diff --git a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
index e6306083d..624015c67 100644
--- a/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
+++ b/src/frontend/src/content/docs/deployment/kubernetes-ingress.mdx
@@ -115,9 +115,44 @@ await ingress.withPath('/', web.getEndpoint('http'));
## Hostname inheritance
-`WithHostname` / `withHostname` on an Ingress or Gateway supplies the hostname for paths and routes that don't specify one. A hostname supplied explicitly to a path or route takes precedence. This lets you configure one shared hostname without accidentally publishing the hostless paths as catch-all rules.
+`WithHostname` on an Ingress or Gateway supplies the hostname for every path or route you add without an explicit hostname of its own. This lets you set the hostname once and reuse it across all hostless paths (`WithPath`) and routes (`WithRoute`), instead of publishing them as catch-all rules:
-`WithDefaultBackend` / `withDefaultBackend` is a catch-all and doesn't inherit that hostname, including the TLS compatibility rule generated for it.
+
+
+```csharp title="AppHost.cs"
+var ingress = k8s.AddIngress("public")
+ .WithHostname("app.example.com")
+ .WithTls();
+
+// Both paths inherit "app.example.com" from WithHostname.
+ingress.WithPath("/api", api.GetEndpoint("http"));
+ingress.WithPath("/", web.GetEndpoint("http"));
+```
+
+
+```typescript title="apphost.mts"
+const ingress = await k8s.addIngress('public');
+await ingress.withHostname('app.example.com');
+await ingress.withTls();
+
+// Both paths inherit "app.example.com" from withHostname.
+await ingress.withPath('/api', api.getEndpoint('http'));
+await ingress.withPath('/', web.getEndpoint('http'));
+```
+
+
+
+If you call `WithHostname` more than once, each hostless path or route applies to every configured hostname. A hostname supplied explicitly to a path or route takes precedence — use the host-scoped `WithPath("api.example.com", "/", endpoint)` overload on an Ingress, or `WithRoute("api.example.com", "/", endpoint)` on a Gateway.
+
+A Gateway API `HTTPRoute` supports at most 16 hostnames. If a Gateway has more than 16 hostnames and any hostless routes, publishing fails; define explicit host-scoped routes instead.
+
+An Ingress default backend (`WithDefaultBackend`) doesn't inherit the hostname and remains a catch-all for any traffic that doesn't match a more specific rule. When TLS is also configured, Aspire adds a rule that forwards each TLS hostname without its own rule to the default backend, because some ingress controllers require every TLS host to have a matching rule.
+
+
## TLS and certificates