Design a Rate-Limited API Gateway (Kong / Envoy)
Architect edge perimeter infrastructure: Dynamic path-based routing, JWT token validation, distributed token bucket rate limiting, and circuit breaking.
01.1. Functional & Non-Functional Requirements
An API Gateway serves as the single perimeter entry point for all external web, mobile, and third-party API traffic, centralizing cross-cutting concerns (authentication, rate limiting, routing, SSL offloading, observability) before forwarding requests to internal microservices.
Functional Requirements
- Dynamic Path-Based Routing: Route requests (e.g.,
/api/v1/orders/*→Order Service) based on path, HTTP methods, or headers. - Authentication & Authorization: Verify JWT signatures and API keys at the perimeter.
- Distributed Rate Limiting: Enforce per-user, per-IP, and per-tenant rate limits using Token Bucket algorithms.
- Protocol Translation & SSL Offloading: Terminate external TLS 1.3 HTTPS/HTTP2 traffic and route internally via gRPC or HTTP/1.1 with mutual TLS (mTLS).
- Circuit Breaking & Outlier Detection: Automatically shed load or return fallback responses when a downstream microservice degrades.
Non-Functional Requirements
- Ultra-Low Latency Overhead: Gateway filter pipeline must execute in
< 2 ms(p99). - High Throughput: Handle
> 100,000 requests/secondacross an autoscaling gateway fleet. - High Availability & Statelessness: Zero local state on gateway nodes; all rate limit counters stored externally in Redis.
Edge API Gateway Multi-Stage Filter Pipeline Architecture 🛡️
Edge API Gateway Multi-Stage Filter Pipeline Architecture 🛡️
Stateless Envoy/Kong proxy fleet executing TLS termination, local JWT verification, Redis token-bucket rate limiting, and dynamic path routing.
Unlock Topic #249: Design a Rate-Limited API Gateway (Kong / Envoy)
You are viewing a preview. The full in-depth engineering deep dive, interactive simulators, architecture flowcharts, and self-assessment quizzes for this topic are available with Pro or Lifetime Access.
Failure modes, high-throughput bottlenecks, and real FAANG implementation decisions.
Interactive system topology diagrams, live parameter simulators, and downloadable SVG charts.
Staff-level multiple-choice quiz questions with instant feedback and answer explanations.
Firebase Google authentication automatically syncs your completed topics and quiz scores.
How clear and staff-actionable was this system breakdown?