# Guides > Task-oriented guides for exposing workloads, managing tenants, tuning Envoy Proxy, and securing KubeLB traffic. > Last updated: 2026-08-18 > Version: v1.5 > Pages: 25 ## About this section - [Guides — Full Content](https://docs.kubermatic.com/kubelb/v1.5/tutorials/llms-full.txt) ## Pages - [Tenants](https://docs.kubermatic.com/kubelb/v1.5/tutorials/tenants/llms-full.txt): Register KubeLB tenants and configure per-tenant load-balancing, DNS, certificate, and quota settings. - [TCP/UDP Load Balancing](https://docs.kubermatic.com/kubelb/v1.5/tutorials/loadbalancer/llms-full.txt): Set up Layer 4 TCP and UDP load balancing with Kubernetes LoadBalancer Services. - [Gateway API](https://docs.kubermatic.com/kubelb/v1.5/tutorials/gatewayapi/llms-full.txt): Set up Layer 7 load balancing with the Gateway API and Envoy Gateway. - [Ingress](https://docs.kubermatic.com/kubelb/v1.5/tutorials/ingress/llms-full.txt): Set up Layer 7 load balancing with Kubernetes Ingress and plan migration to Gateway API. - [Layer 4 Load Balancing with BGP](https://docs.kubermatic.com/kubelb/v1.5/tutorials/bgp/llms-full.txt): Advertise Layer 4 load balancer addresses with BGP by integrating KubeLB with MetalLB. - [Client IP Preservation](https://docs.kubermatic.com/kubelb/v1.5/tutorials/client-ip-preservation/llms-full.txt): Preserve original client IP addresses across KubeLB's multi-cluster Layer 4 and Layer 7 traffic paths. - [Envoy Proxy Configuration](https://docs.kubermatic.com/kubelb/v1.5/tutorials/envoy-proxy/llms-full.txt): Tune the Envoy data plane through the global Config CRD: timeouts, health checks, circuit breakers, and more. - [Security](https://docs.kubermatic.com/kubelb/v1.5/tutorials/security/llms-full.txt): Manage DNS, TLS certificates, secrets, and network policies for KubeLB load balancers. - [Web Application Firewall (Beta)](https://docs.kubermatic.com/kubelb/v1.5/tutorials/web-application-firewall/llms-full.txt): Protect KubeLB Layer 7 routes with centrally managed Coraza and OWASP Core Rule Set policies. - [AI & MCP Gateway](https://docs.kubermatic.com/kubelb/v1.5/tutorials/ai/llms-full.txt): Run agentgateway as a KubeLB addon for LLM, MCP and Agent-to-Agent traffic. - [Backend TLS Re-encryption](https://docs.kubermatic.com/kubelb/v1.5/tutorials/backend-tls/llms-full.txt): Encrypt Layer 4 connections from KubeLB's Envoy Proxy to TLS-enabled backend services. - [mTLS Backend Transport](https://docs.kubermatic.com/kubelb/v1.5/tutorials/mtls-backend-transport/llms-full.txt): Encrypt KubeLB backend traffic between management and tenant clusters with mutual TLS.