API Gateway Pipeline Lab (Interactive)
Fire web, mobile, bot, and expired-token requests through gateway stages and count what dies at the edge. Toggle AuthN, Redis rate limiting, protocol transcoding, and BFF aggregation. Measure backend calls avoided, roundtrips saved, and latency added per pipeline stage.
API Gateway Cross-Cutting Pipeline
Send client traffic through Auth → Rate Limit → Transcode → Aggregate and see what dies at the edge.
Validates signature + scopes; injects X-User-Id downstream.
✓ passed
Sliding window: 100 req/min per API key.
Public JSON/REST → binary gRPC into the VPC (~80% payload cut).
✓ passed
Fans out to User+Order+Recs in parallel, returns ONE lean response.
✓ passed
Response to 📱 Mobile App (home feed)200 OK (composed)
› Backend calls consumed: 3
› Edge RTT: 115ms (vs 285ms if the phone made 3 roundtrips itself)
› Gateway CPU: 1.2ms/req · internal gRPC payload saved 3KB
BFF SPLIT
› Web BFF: rich 48KB tables (fiber, big screen). Mobile BFF: 4KB aggregated feed (battery + cellular). TV BFF: tile queries only. Each frontend owns its gateway, decoupling release cycles.
Load controls
Bot sends 1 req/minute-window; if that exceeds the limit and limiting is on, the gateway returns 429 at the edge.
7 responsibilities
1 Routing · 2 AuthN/AuthZ · 3 Rate limiting · 4 Protocol translation · 5 Aggregation · 6 Tracing (X-Request-Id) · 7 Circuit breaking.
Warning: an unscaled gateway is itself a SPOF and a team-velocity bottleneck — that is why BFFs exist.
How It Works Under the Hood
Letting mobile and web clients call dozens of microservices directly duplicates JWT verification, rate limiting, and CORS across every team and forces chatty multi-roundtrip fetches over cellular. The API Gateway is the single public entry point: it validates tokens and injects clean X-User-Id headers, enforces Redis-backed sliding-window limits, transcodes public JSON/REST into internal binary gRPC, and composes parallel fan-outs to User, Order, and Recommendation services into one lean response. The BFF pattern specializes a gateway per client platform — rich payloads for desktop, sub-5KB aggregated feeds for mobile.
Core Architectural Principles
- Edge AuthN rejects expired JWTs and rate limiting kills abusive keys before any pod spends CPU.
- Protocol transcoding converts public REST/JSON to internal gRPC; composition collapses 3 mobile roundtrips into 1.
- Backend-for-Frontend gateways tailor payload shape and size per client platform.
Enumerate the gateway responsibilities deliberately — routing, AuthN/AuthZ, rate limiting, protocol translation, aggregation, tracing, circuit breaking — then introduce BFF when the design has both mobile and web clients. Always note the gateway itself must scale horizontally or it becomes the new bottleneck.
One place for cross-cutting concerns and fewer client roundtrips, versus a central component that must scale and can bottleneck team release cycles.