API Gateway Auth Pipeline Lab (Interactive)
Validate JWTs locally (RS256) vs remote introspection; watch RPCs and in-flight scale. Contrast stateless local signature verification against per-request remote token introspection through the gateway pipeline.
Kong/Envoy-style Gateway Filter Pipeline Economics
Route 100k RPS through TLS → JWT → rate-limit → route filters and price each stage in latency and RPCs.
› TLS terminate (session resumption ~1 RTT saved) → mTLS to mesh → route match on path prefix → service discovery lookup (Envoy xDS / Consul).
› Auth stage: parse header, verify RS256 sig vs cached JWKS kid — CPU only.
› Distributed token-bucket rate limit in Redis (stateless gateway nodes share counters) → proxy with timeouts + retries-with-jitter.
Gateways stay stateless by pushing sessions out: rate-limit counters in Redis, tokens validated locally so the perimeter never fans a million calls per second into an auth service. When auth must be remote, Envoy outlier detection ejects bad endpoints and the circuit breaker converts a hang into a fast failure — the difference between a degraded route and a dead edge. BGP Anycast sits in front, sending clients to the healthiest region's gateway fleet.
How It Works Under the Hood
Every request through an API gateway pays auth cost, and the design choice is where validation happens. A stateless JWT is verified locally with the issuer's public key using RS256 in microseconds with zero network calls, so the gateway scales with CPU; remote introspection of opaque tokens makes every request block on a round trip to the auth service, multiplying RPCs by RPS and adding latency plus an availability dependency. Rate limiting, the other gateway duty, is Little's-law math: in-flight connections equal RPS x latency, so slow auth directly inflates concurrent socket load. Toggle local versus remote introspection or trip the breaker to watch RPCs/sec, p99 latency, and shed load diverge.
Core Architectural Principles
- Local RS256 verify is about 0.05 ms and zero RPCs; remote introspection adds a full round trip per request.
- In-flight connections = RPS x latency (Little's law), so slow auth inflates concurrent sockets.
- A circuit breaker sheds or fails closed when the auth dependency degrades.
Argue for stateless JWT local validation to keep the gateway fast and dependency-free, then honestly raise the revocation gap — you cannot instantly kill a JWT — and answer with short TTLs plus a revocation list or introspection for high-risk scopes. Cover rate limiting with a token bucket and Little's law for concurrency, plus circuit breaking the auth call. Quantify RPC amplification from per-request introspection.
Local JWT validation is fast and resilient but cannot revoke instantly; remote introspection revokes cleanly but adds per-request latency and a hard dependency.