API Gateway and Service Mesh

Learn how API gateways and service meshes route, secure, protect and observe traffic: routing, canaries, rate limits, retries, circuit breakers, mTLS and operations, tested on a real gateway.

Start course →

Syllabus

Gateways and Meshes: the Big Picture

  1. Why Gateways and Meshes Exist
  2. What an API Gateway Does
  3. What a Service Mesh Does
  4. Gateway vs Mesh vs Load Balancer vs Ingress

Routing, Rewriting and Traffic Splitting

  1. The Demo Environment
  2. Routing by Path and Header
  3. Prefix Stripping and Header Injection
  4. Weighted Traffic Splitting for Canaries

Security at the Edge

  1. Authentication at the Gateway
  2. Rate Limiting at the Gateway
  3. TLS Termination, WAF and CORS

Resilience: Timeouts, Retries, Breakers, Balancing

  1. Timeouts and Latency Budgets
  2. Retries, Idempotency and Retry Storms
  3. Circuit Breakers and Outlier Detection
  4. Load Balancing Algorithms and Consistent Hashing

Service Mesh in Practice

  1. Mutual TLS and Workload Identity
  2. Traffic Management as Configuration
  3. Service-to-Service Authorisation
  4. Observability: Golden Signals and Tracing

Choosing and Operating

  1. Choosing a Gateway or Mesh
  2. Running It: Availability, Config and Upgrades
  3. Common Pitfalls and Failure Drills

Gateway Patterns and Progressive Delivery

  1. Backend for Frontend and Aggregation
  2. Shadowing, Blue-Green and Progressive Delivery

Putting It Together

  1. Case Study: Designing the Edge for an Orders Platform
  2. Revision: Cheat Sheet and Self-Check