The timing could not be more pointed. As KubeCon + CloudNativeCon Europe 2026 opens its doors this month, the Kubernetes community is grappling with one of its most consequential infrastructure transitions in years: the official retirement of Ingress NGINX. For platform teams scrambling to find a migration path that doesn’t require rebuilding everything from scratch, Traefik Labs is arriving in London with a pointed message — and a booth at #981. With over 3.4 billion downloads and 60,000 GitHub stars, Traefik Proxy has quietly become one of the most deployed pieces of cloud-native infrastructure on the planet, and the company says it remains the only solution offering a true zero-configuration, drop-in replacement for the retiring controller.
But the Ingress NGINX story is really just the entry point. In this pre-show Q&A, Immánuel Fodor, Principal Product Manager at Traefik Labs, makes the case that the deeper problem facing enterprises in 2026 isn’t any single migration — it’s fundamental infrastructure fragmentation. Multiple ingress controllers, sprawling API gateways, inconsistent security policies across clouds, and now a wave of AI workloads landing on top of architectures never designed to handle them. Fodor argues that Traefik’s answer is a unified runtime layer spanning ingress, API gateway, API management, AI traffic, and MCP governance across Kubernetes, VMs, edge, and air-gapped environments — all declarative, all GitOps-driven, all from one platform. With the company’s CEO, CTO, Head of Engineering, and Head of Product all on the show floor, KubeCon EU is shaping up to be a pivotal moment for Traefik Labs.
VMblog: What’s your elevator pitch for KubeCon EU 2026? If attendees only remember one thing about your company after visiting your booth, what should it be?
Immánuel Fodor: If attendees only remember one thing, aside from Traefik being the only drop-in, zero-config replacement for Ingress NGINX, then it’s this:
Your infrastructure is fragmented, and Traefik fixes that.
Most platform teams we talk to are managing the same mess: multiple ingress controllers, multiple API gateways, inconsistent security policies across clouds, and now AI workloads landing on top of all of it. That’s not a tooling problem—it’s an architecture problem.
Traefik Labs built the unified runtime layer: one platform that handles ingress, API gateway, API management, AI traffic, and MCP governance consistently across Kubernetes, VMs, edge, and air-gapped environments. One control plane, one policy model, everything as code.
Start with Traefik Proxy, our OSS ingress controller with over 3.4B downloads and 60k GitHub stars. Then, as your requirements change, add API, AI, and MCP governance capabilities seamlessly to existing deployments. It’s really that easy.
VMblog: You’ve chosen to sponsor KubeCon + CloudNativeCon Europe 2026—what makes the European cloud-native community particularly strategic for your business objectives this year?
Fodor: Ever since the #IngressNightmare in July 2025 and then the Ingress NGINX retirement announcement at Kubecon NA in November 2025, we’ve been leading the conversation about the need to migrate. It just so happens that Kubecon EU landed in the same month as the official retirement.
This year’s event is strategic for us because Traefik is still the only drop-in replacement for Ingress NGINX. Instead of simply publishing a migration guide, expecting organizations to reconfigure everything from scratch, we built a uniquely seamless, zero-configuration migration path from Ingress NGINX to Traefik.
This includes our OSS tool for analyzing your existing annotations to help you plan your migration, our Ingress NGINX Provider that lets you drop Traefik in and continue running your annotations, and the ability to operate Ingress and Gateway API workloads simultaneously through one controller.
Together, this means organizations can quickly and painlessly migrate off Ingress NGINX to an actively maintained solution and then migrate gradually to Gateway API on their own schedules.
Given all this, we’re seeing Kubecon EU as a great opportunity to make this critical situation a non-event.
VMblog: Where exactly can attendees find you on the show floor, and what’s the one must-see demo or experience you’ve built that showcases your technology’s real-world impact?
Fodor: Attendees can visit us at Booth #981. Our founder and CTO, our Head of Engineering, and our Head of Product will be on-site, along with a group of our top engineers, looking to have deep, technical conversations.
It’s worth coming by to see why Traefik is the only drop-in replacement to Ingress NGINX. No other solution can do what we’re doing. CTOs and CISOs are forced by other vendors onto a migration path that is impossible to complete within the remaining short time, but Traefik gives them the peace of mind.
VMblog: Let’s get technical—what specific architectural challenges or operational bottlenecks does your solution address for cloud-native teams in 2026?
Fodor: The bottlenecks we hear about most from DevOps and Platform teams fall into four buckets:
Fragmentation—API sprawl is real. Rapid proliferation means most teams have lost track of which APIs they have, let alone who’s accessing them. That’s not just an operational headache; it’s a security vulnerability.
GitOps Gaps—Legacy API management tools were built for ClickOps. They’re UI-dependent, not fully declarative, and don’t support open standards, which means your GitOps and CI/CD pipelines hit a wall the moment they touch API management. Air-gapped operations get even worse: less automated, harder to reproduce, and nearly impossible to audit.
AI Workload Dissonance—AI inference traffic doesn’t fit neatly into what legacy platforms were designed for. Specialized routing, semantic caching, and guardrails all create architectural conflicts that older tools simply weren’t built to handle.
Governance at Scale—Most legacy solutions offer all-or-nothing governance. When you need true isolation between teams or customers (e.g., separate quotas, RBAC boundaries, distinct policies, etc.) they can’t deliver it without significant custom work.
Traefik addresses all of these from a single, unified runtime layer: Kubernetes-native, fully declarative, GitOps-driven, with first-class support for both traditional API traffic and AI workloads.
VMblog: The cloud-native landscape is maturing rapidly. How has your technology evolved to meet the sophisticated demands of enterprises running production Kubernetes at scale?
Fodor: Traefik was born in the cloud-native era and has been evolving alongside the industry for 10 years.
In the early days, we were solving bleeding-edge problems: automatic service discovery, dynamic container networking, and manual configuration challenges that required deep Kubernetes expertise just to get started. That era was about making cloud-native possible.
The industry has shifted. Enterprises aren’t experimenting anymore; they’re running critical workloads in production, across hybrid and multi-cloud environments, with real SLAs and real consequences for getting it wrong. The question is no longer “can we run Kubernetes?” Now it’s “can we operate it at scale, consistently, without downtime, without security blind spots, across different clouds and on-premises?”
That’s where Traefik is today:
- Zero-downtime upgrades, enabling organizations to start with Traefik OSS and add API gateway, AI & MCP gateway, or API management capabilities in sections
- Unified runtime governance for all workloads across multi-cloud, hybrid, on-premises, edge, and air-gapped deployments
- Native Kubernetes integration with support for modern protocols like HTTP/3 and gRPC
- GitOps-driven operations for fully declarative, code-driven workflows that eliminate ClickOps, support CI/CD end-to-end, and make infrastructure reproducible and auditable
- Built-in AI workload management with semantic caching, safety guardrails, cost controls, and multi-LLM connectivity without vendor lock-in
VMblog: AI and machine learning workloads are becoming first-class citizens in Kubernetes environments. How does your solution address the unique infrastructure and operational demands of AI/ML pipelines?
Fodor: AI workloads aren’t just becoming first-class citizens in Kubernetes. They’re introducing attack surfaces that most security teams don’t even know exist yet.
The emergence of MCP as the de facto standard for how AI agents interact with enterprise tools has fundamentally changed the threat landscape. Agents now have access to databases, CRMs, file systems, and cloud platforms, and traditional API security was never designed to govern them.
Traefik addresses this with the Triple Gate Pattern—three independent layers of defense, each operating on different principles, all in one, lightweight solution.
Gate 1: AI Gateway blocks threats at the conversation layer (e.g., prompt injection, jailbreak attempts, PII extraction, and off-policy interactions) before they reach your AI systems. The entire security pipeline runs inside your infrastructure.
Gate 2: MCP Gateway governs tool access through Task-Based Access Control (TBAC), which is an authorization paradigm designed specifically for AI agents. TBAC scopes permissions to the actual work being done: which business tasks the agent is authorized for, which tools it can access, and which exact operations are permitted at runtime—all declaratively with dynamic, Identity Provider-driven policies.
Gate 3: API Gateway protects the backend with centralized credential management, fine-grained API authorization, rate limiting, and DLP-style response inspection.
VMblog: Platform engineering continues reshaping how organizations approach cloud-native infrastructure. What’s your perspective on this shift, and how does your technology enable effective platform teams?
Fodor: Infrastructure complexity has outpaced teams’ ability to manage it. According to Gartner’s 2025 DHI report, distributed hybrid infrastructure is projected to grow from 15% to 55% of enterprises by 2028. Multi-cloud environments bring incompatible networking stacks, causing identical application code to behave differently in production. For example, AWS ALB defaults to 60-second timeouts, Azure App Gateway to 90.
The result is a hidden operational tax that slows deployments and inflates time to resolution. Platform engineering exists to fix this, moving from ticket-driven ops to self-service platforms with built-in guardrails.
Traefik enables that shift by providing a single, consistent interface across every environment, so platform teams don’t have to maintain cloud-specific configurations for every provider they touch. Developers get self-service simplicity. Platform teams keep control. Security, observability, and governance are baked in, not bolted on—and it all works consistently whether clusters run on-prem, in the cloud, or at the edge.
VMblog: Multi-cloud and hybrid strategies are now table stakes. How does your solution help organizations navigate the complexity of distributed, heterogeneous environments?
Fodor: Multi-cloud and hybrid complexity compounds fast. Every cloud provider brings its own identity and access management system, security controls, and observability stack. Policies that work in AWS don’t automatically translate to Azure or GCP. The result is fragmented authentication, inconsistent security posture, and observability blind spots that make troubleshooting across environments genuinely painful.
Traefik addresses this as an Application Intelligence Layer—a unified governance fabric that sits above the underlying infrastructure. Authentication, security, and routing policies are defined once and applied everywhere: AWS, Azure, GCP, sovereign clouds, on-premises data centers, and edge locations. There’s no configuration drift, no environment-specific exceptions, and no provider-specific tooling to learn.
Critically, Traefik also handles VM-based monolithic applications and modern cloud-native microservices through the same platform, so teams managing legacy workloads don’t have to maintain separate solutions as they transition to modern deployment models. It also works across orchestrators, including Kubernetes and HashiCorp Nomad, and can function without a container orchestrator entirely, avoiding lock-in at every layer.
VMblog: Security, compliance, and governance remain top concerns. What’s your approach to helping organizations build secure, compliant cloud-native systems without sacrificing velocity?
Fodor: The tension between security and velocity is largely an architecture problem, not an inevitability. Most organizations slow down because security is bolted on after the fact. Environment-specific policies, manual configurations, and fragmented tooling force teams to re-implement controls every time infrastructure changes.
Traefik’s answer is a “define-once, apply-everywhere” model that makes security a property of the platform, not a tax on each deployment.
In practice, that means:
- Consistent policy enforcement across Kubernetes, VMs, edge, and legacy systems with no environment-specific exceptions
- Centralized authentication via native integrations with OIDC, OAuth2, LDAP, and other enterprise identity standards
- Built-in compliance via audit trails, OpenAPI Specification (OAS) enforcement, and API lifecycle governance for regulated industries like healthcare, finance, and government
- CVE embargo access, meaning customers get patches before public disclosure, so remediation happens within compliance-mandated timelines
- GitOps-driven policy deployment makes everything version-controlled, automated, and auditable
In short, security teams get confidence. Development teams keep their speed. IT managers get velocity.
VMblog: As we enter 2026, what’s your unique value proposition? With dozens of vendors claiming similar capabilities, why should CTOs choose your solution?
Fodor: Aside from much of what I’ve already detailed in this interview, I can boil it down to this:
Traefik is built on three primary commitments. Firstly, when you choose Traefik, you gain architectural sovereignty, so no private data leaves your environment, and you can prove to customers and regulators exactly where data lives and who can see it.
The second is genuine vendor independence with no vendor lock-in. Portable infrastructure has real monetary value when it’s time to renegotiate contracts.
Finally, Traefik offers a single, unified platform that enables operations-as-code across application delivery, API management, and AI workloads. This eliminates the security gaps and operational overhead that come with fragmented tooling.
I’d recommend dropping by booth #981 at KubeCon EU to see what these mean in practice.
VMblog: Give us your executive pitch—how do you articulate ROI and business value to C-suite leaders who need to justify cloud-native investments?
Fodor: C-suite leaders don’t buy infrastructure. They buy risk reduction, cost savings, and competitive advantage.
Three numbers tend to land immediately. Enterprise downtime averages $300K per hour. Regulatory fines under GDPR and HIPAA routinely exceed millions. And unchecked AI infrastructure spending—without caching and quota management—compounds fast, often reaching six figures annually before organizations realize it.
Traefik addresses all three directly. Our resilience and intelligent traffic management prevent the outages that drain budgets. Consistent policy enforcement and audit-grade evidence reduce compliance exposure. And semantic caching with intelligent quota management cuts AI infrastructure spending.
Beyond risk, there’s recaptured productivity. Teams typically spend 20-30% of their time managing configuration drift, static IP assignments, and firewall exceptions. Traefik’s unified policy management and operations-as-code model gives that time back, redirecting senior engineering hours from operational overhead to revenue-generating work.
And by unifying Web Application Firewall (WAF), ingress, API gateway, and observability into a single platform, we eliminate redundant licensing, reduce training overhead, and remove the security gaps that fragmented tooling creates.
This isn’t speculative ROI. It’s embedded in avoided costs and operational efficiencies that finance teams can validate from day one.
VMblog: FinOps and cost optimization have become critical as cloud spending comes under increased scrutiny. How does your solution help organizations maximize efficiency and control costs?
Fodor: Cloud spending scrutiny has finally reached AI infrastructure, and that’s where the biggest optimization opportunities are hiding.
LLM and GPU costs are notoriously opaque. Most organizations are flying blind, unable to see which models are being called, by which teams, for what purpose, at what cost. Traefik’s AI Gateway changes that by turning LLM cost management from a black box into a data-driven practice via detailed token usage metrics per model, per team, per endpoint, giving you the visibility to actually act.
Visibility alone isn’t enough though. We reduce redundant API calls through semantic caching—i.e., intelligently recognizing similar queries rather than repeatedly hitting expensive models. Model routing directs simple queries to cheaper models and reserves expensive ones for complex requests. And usage quotas enforce budget predictability at the team, project, or endpoint level before costs spiral.
For traditional infrastructure, Traefik’s Knative integration delivers scale-to-zero for variable workloads for webhook handlers, batch processors, sporadic APIs, and AI pipelines on schedules. There’s zero compute cost when idle, and automatic scaling when needed.
Stepping back, fragmented tooling is itself a FinOps problem. Managing separate solutions for ingress, API gateway, WAF, and observability means redundant licensing, duplicated operational overhead, and ungoverned access that wastes resources. Traefik consolidates all of that into a single, lightweight platform.
VMblog: Looking beyond KubeCon EU 2026, what emerging trends or technologies should cloud-native practitioners be preparing for? What’s on your company’s innovation roadmap that signals where the industry is heading?
Fodor: This year, we’re focusing on three key areas:
- Open-source and the community. This is core to our DNA.
- VM and container co-existence in organizations
- AI and Agent governance, as this is the new frontier
Expect new features and strategic partnerships to land around these. Stay tuned!
##






