Ingress VIP is active/passive via keepalived. Only 1 of 3 router pods receives traffic at any time. Effective app throughput: maxconn 50,000 (single pod), not 150,000. Other 2 router pods are hot standby. API traffic is different — KNI HAProxy on VIP holder round-robins across all 3 apiservers.
192.168.37.201:6443 on master2. nftables rewrites 6443 → 9445. KNI HAProxy round-robins across all 3 apiservers with /readyz health checks.192.168.37.202:443. Router HAProxy via HostNetwork — no DNAT. L7 routing, TLS termination, OVN overlay to pods. Only 1 of 3 routers active (active/passive VIP).kubernetes.default.svc:443, OVN LB DNATs to endpoint. Bypasses VIP/HAProxy.VIP:6443 → nftables redirect → :9445 → KNI HAProxy → all 3 apiservers.svc.cluster.local. Node CoreDNS (KNI) resolves api-int and *.apps to VIPs.chk_ingress (weight=0) → FAULT on workers. Workers can never hold VIP.