// the find
kubernetes-sigs/aws-load-balancer-controller
A Kubernetes controller for Elastic Load Balancers
This is the official AWS-maintained controller for wiring Kubernetes Ingress, Service, and Gateway API resources to real ALBs/NLBs. It's for anyone running Kubernetes on AWS who wants native load balancer provisioning instead of hand-rolling ELB config outside the cluster.
One controller covers three resource models — Ingress (ALB), Service type=LoadBalancer (NLB), and Gateway API (both) — so you're not running separate controllers as you migrate. TargetGroupBinding CRD is a solid escape hatch: it lets you attach a manually-created target group to pods directly when the automatic provisioning path doesn't fit. It ships IAM policy JSON for standard, GovCloud, China, and ISO partitions, which tells you this has actually been run in weird regulated environments, not just us-east-1. There's a dedicated migration tool (cmd/lbc-migrate) with dry-run support for moving from Ingress to Gateway API, which is more than most projects offer for their own breaking transitions.
It inherited the old ALB Ingress Controller's annotation-heavy config model, so a real-world Ingress ends up with a dozen-plus aws-load-balancer-* annotations that are hard to review at a glance compared to the newer Gateway API CRDs. Getting the IRSA IAM policy scoped correctly is the single most common failure mode — an out-of-date or overly narrow policy fails silently with no obvious error in the Ingress status. The v1-to-v2 upgrade required a manual migration doc, not a clean version bump, so treat major version jumps here as a real project, not a Helm bump. It's AWS-only by design, so none of this transfers if you're multi-cloud or move workloads later.