Part 6 · 1 chapters · ~8 min

API Gateways, North-South and East-West

The edge gateway's job against the mesh's job, public API concerns (keys, quotas, versioning, WAF), internal concerns (identity, mTLS, retries), the Kubernetes Gateway API, and products that play each role.

10

Two boundaries, two jobs

code
# Kubernetes Gateway API: an HTTPRoute with a weighted canary (works with many implementations)
apiVersion: gateway.networking.k8s.io/v1
kind: HTTPRoute
metadata: { name: ledger }
spec:
  parentRefs: [ { name: public-gateway } ]
  hostnames: [ api.bank.example ]
  rules:
  - matches: [ { path: { type: PathPrefix, value: /v1/transfers } } ]
    backendRefs: [ { name: ledger-v1, port: 8080, weight: 90 }, { name: ledger-v2, port: 8080, weight: 10 } ]
NORTH-SOUTH AND EAST-WEST
traffic entering the platform versus traffic between services
clientsapps, partnersAPI gateway / ingressnorth-southtransfersledgernotifications
swipe the figure sideways, or tap expand for full screen
1/4
north-south
Traffic entering from outside crosses one boundary: the gateway or ingress. Concerns there are external: client authentication, API keys, quotas, WAF, public TLS, versioned public APIs.
external traffic, one front doorclient auth, quotas, public TLS