A layer in front of your services.
WHAT A GATEWAY DOES
Receives every request and handles concerns common to all of them.
WHAT IT TYPICALLY HANDLES
Authentication Rate limiting Routing to the right service Logging Request and response transformation Caching
WHY CENTRALISE THOSE
Implementing them in every service produces inconsistency and duplication.
WHAT IT PROVIDES ORGANISATIONALLY
One place to enforce policy One place to see all traffic A stable public surface over changing internals
WHAT IT COSTS
Another component to operate A single point of failure Latency on every request
WHAT TO BE CAREFUL WITH
Business logic creeping into it Configuration nobody has in version control Becoming dependent on a specific product
WHY THAT FIRST POINT MATTERS
Logic in the gateway is invisible to anyone reading the service.
WHEN A GATEWAY IS WORTH IT
Several services behind one interface Public exposure requiring consistent controls Many callers needing management
WHEN IT IS NOT
One application, with a handful of callers.
WHAT TO USE INSTEAD THEN
Middleware inside the application.
WHAT TO KEEP REGARDLESS
Authentication enforced in the service too.
WHY
A misrouted request must not bypass it.