01 · Shared ingress trunk
Client → MetalLB VIP → Gateway API listener → HTTPRoute, then three conditions branch into A · B · C · D1 · D2
02 · Node datapaths A · B · C
Single backendRef → Service (Pod-A) — the three outcomes of CONDITION 2 through Pod-A's namespace and the node's kernel and user space
03 · Canary split D1 · D2
Weighted backendRefs · canary (RKE2 guest ingress) — the two outcomes of CONDITION 3, 90 % to the mesh and 10 % to an external VM
04 · Sequence flows
Message order between components — one sequence diagram per path A · B · C · D