IPv6 Support Overview by Infrastructure ​
Summary ​
Gardener supports three IPv6 networking modes depending on the infrastructure:
| Mode | Description |
|---|---|
| IPv6 Ingress for IPv4 clusters | Adds a dual-stack load balancer to an existing IPv4-only cluster so external IPv6 clients can reach services. The cluster interior stays IPv4-only. |
| Dual-stack | Both IPv4 and IPv6 are active inside the cluster. Recommended migration path for existing IPv4 clusters. |
| IPv6-only | Only IPv6 is used inside the cluster. Ideal for validating full IPv6 compatibility. |
The spec.networking.ipFamilies field in the Shoot resource controls the mode:
# IPv4-only (default)
ipFamilies: [IPv4]
# Dual-stack (IPv4 preferred)
ipFamilies: [IPv4, IPv6]
# IPv6-only
ipFamilies: [IPv6]Infrastructure Support Matrix ​
| Infrastructure | IPv6 Ingress for IPv4 | Dual-Stack | IPv6-only |
|---|---|---|---|
| AWS | âś… | âś… | âś… |
| GCP | ❌ | ✅ | ❌ |
| Azure | ❌ | ❌ | ❌ |
| OpenStack | ❌ | ✅ | ❌ |
| Alibaba Cloud | ✅ | ❌ | ❌ |
AWS ​
AWS has the most complete IPv6 support, offering all three modes: IPv6 ingress for IPv4 clusters, dual-stack, and IPv6-only.
Requirements ​
- Worker nodes must use Nitro-based instance types.
- IPv4 CIDR ranges are still required for the VPC and public/internal subnets, even for IPv6-only clusters (needed for load balancers).
- IPv6 address ranges are globally unique and internet-routable, provided by AWS.
Migration ​
Add IPv6 to spec.networking.ipFamilies to migrate an existing IPv4-only cluster to dual-stack. The cluster must already run in native routing mode (overlay disabled).
Migration between IPv6-only and dual-stack is not supported in either direction.
Load Balancers ​
The AWS Load Balancer Controller is deployed automatically for dual-stack and IPv6-only clusters. New LoadBalancer services receive dual-stack annotations via a mutating webhook. Services without explicit annotations default to IPv4-only.
Connectivity to IPv4-only external services from IPv6-only clusters is handled transparently via DNS64/NAT64.
References:
- AWS IPv6 guide
- AWS dual-stack ingress guide
- Dual-stack network migration (gardener/gardener)
GCP ​
GCP supports dual-stack clusters. IPv6-only is not supported.
Requirements ​
- IPv4 ranges are user-defined; IPv6 ranges are assigned automatically by GCP.
- The
ingress-gcecomponent is deployed automatically and is required for IPv6 load balancers (the GCP Cloud Controller Manager does not support IPv6 load balancers).
Migration ​
Add IPv6 to spec.networking.ipFamilies. The cluster must be in native routing mode.
Load Balancers ​
Services of type LoadBalancer require spec.ipFamilies, spec.ipFamilyPolicy, and the annotation cloud.google.com/l4-rbs: enabled (added automatically via webhook for new services). Internal IPv6 load balancers are not supported. Existing LoadBalancer services cannot be migrated to dual-stack; they must be recreated.
References:
- GCP IPv6 guide
- Dual-stack network migration (gardener/gardener)
Azure ​
IPv6 is currently not supported on Azure. Neither dual-stack nor IPv6-only clusters can be created.
OpenStack ​
OpenStack supports dual-stack clusters. IPv6-only is not supported.
Requirements ​
IPv6 subnets are configured via infrastructureConfig.networks.ipv6 using one of two options:
- Subnet pool (recommended): Provide a
subnetPoolID; IPv6 CIDRs for nodes, pods, and services are allocated automatically from the pool. - Explicit CIDRs: Specify
nodeCIDR,podCIDR, andserviceCIDRdirectly.
WARNING
The networks.ipv6 configuration is immutable after cluster creation.
Migration ​
Migration to dual-stack is not yet supported but planned for H2 2026.
Load Balancers ​
Load Balancers are not yet supported.
References:
- OpenStack provider usage docs
- Dual-stack network migration (gardener/gardener)
Alibaba Cloud ​
Alibaba Cloud supports dual-stack ingress. Full dual-stack and IPv6-only are not supported.
Requirements ​
- Dual-stack requires Alibaba Cloud NLB support in the target region.
- Enable dual-stack by setting
dualStack.enabled: trueinInfrastructureConfig. - For Gardener-managed VPCs: IPv6 is enabled on the VPC automatically. Each zone's VSwitch gets a
/64from the VPC's/56block. - For user-provided VPCs: IPv6 must already be enabled on the VPC, an IPv6 Gateway must exist, and
ipv6CidrBlockmust be specified for every zone. ipv6CidrBlockvalues (integers 0–255) select which/64subnet is assigned to each zone's VSwitch. The value is immutable once set. Plan carefully when multiple clusters share a VPC.
WARNING
Do not use the Alibaba Cloud console's bulk IPv6-enable option on VSwitches. Gardener will not overwrite existing IPv6 CIDRs, and the console assigns subnet indices arbitrarily.
Migration ​
Add dualStack.enabled: true to InfrastructureConfig. The infrastructure will be reconciled to enable IPv6 on the VPC and assign /64 CIDRs to each zone's VSwitch.
Load Balancers ​
Only dual-stack (IPv4+IPv6) load balancers are supported via Alibaba Cloud NLB. IPv6-only load balancers are not available. Setting dualStack.enabled: true in InfrastructureConfig is a prerequisite, but each Service also requires explicit annotations to create a dual-stack NLB:
apiVersion: v1
kind: Service
metadata:
annotations:
service.beta.kubernetes.io/alibaba-cloud-loadbalancer-ip-version: "DualStack"
service.beta.kubernetes.io/alibaba-cloud-loadbalancer-zone-maps: "<zone-a>:<vswitch-id-a>,<zone-b>:<vswitch-id-b>"
spec:
loadBalancerClass: alibabacloud.com/nlbBy default, IPv6 addresses of dual-stack services created by the Alibaba Cloud CCM only support internal access. To enable external internet access via IPv6, add the following annotation to your Service manifest: service.beta.kubernetes.io/alibaba-cloud-loadbalancer-ipv6-address-type: internet.
Alibaba Cloud NLB requires at least two VSwitches in different zones — this is a platform constraint, not specific to dual-stack. The VSwitch IDs can be found in the shoot's InfrastructureStatus.
References:
- AliCloud provider usage docs
- Dual-stack network migration (gardener/gardener)
Related Pages ​
- Dual-stack network migration — gardener/gardener
- Shoot networking configurations — gardener/gardener
- AWS IPv6 guide — gardener-extension-provider-aws
- AWS dual-stack ingress guide — gardener-extension-provider-aws
- GCP IPv6 guide — gardener-extension-provider-gcp
- OpenStack provider usage docs — gardener-extension-provider-openstack
- AliCloud provider usage docs — gardener-extension-provider-alicloud