# API Gateway क्या करता है — API Gateway और Service Mesh

Source: https://www.geekswithgeeks.com/hi/api-gateway-service-mesh/c-gateway-role

> API gateway की ज़िम्मेदारियाँ गिनाएँ और क्या उसमें नहीं होना चाहिए।

## एक सामने का दरवाज़ा

**API gateway** client अनुरोधों का एकल प्रवेश-बिंदु है। आम काम: host, path, method या header से सही backend तक **routing**; **authentication** और मोटी authorisation (API keys, JWT या OAuth validation); **rate limiting** और quotas; **TLS termination**; **अनुरोध/response रूपांतरण** (path बदलना, headers जोड़ना या हटाना); **caching**; **load balancing** और health checks; **observability** (access logs, metrics, request IDs); और कभी-कभी कई backend calls का **aggregation**। **व्यावसायिक तर्क gateway से बाहर रखें**: वह पतला configuration और नीति होना चाहिए, वरना वह bottleneck और deployment का ऐसा जोखिम बन जाता है जिस पर हर टीम निर्भर है।

## Gateway से अनुरोध का रास्ता

हर चरण नीति को हर service की जगह एक बार लागू करने की जगह है।

```text
client --HTTPS--> [ gateway ]
                     1. terminate TLS
                     2. authenticate (API key / JWT)
                     3. rate limit per client
                     4. route by host/path/header   --> orders-service
                     5. add X-Request-ID, strip internal headers
                     6. log + metrics            --> users-service
```

## Gateway को stateless रखें

Stateless gateway load balancer के पीछे copies जोड़कर scale होता है और restarts सह लेता है। साझा state (rate-limit counters, sessions) Redis जैसे तेज़ बाहरी store में रखें।

**Quiz:** API gateway में क्या आता है?

- [x] Authentication, rate limiting और routing
- [ ] Order pricing के व्यावसायिक नियम
- [ ] Database migrations
- [ ] UI डिज़ाइन

*Answer:* Authentication, rate limiting और routing. क्रॉस-कटिंग नीति gateway में ठीक बैठती है; व्यावसायिक नियम services में।
