F5 BIG-IP Container Ingress Services

Self-hosted · API

Freedom report

Two barsScore 6.2

  • Free tierA free tier is on its own pricing page
  • Open codeNo open-source code on record
  • Runs widely0 of 6 device platforms
  • DocumentedPlans, terms and facts published

F5 BIG-IP Container Ingress Services (CIS) connects Kubernetes and Red Hat OpenShift environments to F5 BIG-IP, updating network services as container applications change. CIS watches Kubernetes resources and adjusts BIG-IP configuration; teams can manage BIG-IP through Kubernetes or OpenShift command-line tools and APIs. It supports forwarding traffic from BIG-IP to Kubernetes clusters through NodePort or ClusterIP and can use F5 AS3 declarations. Traffic management includes HTTP and URI routing, load balancing, scaling, health monitoring, and Blue/Green or A/B handling of application versions. F5 documents support for Kubernetes Ingress resources and OpenShift Routes, plus IngressLink to coordinate CIS with NGINX Ingress Controller. Listed overlay integrations include OpenShift SDN, Flannel, and Calico. BIG-IP data streams can export application and network statistics to third-party visibility and analytics tools, including Splunk. CIS is a control-plane component: F5 says traffic is not affected during a CIS outage, and a replacement replica can collect cluster state and reapply it to BIG-IP. Installation can be done with Helm or manually, and releases are available from Docker Hub and Red Hat Container Registry. The open-source software is free, but use requires a compatible licensed BIG-IP system, a Kubernetes or OpenShift cluster, and AS3 installed on BIG-IP. CIS requires administrative privileges on the BIG-IP iControl REST partition; the Kubernetes guide recommends a dedicated partition.

Who it is for

CIS suits network architects, network operations teams, AppDev and DevOps teams, and system infrastructure teams managing container applications with BIG-IP. It is intended for environments using Kubernetes or Red Hat OpenShift alongside a compatible licensed BIG-IP system.

What is good

  • Updates BIG-IP configuration as Kubernetes resources change.
  • Supports NodePort and ClusterIP forwarding and F5 AS3 declarations.
  • Provides HTTP and URI routing, load balancing, scaling, and health monitoring.
  • Supports Blue/Green and A/B traffic management for application versions.
  • Helm and manual installation options are documented.
  • A CIS outage does not interrupt traffic, according to F5.

What to know first

  • Requires a compatible, licensed BIG-IP system.
  • Requires a Kubernetes or OpenShift cluster and AS3 installed on BIG-IP.
  • Requires administrative privileges on the BIG-IP iControl REST partition.
  • NodePortLocal is available only with Antrea CNI and enabled feature gates.

Verdict

Choose CIS if your Kubernetes or OpenShift environment needs to update F5 BIG-IP services as container applications change. It is free open-source software, but it depends on a compatible licensed BIG-IP system, a cluster, and AS3; check F5's verified compatibility versions before adopting it.

Get started with F5 BIG-IP Container Ingress Services

  1. Confirm that you have a compatible, licensed BIG-IP system, a Kubernetes or OpenShift cluster, and AS3 installed on BIG-IP.
  2. Choose a Helm-based or manual installation method from F5's documentation.
  3. Get a CIS release from Docker Hub or Red Hat Container Registry.
  4. Configure the required BIG-IP iControl REST access; F5's Kubernetes guide recommends a dedicated partition.
  5. Manage BIG-IP through Kubernetes or OpenShift CLI/API tools.

What the free plan stops at

The free open-source software requires a compatible, licensed BIG-IP system, a Kubernetes or OpenShift cluster, and AS3 installed on BIG-IP. F5's current compatibility table lists tested Kubernetes v1.13–v1.35, OpenShift v3.11–v4.21.0, BIG-IP v12–v17, and AS3 v3.13–v3.56; F5 does not verify versions outside those ranges.

Questions about F5 BIG-IP Container Ingress Services

How much does CIS cost?

The open-source software is listed at 0.00 USD per free, billed no charge. It requires a compatible, licensed BIG-IP system, a Kubernetes or OpenShift cluster, and AS3 installed on BIG-IP.

Which orchestration environments does it integrate with?

F5 documents integrations with Kubernetes and Red Hat OpenShift, including Ingress resources and OpenShift Routes.

How does CIS handle traffic?

It supports NodePort or ClusterIP forwarding, HTTP and URI routing, load balancing, scaling, health monitoring, and Blue/Green and A/B traffic management.

How can CIS be installed?

F5 documents Helm-based and manual installation. Releases are available from Docker Hub and Red Hat Container Registry.

What happens to traffic if CIS goes down?

F5 describes CIS as a control-plane component and says traffic is not affected during an outage. A replacement replica gathers cluster state and reapplies it to BIG-IP.

Which versions are listed as tested?

F5 lists Kubernetes v1.13–v1.35, OpenShift v3.11–v4.21.0, BIG-IP v12–v17, and AS3 v3.13–v3.56. Versions outside those ranges are not verified by F5.

F5 BIG-IP Container Ingress Services plans and pricing

All plans
Open-source software Free No charge Requires a compatible, licensed BIG-IP system · Kubernetes or OpenShift cluster · AS3 installed on BIG-IP f5.com · 4 Oct 2026

Compared on Kubernetes ingress controllers

Ingress API model
ingress
Canary routing
Yes
Web application firewall
Yes
Deployment model
self-hosted

Best F5 BIG-IP Container Ingress Services alternatives

See all 20