API Gateway and Service Mesh
Learn how API gateways and service meshes route, secure, protect and observe traffic: routing, canaries, rate limits, retries, circuit breakers, mTLS and operations, tested on a real gateway.
Syllabus
Gateways and Meshes: the Big Picture
- Why Gateways and Meshes Exist
- What an API Gateway Does
- What a Service Mesh Does
- Gateway vs Mesh vs Load Balancer vs Ingress
Routing, Rewriting and Traffic Splitting
- The Demo Environment
- Routing by Path and Header
- Prefix Stripping and Header Injection
- Weighted Traffic Splitting for Canaries
Security at the Edge
Resilience: Timeouts, Retries, Breakers, Balancing
- Timeouts and Latency Budgets
- Retries, Idempotency and Retry Storms
- Circuit Breakers and Outlier Detection
- Load Balancing Algorithms and Consistent Hashing
Service Mesh in Practice
- Mutual TLS and Workload Identity
- Traffic Management as Configuration
- Service-to-Service Authorisation
- Observability: Golden Signals and Tracing
Choosing and Operating
- Choosing a Gateway or Mesh
- Running It: Availability, Config and Upgrades
- Common Pitfalls and Failure Drills