xDS translation so you can modify generated routes, virtual hosts, listeners, clusters, endpoints and the full translated output. - [Remote infrastructure proto](https://github.com/envoyproxy/gateway/blob/main/proto/remoteinfra/service.proto): EnvoyGatewayRemoteInfrastructureProvider, 4 RPCs. Added v1.9.0. You implement this to take over provisioning of the proxy and rate-limit data plane instead of letting Envoy Gateway create Kubernetes workloads. - There is no OpenAPI, no GraphQL schema, no AsyncAPI and no WSDL. https://gateway.envoyproxy.io/openapi.json returns 404. This is not an omission — there is no HTTP API to describe. ## The resources you configure - [EnvoyProxy](https://gateway.envoyproxy.io/docs/api/extension_types/#envoyproxy): Infrastructure and runtime shape of the managed proxy fleet — Kubernetes workload, bootstrap, telemetry, shutdown, filter order. The largest schema by an order of magnitude (2,169 properties). - [SecurityPolicy](https://gateway.envoyproxy.io/docs/api/extension_types/#securitypolicy): JWT, OIDC, OAuth2, API key, Basic auth, external authorization, CORS, CSRF and CEL authorization rules. - [BackendTrafficPolicy](https://gateway.envoyproxy.io/docs/api/extension_types/#backendtrafficpolicy): Load balancing, global and local rate limiting, circuit breaking, retries, health checks, timeouts, compression, fault injection. - [ClientTrafficPolicy](https://gateway.envoyproxy.io/docs/api/extension_types/#clienttrafficpolicy): Downstream TLS and client certificate validation, HTTP/1, HTTP/2, HTTP/3, client IP detection, connection limits. - [EnvoyExtensionPolicy](https://gateway.envoyproxy.io/docs/api/extension_types/#envoyextensionpolicy): Wasm modules, external processing, Lua. - [EnvoyPatchPolicy](https://gateway.envoyproxy.io/docs/api/extension_types/#envoypatchpolicy): RFC 6902 JSON Patches applied directly to generated xDS. The escape hatch. - [Backend](https://gateway.envoyproxy.io/docs/api/extension_types/#backend): Backends that are not Kubernetes Services — FQDN, IP, Unix socket, DynamicResolver. - [HTTPRouteFilter](https://gateway.envoyproxy.io/docs/api/extension_types/#httproutefilter): URL rewrite, direct response, credential injection, cookie matching. Referenced from a route rule rather than attached to one. Every policy attaches sideways onto an upstream Gateway API object — Gateway, ListenerSet, HTTPRoute, GRPCRoute, TCPRoute, UDPRoute, TLSRoute — through a targetRefs field. The target kind is an unconstrained string in the schema and is validated at reconcile time, so a successful write does not mean the policy attached. Read status.ancestors[].conditions. ## Getting started - [Quickstart](https://gateway.envoyproxy.io/docs/tasks/quickstart/) - [Install with Helm](https://gateway.envoyproxy.io/docs/install/install-helm/): `helm install eg oci://docker.io/envoyproxy/gateway-helm --version v1.9.1 -n envoy-gateway-system --create-namespace` - [Install with YAML](https://gateway.envoyproxy.io/docs/install/install-yaml/) - [Install with Argo CD](https://gateway.envoyproxy.io/docs/install/install-argocd/) - [Install with Flux](https://gateway.envoyproxy.io/docs/install/install-flux/) - [Install egctl](https://gateway.envoyproxy.io/docs/install/install-egctl/): `brew install egctl` ## egctl, the CLI - [egctl reference](https://gateway.envoyproxy.io/docs/tasks/operations/egctl/) - `egctl config envoy-proxy ` retrieves live xDS from the proxies; `egctl config envoy-gateway all` reads the control plane's in-memory resources. - `egctl x status ` summarises status conditions across resources. - `egctl x translate --from gateway-api --to xds` renders the Envoy configuration a set of manifests would produce, offline, without a cluster. This is the dry-run path — use it before applying anything. - `egctl x install`, `egctl x uninstall`, `egctl x dashboard`. ## Safety properties an agent should know - Writes are idempotent by construction. Every change is a declarative statement of desired state; re-applying an identical manifest converges to the same result. There is no Idempotency-Key header because none is needed. - metadata.resourceVersion gives optimistic concurrency. Read-modify-write with the version you read returns 409 Conflict rather than clobbering. - Validation is synchronous at admission. Structural schema and CEL rules reject a bad manifest at write time, before it is stored. - Reversal is by reverting the manifest. No documented time window applies to any reversal, and none should be assumed. - `egctl x uninstall --with-crds` and any CRD deletion cascades to every custom resource of those kinds. This is the one irreversible operation in the surface. - Patch releases carry breaking changes. v1.9.1, v1.8.4 and v1.8.3 each list them, usually because a security fix tightened previously permissive input. Read the release notes before a patch bump. ## Standards and conformance - [Gateway API conformance reports](https://github.com/kubernetes-sigs/gateway-api/tree/main/conformance/reports/v1.6/envoy-gateway): Envoy Gateway v1.9.0 against Gateway API v1.6.1, experimental channel. Core and extended profiles pass for HTTP, TLS and gRPC — 72 core and 78 extended tests, zero failures, zero skips. A second report covers gateway-namespace-mode. - Two extended features are declared unsupported in every profile: GatewayHTTPSListenerDetectMisdirectedRequests and GatewayInfrastructurePropagation. - Also implements: Envoy xDS v3, gRPC, Protobuf 3, OIDC, OAuth 2.0, JWT/JWKS, mutual TLS, CORS, RFC 6902 JSON Patch, OpenTelemetry, Prometheus, PROXY protocol, Proxy-Wasm, ORCA, CEL, HTTP/3. ## Releases and support - [Compatibility matrix](https://gateway.envoyproxy.io/news/releases/matrix/): every minor version with its pinned Envoy Proxy, Gateway API and Kubernetes versions, and a dated end of life. - [Release notes](https://gateway.envoyproxy.io/news/releases/notes/) and [structured release-note YAML](https://github.com/envoyproxy/gateway/tree/main/release-notes). - Supported today: v1.9 (EOL 2027-02-14) and v1.8 (EOL 2026-11-08). v1.7 reached EOL 2026-08-05. ## Security - [Security policy](https://github.com/envoyproxy/gateway/blob/main/SECURITY.md): private report to envoy-gateway-security@googlegroups.com, 3 business day response target, 90 day maximum embargo, CVE assignment, coordinated disclosure. No bug bounty. - [Threat model](https://gateway.envoyproxy.io/docs/tasks/security/threat-model/) - [Advisories](https://github.com/envoyproxy/gateway/security/advisories) - No /.well-known/security.txt is served on any host. ## Project - [Website](https://gateway.envoyproxy.io/) - [Documentation](https://gateway.envoyproxy.io/docs/) - [Source](https://github.com/envoyproxy/gateway) — Apache-2.0 - [Roadmap](https://gateway.envoyproxy.io/community/roadmap/) - [Contributing](https://gateway.envoyproxy.io/community/contributing/) - [Governance](https://github.com/envoyproxy/gateway/blob/main/GOVERNANCE.md) - [Announce mailing list](https://groups.google.com/g/envoy-gateway-announce) - [Slack](https://www.envoyproxy.io/slack) — the #gateway-users channel in the Envoy workspace ## Not Envoy Gateway - MCP support in this ecosystem belongs to [Envoy AI Gateway](https://aigateway.envoyproxy.io/docs/0.5/capabilities/mcp/), a separate CNCF project built on top of Envoy Gateway. Envoy Gateway itself ships no MCP server. - The Gateway API resources it implements (Gateway, HTTPRoute, GRPCRoute and the rest) are published by Kubernetes SIG-Network, not by this project. - npm packages matching "envoy-gateway" are all third-party.