Announcing Built On Envoy: Making Envoy Extensions Accessible to Everyone

Learn more

Announcing Tetrate Enterprise Gateway for Envoy 1.0

We are thrilled to announce the general availability of Tetrate Enterprise Gateway for Envoy (TEG), the only 100% upstream, enterprise-ready distribution

Announcing%20Tetrate%20Enterprise%20Gateway%20for%20Envoy%201.0

We are thrilled to announce the general availability of Tetrate Enterprise Gateway for Envoy (TEG), the only 100% upstream, enterprise-ready distribution of Envoy Gateway.  

Envoy Gateway is the cloud-native service gateway that allows you to leverage the power of Envoy Proxy in an easy-to-consume package managed by the Kubernetes Gateway API, the latest evolution of application ingress. 

Are you using Kubernetes? Try out TEG in your cluster today.. Please keep reading to learn how TEG simplifies the integration of Envoy into your infrastructure and lets you use Envoy Gateway confidently in your enterprise environment.

What Is Envoy Gateway?

Envoy Gateway is the cloud-native service gateway, an open source initiative under the umbrella of the widely-used Envoy Proxy project. With Envoy Gateway you get the power of Envoy Proxy—the de facto standard data plane for cloud-native applications—managed by the Gateway API, the unified future of cloud-native application ingress.

Tetrate Enterprise Gateway for Envoy maximizes the capabilities of open-source Envoy and Envoy Gateway as quickly as possible, so you can:

  • Protect critical applications. Deploy global rate limiting and WAF-based security, to ensure your best day doesn’t become your worst nightmare.
  • Scale across clusters and clouds. Grow to global scale with tiered gateway and multi-cluster load balancing from edge to application.
  • Manage application delivery. Configure application rollout from GitOps pipelines and other automation tooling, using the scalable Kubernetes Gateway API.
  • Authenticate user traffic. Integrate with OpenID Connect providers to enable single sign-on, reduce developer burden and ensure a consistent identity framework.

Why Tetrate Enterprise Gateway for Envoy?

Tetrate Enterprise Gateway for Envoy is the only fully upstream Gateway API implementation based on open-source Envoy Gateway. Let’s break down what sets it apart:

Expert support and best practices. TEG combines always-on expert support and best practices, ensuring that your Envoy Gateway deployment is not just functional but optimized for success.

CVE protection. Tetrate understands the importance of security. With TEG, you get continuous and extended protection from Common Vulnerabilities and Exposures (CVEs) of open-source components. This means you can rest easy knowing your environment is safeguarded against potential threats. 

FIPS and FedRAMP compliance. TEG is the only FIPS-verified, 100% upstream distribution that meets FedRAMP authorization requirements. If you’re part of a government agency or highly regulated industry, you’ll appreciate TEG’s fast-track to a verifiably compliant Federal Risk and Authorization Management Program (FedRAMP) environment. 

Commitment to open source. Tetrate is committed to invest in and drive the evolution of Envoy Gateway to benefit the users of the technology, engaging with users and contributors while offering its clients an enterprise-ready solution.

Key Facts About Tetrate Enterprise Gateway for Envoy

  • TEG is a 100% upstream distro that provides builds of Envoy Gateway tested against all major cloud platforms.
  • TEG comes in an enterprise-ready package with extra functionality like WAF, service discovery integration, CVE reporting, and lifecycle management.
  • It also adds training, architectural workshops, expert enterprise production support, best practices, and extended CVE support.
  • TEG is the first and only 100% pure upstream Envoy Gateway distribution to achieve FIPS verification.
  •  It’s fully compliant with NIST 207A, the U.S. federal standard for Zero Trust architecture.
  • TEG is designed for highly regulated industries, providing automated policies for compliant security.

In short, Tetrate Enterprise Gateway for Envoy revolutionizes the landscape for enterprises aiming to leverage Envoy for application ingress for enterprises seeking the power of Envoy for application ingress. With TEG, you get the assurance and risk mitigation of a widely-deployed open-source technology stack that is FIPS certified and FedRAMP compliant.

Get Started

TEG is designed to help you quickly and easily bring Envoy into your organization. Explore the TEG starter package, designed to simplify installation and get ready to experience the power of Envoy as a universal service gateway.

Get Access Today ›

Product background Product background for tablets
Building AI agents

Agent Router Enterprise provides managed LLM & MCP Gateways plus AI Guardrails in your dedicated instance. Graduate agents from prototype to production with consistent model access, governed tool use, and runtime supervision — built on Envoy AI Gateway by its creators.

  • LLM Gateway – Unified model catalog with automatic fallback across providers
  • MCP Gateway – Curated tool access with per-profile authentication and filtering
  • AI Guardrails – Enforce policies, prevent data loss, and supervise agent behavior
  • Learn more
    Replacing NGINX Ingress

    Tetrate Enterprise Gateway for Envoy (TEG) is the enterprise-ready replacement for NGINX Ingress Controller. Built on Envoy Gateway and the Kubernetes Gateway API, TEG delivers advanced traffic management, security, and observability without vendor lock-in.

  • 100% upstream Envoy Gateway – CVE-protected builds
  • Kubernetes Gateway API native – Modern, portable, and extensible ingress
  • Enterprise-grade support – 24/7 production support from Envoy experts
  • Learn more
    Decorative CTA background pattern background background
    Tetrate logo in the CTA section Tetrate logo in the CTA section for mobile

    Ready to enhance your
    network

    with more
    intelligence?