System design2 min
Reverse Proxies & API Gateways
As your system scales from a monolithic architecture to microservices, the complexity of managing client-to-server communication explodes. This is where Reverse Proxies and API Gateways come in.
Reverse Proxy
A Forward Proxy sits in front of clients and protects them from the internet (e.g., a corporate proxy blocking Facebook). A Reverse Proxy sits in front of servers and protects them from the internet.
When a user tries to access your website, they don't hit your backend application server directly. They hit the Reverse Proxy (like NGINX or HAProxy), which then forwards the request to your backend.
Benefits of a Reverse Proxy:
- Security: It hides the existence and characteristics of your origin servers. It can drop malicious requests before they ever reach your app.
- SSL Termination: Decrypting HTTPS is CPU intensive. The reverse proxy handles the decryption, allowing your internal servers to communicate via fast, unencrypted HTTP.
- Static Content Caching: It can cache images and CSS locally, serving them instantly without bothering the backend application.
- Compression: It can compress outgoing data (using GZIP or Brotli) to save bandwidth.
API Gateway
An API Gateway is essentially a Reverse Proxy on steroids. While a reverse proxy handles generic web traffic, an API Gateway is specifically designed to manage, secure, and route API calls in a microservices architecture.
Imagine a mobile app that needs to load a user's profile. In a microservices architecture, this might require data from the User Service, the Order Service, and the Review Service. If the mobile app makes 3 separate network requests over a 3G connection, the user experience will be terrible.
Core Features of an API Gateway:
- Request Routing: It acts as the single entry point. The client calls
api.example.com/profile, and the Gateway knows exactly which internal microservices to route that request to. - API Composition / Aggregation: To solve the 3G network issue, the Gateway can take a single request from the mobile app, fan it out to the 3 internal services simultaneously, aggregate their JSON responses into one massive payload, and send it back to the mobile app in a single round trip.
- Authentication & Authorization: Instead of every microservice verifying JWT tokens, the Gateway validates the user's identity once at the perimeter.
- Rate Limiting & Throttling: It protects internal services from DDoS attacks or accidental spam by limiting how many requests a user can make per second.
- Protocol Translation: It might accept standard HTTP/REST requests from the client, but translate them into gRPC calls internally for blazing-fast microservice communication.
Popular API Gateways: Kong, AWS API Gateway, Apigee, Traefik.