PRIMITIVE #14Core Distributed Systems Component
API Gateway & Reverse Proxy
1. What It Is & Why It Exists
The Core Problem: Direct Client-to-Microservice Chaos
In a distributed microservices ecosystem, allowing mobile apps and browser clients to communicate directly with individual backend microservices introduces critical architectural vulnerabilities:
- Security Attack Surface: Exposing hundreds of internal private IP endpoints directly to the public internet.
- Duplicated Cross-Cutting Logic: Every microservice team must independently build and maintain authentication (JWT validation), rate limiting, SSL/TLS certificates, CORS headers, and audit logging.
- Protocol & Network Friction: Mobile clients on high-latency cellular networks must make 15 separate roundtrips to hydrate a single page (the "Chatty Client" problem), while internal services communicate over high-performance binary gRPC.
The First-Principles Solution: Reverse Proxy & API Gateway
An API Gateway is a reverse proxy positioned at the network edge that intercepts all incoming client traffic, terminates TLS, enforces authentication, quotas, and security policies, and intelligently routes requests to downstream internal services.
Interactive Architecture DiagramSynthesizing vector architecture diagram...
2. Core Mechanics: Layer 4 vs. Layer 7 Ingress
Interactive Architecture DiagramSynthesizing vector architecture diagram...
Comprehensive Comparison Matrix
| Ingress Proxy | OSI Layer | Routing Criteria | Latency Overhead | Memory Footprint | Primary Production Fit |
|---|---|---|---|---|---|
| Amazon API Gateway | Layer 7 | Method + Path (/v1/orders), JWT claims | Serverless | Serverless architectures, AWS Lambda, external partner APIs | |
| Envoy Proxy | Layer 7 | Path, Headers, Query params, gRPC | Low (C++ event loop) | Kubernetes Service Mesh (Istio), high-throughput internal routing | |
| AWS ALB | Layer 7 | Host header, Path, Query parameters | Managed | General microservices, ECS container fleets, web applications | |
| AWS NLB | Layer 4 | TCP / UDP / TLS ports | Managed | Ultra-high throughput gaming, IoT streaming, static IP requirements | |
| Nginx | Layer 7 | URI, Regular Expressions | Low (C event-driven) | Static asset reverse proxy, edge caching |
Part 2: Production Deep-Dive Locked1 Coin = 24 Hours
Unlock Complete Architecture & Production Runbooks
Your Balance:40 Coins
You have explored the free architectural preview (~44%). Spend 1 Coin to unlock the remaining 5 production deep-dive sections for a full 24 hours.
Sections Included in This 24-Hour Pass:
3. Resilience Patterns: Circuit Breakers & Adaptive Concurrency Limiting
4. Critical Edge Cases & Distributed Failure Modes
5. Production Pitfalls & Anti-Patterns (The "Gotchas")
6. AWS Cloud Service Implementation & Production Patterns
7. Production Sizing Formulas & Operational Runbook
Keeps page unlocked for exactly 24 hoursSpend coins to fund LLM & compute infrastructure