HeroDevs NES for Ingress NGINX delivers ongoing CVE patches and compliance coverage as a drop-in replacement for end-of-life Ingress NGINX in Kubernetes environments.
HeroDevs NES for Ingress NGINX is a commercially supported, drop-in replacement for end-of-life Ingress NGINX controllers. Built by a team of major open source contributors and maintainers, NES delivers ongoing CVE remediation and compliance coverage so platform and security teams can continue operating on their existing ingress architecture without disruption.
HeroDevs has already shipped patches addressing critical vulnerabilities including CVE-2026-32282, demonstrating rapid response to newly disclosed threats targeting EOL Ingress NGINX deployments.
Why It Matters
Ingress controllers sit directly in the request path for production traffic. Running unsupported ingress software creates high-impact security, compliance, and operational risk. NES for Ingress NGINX eliminates that exposure while giving teams a realistic runway to plan and execute migrations - whether to Gateway API, a new controller, or an upgraded architecture.
Use case example: A financial services platform team facing PCI-DSS audit pressure on dozens of clusters running EOL Ingress NGINX can deploy NES immediately to restore compliance posture while developing a 6-12 month migration plan to Gateway API.
How It Works
Drop-in replacement: Existing ingress rules, annotations, and application configuration remain untouched when replacing the upstream controller.
Kubernetes-native delivery: Deployed via Helm chart and OCI container image - compatible with GitOps workflows including Argo CD and Flux.
Ongoing vulnerability remediation: As new CVEs are reported against Ingress NGINX, HeroDevs ships patched releases so your ingress layer stays secure.
Compliance coverage: Helps organizations maintain audit readiness for frameworks that require supported, patched software in production.
Deployment and Delivery
NES for Ingress NGINX is delivered through AWS Marketplace as a metered product. Deployment follows standard Kubernetes workflows:
Subscribe through AWS Marketplace.
Add the NES Helm repository.
Configure your values.yaml (existing ingress configuration carries over).
Run helm install or helm upgrade to replace the upstream controller.
See the Pricing tab for details on metered dimensions.
Who This Is For
Platform engineering teams managing Kubernetes clusters with EOL Ingress NGINX controllers
Security teams needing verified CVE remediation for ingress infrastructure
Organizations in regulated industries requiring audit-ready, commercially supported software in the request path
Teams mid-migration to Gateway API or alternative controllers who need secure coverage during the transition
Get Started
To schedule a migration assessment or request a guided pilot, contact the HeroDevs team. Visit herodevs.com/support/nes-for-ingress-nginx for documentation, release notes, and CVE coverage details.
Highlights
Proven CVE remediation from open source maintainers - HeroDevs' team of major open source contributors and maintainers delivers rapid vulnerability patches for EOL Ingress NGINX. The team has already shipped fixes for critical vulnerabilities including CVE-2026-32282, ensuring your ingress layer stays protected as new threats emerge. Patches are delivered as updated OCI container images compatible with existing deployment pipelines.
Zero-disruption drop-in replacement for production ingress - Replace your unsupported Ingress NGINX controller without modifying existing ingress rules, annotations, or application configuration. NES is designed for teams that need to maintain production traffic flow while restoring security and compliance posture on a realistic migration timeline.
Kubernetes-native delivery with GitOps compatibility - Deployed via Helm chart and OCI container image, NES integrates with standard Kubernetes workflows including Argo CD and Flux. Platform teams can manage the replacement controller using the same infrastructure-as-code practices they already use, minimizing operational overhead and change risk.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay based on usage, measured in container hours. The single dimension bills per hour that the supported ingress controller container runs. Your cost scales directly with how long you keep the container running across your Kubernetes deployment. There are no separate tiers or instance sizes to choose. As you run more container hours, you accrue more charges. This model ties your spend to actual runtime rather than a fixed seat count or upfront quantity, so costs rise or fall with your deployment footprint.
Top-of-mind questions for buyers
What counts as one container hour for billing?
One container hour is one hour that the supported ingress controller container runs in your Kubernetes cluster. The controller ships as an OCI container image and Helm chart. Each running container instance accrues hours independently. If you run several controller replicas, each one meters its own hours.
Am I charged when the ingress controller container is stopped or scaled down?
Charges accrue only while the container runs, measured in container hours. When you stop or scale down the controller, those instances stop accruing hours. Your cost tracks actual runtime. Running more replicas or keeping the controller up longer raises your total container hours.
Does the hourly charge cover CVE patches and compliance evidence?
Yes. Running the container gives you ongoing CVE patches delivered as new releases through the Helm chart. Each release ships with a VEX statement and attestation for audits. The support commitment includes SLA-backed remediation. There is no separate charge for patches beyond the container hours you run.
docs.herodevs.com+1
Helpful?
Vendor refund policy
All sales are non-refundable
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
Helm charts are Kubernetes YAML manifests combined into a single package that can be installed on Kubernetes clusters. The containerized application is deployed on a cluster by running a single Helm install command to install the seller-provided Helm chart.
Version release notes
First canonical Helm delivery version published through the helm-charts release workflow (chart 0.0.13). Functionally equivalent to v1.15.1-nes-1.15.7-helm-preview.3: same controller (v1.15.1-nes-1.15.7-2) and default backend images; the kube-webhook-certgen utility is the same NES-relabeled build under the workflow's deterministic v1.6.9-nes tag.
Additional details
Usage instructions
Requires: An active subscription to HeroDevs NES for Ingress NGINX
HeroDevs provides commercial support for NES for Ingress NGINX through its team of security-focused engineers. The team is comprised of major open source contributors and maintainers across various software ecosystems.
Support Scope:
Installation and deployment guidance (Helm chart configuration, OCI image setup)
Vulnerability information and CVE remediation updates
Compatibility questions for Kubernetes environments
NES documentation, release notes, and vulnerability coverage details are available at herodevs.com/support/nes-for-ingress-nginx.
Migration Assessments:
For teams evaluating NES for Ingress NGINX or planning a migration from upstream EOL controllers, contact the HeroDevs team to schedule a guided assessment.
For urgent security issues related to your NES deployment, contact support@herodevs.com with the subject line including your environment details and severity level.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Deliver apps with performance, reliability, security, and scale. NGINX Plus and NGINX App Protect on AWS deploy quickly and cost-effectively, and you'll benefit from speeds <30ms. Get the all in one (yet surprisingly lightweight) load balancer, reverse proxy, and API gateway with WAF.
Deliver apps with performance, reliability, security, and scale. NGINX Plus and NGINX App Protect on AWS deploy quickly and cost-effectively, and you'll benefit from speeds <30ms. Get the all in one (yet surprisingly lightweight) load balancer, reverse proxy, and API gateway with WAF.
Deliver apps with performance, reliability, security, and scale. NGINX Plus and NGINX App Protect on AWS deploy quickly and cost-effectively, and you'll benefit from speeds <30ms. Get the all in one (yet surprisingly lightweight) load balancer, reverse proxy, and API gateway with WAF.
Deliver apps with performance, reliability, security, and scale. NGINX Plus and NGINX App Protect on AWS deploy quickly and cost-effectively, and you'll benefit from speeds <30ms. Get the all in one (yet surprisingly lightweight) load balancer, reverse proxy, and API gateway with WAF.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.