apiVersion: gateway.networking.k8s.io/v1 kind: Gateway metadata: name: external-http-gateway namespace: customer1 spec: gatewayClassName: gke-l7-global-external-managed # Use gke-l7-global-external-http for external, or gke-l7-rilb for internal listeners: - name: https protocol: HTTPS port: 443 tls: mode: Terminate certificateRefs: - group: networking.gke.io # This tells K8s it's a GKE-specific resource kind: CertificateMap # This tells K8s it's not a Secret name: devops-lab-cert-map allowedRoutes: namespaces: from: All