4
System Design
Should we put an API gateway in front of three services?
Context
We have three backend services and one web client. Someone proposed introducing an API gateway (Kong or AWS API Gateway) for auth, rate limiting and routing.
My hesitation: it's another hop, another config surface and another thing to page on. At what point does a gateway pay for itself versus a shared middleware library in each service?
I'm interested in concrete thresholds people have used: number of services, number of client types, or external API exposure.
Community discussion
2 comments
Have you made this decision in production? Share your reasoning.
Sign in to commentOur trigger was the first external consumer. Once partners needed keys, quotas and usage analytics, the gateway paid for itself immediately. For internal-only traffic, shared middleware was fine.
If you're on Kubernetes, your ingress controller probably already does 80% of this (TLS, routing, basic rate limits). Start there before adding a dedicated gateway product.