Items related to Modern API Gateways in Production: Build Secure, Scalable...

Modern API Gateways in Production: Build Secure, Scalable API Platforms with Kong, Envoy Gateway, Kubernetes Gateway API, Apache APISIX, NGINX, OAuth 2.0, Zero Trust, GitOps, Observability, and AI - Softcover

Vexel, Alira

 
9798172876707: Modern API Gateways in Production: Build Secure, Scalable API Platforms with Kong, Envoy Gateway, Kubernetes Gateway API, Apache APISIX, NGINX, OAuth 2.0, Zero Trust, GitOps, Observability, and AI

Synopsis

Modern API Gateways in Production

Modern APIs are no longer simple application endpoints. They connect microservices, mobile applications, partners, cloud platforms, AI models, MCP servers, and autonomous agents—while carrying sensitive data, business transactions, and production-critical traffic.

This book shows you how to design, deploy, secure, automate, observe, scale, and operate a complete modern API gateway platform using Kubernetes Gateway API, Kong Gateway, Envoy Gateway, Apache APISIX, NGINX, Keycloak, Open Policy Agent, Argo CD, Terraform, OpenTelemetry, Ollama, vLLM, and other production technologies.

Written for platform engineers, DevOps engineers, SREs, cloud architects, security engineers, Kubernetes administrators, API developers, and infrastructure professionals, this practical guide moves beyond basic reverse-proxy configuration. You will build an operator-grade platform that supports REST, gRPC, WebSocket, asynchronous, AI, LLM, MCP, and agent traffic.

Inside this book, you will learn how to:

• Build a repeatable Kubernetes API gateway laboratory
• Understand the complete gateway request lifecycle
• Deploy Kubernetes Gateway API with Kong and Envoy Gateway
• Configure HTTPRoute, GRPCRoute, TCPRoute, UDPRoute, TLSRoute, and ReferenceGrant
• Implement advanced routing, canary releases, blue-green delivery, retries, timeouts, mirroring, and traffic splitting
• Secure APIs with OAuth 2.0, OpenID Connect, JWT, API keys, TLS, mTLS, Keycloak, and OPA
• Enforce tenant isolation, least privilege, quotas, rate limits, schemas, and Zero-Trust access
• Protect against API abuse, broken authorization, injection, SSRF, resource exhaustion, and other OWASP API risks
• Build Prometheus metrics, Grafana dashboards, structured logs, and OpenTelemetry traces
• Engineer health checks, circuit breakers, outlier detection, load shedding, autoscaling, SLOs, and disaster recovery
• Manage routes, plugins, policies, certificates, and environments with Helm, Kustomize, Argo CD, GitOps, Terraform, and OpenTofu
• Compare Kong, Envoy Gateway, Apache APISIX, NGINX, Traefik, KrakenD, Tyk, Gravitee, WSO2, and managed cloud API platforms
• Build a multi-provider AI gateway for OpenAI-compatible services, Ollama, and vLLM
• Apply model allowlists, token limits, cost budgets, guardrails, semantic caching, and provider fallback
• Secure MCP servers, control tool access, govern agent-to-agent traffic, and prevent excessive permissions
• Execute performance tests, attack simulations, failure injection, migration testing, and production-readiness validation

The final capstone brings every major capability together into a full-stack production platform containing Kong Gateway, Envoy Gateway, Apache APISIX, Keycloak, OPA, cert-manager, Prometheus, Grafana, OpenTelemetry, Argo CD, Terraform, REST, gRPC, WebSocket, AI, LLM, and MCP services.

You will deploy the platform, secure every traffic boundary, release a defective canary, diagnose failures, recover from certificate and identity outages, migrate between gateway implementations, and produce operational runbooks, architecture records, dashboards, capacity plans, and handover documentation.

The appendices provide reusable commands, Gateway API manifests, security templates, troubleshooting matrices, production checklists, migration worksheets, capacity-planning references, and a comprehensive technical glossary.

This is not a theoretical overview or a collection of disconnected examples. It is a practical, production-focused guide to building API gateway infrastructure that is secure, portable, observable, scalable, automated, AI-ready, and recoverable.

Build more than a gateway.

Build the trusted control plane for your APIs, microservices, models, tools, and agents.

"synopsis" may belong to another edition of this title.