Use topology labels to reduce cross-AZ ingress traffic with F5 CIS and EKS
Great option MichaelOLeary​ just tested it on another multi zone cloud deployment (not Azure or AWS) but I think adding the option if no pods are found in the zone to failover to another zone as the pool is empty if there are no matching pods on the labeled nodes.
Maybe something like priority groups that CIS can configure as the matching pods on the labeled nodes to be in the first priority group 🤔
- MichaelOLearyJan 26, 2026
Employee
Nikoolayy1​ great point! I wrote this after dealing with a customer scenario where they controlled the application pods closely and were very concerned about cross-AZ traffic, but as you point out, it's not without room for improvement. I think in the case of priority groups I would recommend the alternateBackends configuration in CIS, but of course this would require your service to select only (or at least prefer) pods in a given topology zone. Thanks for the feedback!
- Nikoolayy1Jan 27, 2026
MVP
At the moment I think RFE if we need functionality is needed and probably as an extra argument that will suggest to CIS to build backup pool from the endpoint ip addresses not tagged with the correct topology label.
Outside of that in the future CIS can get the information from "topology aware hints" new beta feature to actually make this option service specific.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)