API Gateway
A single entry point for policy, routing and protocol translation.
4 to work through
-
intermediate
An API gateway has accumulated authentication, rate limiting, routing, response transformation, request validation and some business logic. Which of these belong there?
2 min answer -
advanced
A developer platform's API gateway has accumulated business logic and become a bottleneck for every team. What should be moved out, and what belongs there?
2 min answer -
advanced
A public API is being overwhelmed by a handful of clients. Where should rate limiting live, which algorithm, and how should limits differ across users, tenants, endpoints and infrastructure?
3 min answer -
advanced
A ticketing platform at Ticketmaster's on-sale peaks routes everything through one gateway. Gateway to BFF to inventory is three hops and each hop retries up to three times on a timeout or a 5xx. Inventory's p99 crosses its 400 ms timeout at 09:00:02. Walk the next ninety seconds and say where the limit actually has to live.
3 min answer
3 terms in this topic
API Gateway
A single entry point that handles cross-cutting edge concerns — routing, authentication, rate limiting, TLS — so backend services do not each impleme…
practiceEdge Policy Ordering
The sequence in which a gateway applies connection limits, authentication, quotas and validation, which decides whether a flood of unauthenticated tr…
patternGateway Aggregation
Combining several backend calls into one client-facing response at the gateway, reducing client round trips at the cost of coupling the gateway to ba…
Neighbouring topics
Architecture Patterns
General material on architectural patterns and their trade-offs.
Layered Architecture
The default shape, its clarity, and where a technical partition fails.
Event-Driven Architecture
Publishing facts, and trading comprehensibility for decoupling.
Pipes and Filters
Independent transformation steps composed into a pipeline.
Publish/Subscribe
Broadcast to every subscriber, as distinct from work distribution.
Competing Consumers
Scaling throughput with instances, at the cost of ordering.
Saga
Local transactions with compensating actions across services.
CQRS
Separate models for writing and reading, each optimised for its job.
Event Sourcing
The event log as the system of record, with state as a projection.
Outbox
Making the event atomic with the business write it describes.
Strangler Fig
Incremental replacement behind a routing facade.
Anti-Corruption Layer
Translating a foreign model at the boundary so it does not leak in.
Sidecar & Ambassador
Cross-cutting behaviour in a co-deployed process.
Service Mesh
Sidecars applied estate-wide, and the scale at which that pays.
Backend for Frontend
A narrow backend per client experience, owned by that client's team.
Cell-Based Architecture
Complete isolated copies each serving a subset of customers.
Sharding Patterns
Directory versus embedded keys, logical shards and rebalancing.
Materialized Views
Precomputed query results, refreshed incrementally or in full.
Orchestration vs Choreography
A coordinator that knows the flow, or services that react to events.