Gatewayeasy0-2 years

A mobile app currently calls eleven different service hosts directly, each with its own certificate and auth flow. What does putting an API gateway in front of them actually buy, and what's the test for whether a piece of logic belongs there?

The gateway becomes the one door: clients see one host and one certificate instead of eleven, and generic cross-cutting concerns move to one place — routing, TLS termination, authenticating the token, rate limiting per client, and a request id and access log for every request that passes through. Everything on that list is the same regardless of which service the request is headed for, which is exactly the test: a rule belongs at the gateway only if it would be identical for every route. The moment a rule needs to know what an order is, it's grown past what a gateway should do.

The lesson behind it →
More on Gateway