Skip to Content

API Gateway

Apache APISIX configuration, routing, and plugins.

Overview

APISIX provides:

  • Dynamic routing synchronized from Consul
  • Authentication (JWT, API Key)
  • Rate limiting and circuit breaking
  • CORS and security headers
  • SSL/TLS termination
  • Prometheus metrics

Ports

PortPurpose
9080HTTP Gateway
9443HTTPS Gateway
9180Admin API

Architecture

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ External Traffic β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ APISIX Gateway β”‚ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ β”‚ β”‚ Auth β”‚ β”‚ Rate β”‚ β”‚ CORS β”‚ β”‚ Logging β”‚ β”‚ β”‚ β”‚ Plugin β”‚ β”‚ Limiter β”‚ β”‚ Plugin β”‚ β”‚ Plugin β”‚ β”‚ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Consul Service Discovery β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β”‚ β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”‚ Backend Services β”‚ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

Route Configuration

Create Route

curl -X PUT http://localhost:9180/apisix/admin/routes/1 \ -H "X-API-KEY: admin-key" \ -H "Content-Type: application/json" \ -d '{ "uri": "/api/v1/users/*", "upstream": { "type": "roundrobin", "discovery_type": "consul", "service_name": "auth_service" }, "plugins": { "jwt-auth": {}, "limit-req": { "rate": 100, "burst": 50 } } }'

Route with Consul Discovery

routes: - uri: /api/v1/auth/* upstream: discovery_type: consul service_name: auth_service plugins: limit-req: rate: 5 burst: 10 - uri: /api/v1/users/* upstream: discovery_type: consul service_name: profile_service plugins: jwt-auth: {}

Plugins

JWT Authentication

{ "plugins": { "jwt-auth": { "key": "user-key", "secret": "your-secret" } } }

Rate Limiting

{ "plugins": { "limit-req": { "rate": 100, "burst": 50, "key_type": "consumer_name" }, "limit-count": { "count": 1000, "time_window": 3600, "key_type": "var", "key": "remote_addr" } } }

CORS

{ "plugins": { "cors": { "allow_origins": "https://app.isa.io", "allow_methods": "GET,POST,PUT,DELETE", "allow_headers": "Authorization,Content-Type", "max_age": 3600 } } }

Rate Limits by Tier

Endpoint TypeRateBurst
Public (login)5/min10
Authenticated100/min200
Admin1000/min500
InternalUnlimited-

Monitoring

Prometheus Metrics

curl http://localhost:9091/apisix/prometheus/metrics

Available metrics:

  • apisix_http_status - HTTP status codes
  • apisix_bandwidth - Bandwidth usage
  • apisix_http_latency - Request latency
  • apisix_upstream_status - Upstream health

Admin API

List Routes

curl http://localhost:9180/apisix/admin/routes \ -H "X-API-KEY: admin-key"

List Upstreams

curl http://localhost:9180/apisix/admin/upstreams \ -H "X-API-KEY: admin-key"

Troubleshooting

Route Not Working

# Check route exists curl http://localhost:9180/apisix/admin/routes/1 -H "X-API-KEY: admin-key" # Check upstream health curl http://localhost:9180/apisix/admin/upstreams/1 -H "X-API-KEY: admin-key"

Service Not Found

# Verify Consul registration curl http://localhost:8500/v1/catalog/service/auth_service # Check APISIX logs kubectl logs -l app=apisix -n isa-cloud-staging

Next Steps