Uploaded August 2026 | Updated September 2026, 2 weeks ago
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Dynamic Modules in Envoy Gateway: API Design, Safety, and Operability - Kota Kimura, CyberAgent, Inc. & Huabing (Robin) Zhao, Tetrate
Envoy’s dynamic modules provide a high-performance way to extend HTTP processing, but turning that capability into a gateway feature introduces important questions around safety, API design, and operability. This talk shows how Envoy Gateway supports dynamic modules with Kubernetes-native APIs that separate infrastructure registration from policy-based attachment on Gateways and Routes. We explain how this maps to Envoy’s `dynamic_modules` HTTP filter and discuss the practical issues that make extensibility supportable in production, including filter ordering, invalid references, lifecycle behavior, and packaging. Using a real module composition approach as a case study, we compare bundled shared libraries with runtime-loaded plugins and highlight the tradeoffs for gateway and platform maintainers.
Don't miss out! Join us at our next KubeCon + CloudNativeCon events in Shanghai, China (8-9 September, 2026) and Salt Lake City, United States (Nov 9–12, 2026). Connect with our current graduated, incubating, and sandbox projects as the community gathers to further the education and advancement of cloud native computing. Learn more at kubecon.io
Dynamic Modules in Envoy Gateway: API Design, Safety, and Operability - Kota Kimura, CyberAgent, Inc. & Huabing (Robin) Zhao, Tetrate
Envoy’s dynamic modules provide a high-performance way to extend HTTP processing, but turning that capability into a gateway feature introduces important questions around safety, API design, and operability. This talk shows how Envoy Gateway supports dynamic modules with Kubernetes-native APIs that separate infrastructure registration from policy-based attachment on Gateways and Routes. We explain how this maps to Envoy’s `dynamic_modules` HTTP filter and discuss the practical issues that make extensibility supportable in production, including filter ordering, invalid references, lifecycle behavior, and packaging. Using a real module composition approach as a case study, we compare bundled shared libraries with runtime-loaded plugins and highlight the tradeoffs for gateway and platform maintainers.










