The controller is up and answering — that is why you get a tidy 404. The request just is not matching a route to your service.
Ingress says class X, the cluster runs controller Y, so nobody claims the object.
Ingress routes to a service whose endpoints list is empty — traffic goes nowhere.
Spec has host a.example.com, request is for b.example.com, or pathType mismatch.
kubectl get ingressclass
kubectl get endpoints <service>
spec:
ingressClassName: nginx
rules:
- host: app.example.com
http:
paths:
- path: /
pathType: Prefix
backend:
service:
name: app
port: { number: 80 }
kubectl get ingress -o yaml shows the object fine whether or not any controller claimed it — an empty endpoints list is the single most common root cause.
The ingress controller is routing, but nothing matches: wrong host header (test with curl -H 'Host: your.host'), path mismatch between ingress rules and the service, or the ingress lacks a matching backend. Controller logs name the decision.
That page means the controller received the request but no ingress rule matched host+path. Compare exactly: trailing slashes, case, and the host the client sends (SNI/Host) against your ingress spec.
Kustomize base with probes, PDBs, and zero-downtime rollouts already wired.
Kubernetes Production Blueprints — $27 →One-time. Yours to modify. Instant download from the NinjaOps template store.