API Gateway Pattern
API Gateway is the single entry point for clients — routing, authentication, rate limiting, request aggregation, and protocol translation before traffic hits internal services.
Introduction
API Gateway is the single entry point for clients — routing, authentication, rate limiting, request aggregation, and protocol translation before traffic hits internal services.
The story
Mobile clients called 8 internal services directly — auth tokens leaked into logs, versioning chaos. Kong gateway at the edge: JWT validation, route /api/v1/* to services, BFF for mobile-specific payloads. Client complexity dropped 70%.
The business problem
Teams that skip disciplined API Gateway Pattern thinking pay in coupling, outages, and failed microservices interviews:
- Distributed ops: no tracing or health checks — hours to debug one checkout failure.
- Coupling: shared databases and libraries recreate monolith pain across the network.
- Deploy blast radius: one bad service deploy takes down unrelated domains.
- Team boundaries: services aligned to tech layers instead of business capabilities.
The problem teams faced
This lesson addresses:
- When and why API Gateway Pattern matters in decomposed architectures.
- How to define service boundaries and contracts under interview time pressure.
- Trade-offs vs alternatives — what staff engineers articulate in architecture reviews.
- Production patterns and failure modes in distributed systems.
Understanding the topic
Core idea: API Gateway Pattern in microservices architecture.
- Problem — distributed ops and coupling this topic addresses.
- Service design — boundaries, contracts, and data ownership.
- Trade-offs — sync vs async, consistency, deploy blast radius.
- Interview — how this appears in decomposition loops.
Internal architecture
API Gateway Pattern — microservices view:
Clients → API Gateway↓ auth · rate limit · TLS├─ /catalog/* → Catalog Service├─ /orders/* → Order Service└─ /mobile/* → Mobile BFF → multiple services↓Internal services not exposed to public internet
Visual explanation
Three diagrams: service architecture, decomposition process, and operational lens:
Informative example
Example — API Gateway Pattern:
Gateway responsibilities:- Authentication / JWT validation- Rate limiting per API key- Request routing + load balancing- Optional: response caching, WAFNot: business logic — keep domain rules in services
Execution workflow
Identify bounded context
Domain language and team ownership.
Real-world use
Netflix pioneered microservices at scale with hundreds of services and chaos engineering. Amazon's two-pizza teams and service-oriented architecture shaped modern decomposition. Uber migrated from monolith to domain-aligned services for independent deploys. Spotify uses squad-aligned microservices with internal platform tooling. These journeys inform every pattern in this course.
Production case study
Mobile clients called 8 internal services directly — auth tokens leaked into logs, versioning chaos. Kong gateway at the edge: JWT validation, route /api/v1/* to services, BFF for mobile-specific payl…
- Context: monolith pain or decomposition scenario from this lesson.
- Decision: service boundary and communication choices explained.
- Outcome: deploy frequency, incident isolation, or latency impact.
Trade-offs
- Pro: team autonomy and isolated failure domains.
- Con: distributed complexity — tracing, sagas, contract tests.
- Con: premature decomposition costs more than a modular monolith.
Decision framework
- Start modular monolith; extract when bounded context and team force are proven.
- Database-per-service — integrate via API and events, not shared schema.
- Document rejected alternatives — ADR or interview closing statement.
Best practices
- Align services to business capabilities, not technical layers.
- Draw sync vs async paths; propagate trace context on every hop.
- Health checks + readiness gates before traffic shift.
Anti-patterns to avoid
- Distributed monolith — shared DB, coupled deploys, synchronous chains everywhere.
- Nano-services — operational overhead exceeds team benefit.
- Shared libraries hiding domain coupling between teams.
Common mistakes
- Splitting before bounded contexts are clear — endless refactor.
- Cross-service transactions without saga or idempotency.
Debugging tips
- Follow one trace_id through the decomposition diagram.
- Ask "what couples these services?" for every sync call.
Optimization strategies
- Replace sync chains with domain events where latency allows.
- BFF to aggregate calls — don't make clients orchestrate services.
Common misconceptions
- Microservices ≠ always better — monolith wins for small teams and unclear domains.
- Interviews test decomposition judgment — not memorizing Netflix's service count.
Advanced interview questions
Interview Prep
Practice concise answers, then expand each card for the explanation.
1IntermediateQuestionHow would you decompose a monolith involving API Gateway Pattern?+
Answer
Follow-up
2IntermediateQuestionWhat breaks if API Gateway Pattern is wrong?+
Answer
Follow-up
3AdvancedQuestionSenior trade-off for API Gateway Pattern?+
Answer
Follow-up
Summary
You can explain API Gateway Pattern in microservices interviews and production RFCs — with bounded contexts, data ownership, and resilience patterns. Teach it back without notes.