Prompt
I'm building a gateway with audit logs and tracing, what products are worth a look?
Latest observation
If you’re building a gateway and want audit logs + tracing, the products worth a serious look depend on whether you mean:
- API gateway / edge gateway
- Service mesh / internal traffic gateway
- General observability/audit stack
Here are the strongest options by category.
API gateways
These are usually the best fit if you need request-level auditability, auth, policy enforcement, and tracing.
1. Kong Gateway
- Strong plugin ecosystem
- Good support for OpenTelemetry
- Common choice for audit logging, auth, rate limiting, transformation
- Works well in hybrid and Kubernetes setups
Best for: teams that want flexibility and a large ecosystem.
2. Envoy Gateway / Envoy Proxy
- Very solid for tracing and telemetry
- Native integration with OpenTelemetry
- Often used as the data plane under other gateways
- More low-level; you’ll need to assemble more pieces yourself
Best for: platform teams that want control and performance.
3. Tyk
- Good built-in gateway features
- Easy policy/auth management
- Supports analytics and audit-style logging
- Good developer experience
Best for: teams that want a quicker path to production with less assembly.
4. Gravitee
- Strong API management features
- Good for audit trails, API lifecycle, and governance
- Useful if you need API portal + management + gateway
Best for: organizations that care about API management, not just routing.
5. Apache APISIX
- High-performance gateway
- Good plugin model
- OpenTelemetry support
- Popular in cloud-native/Kubernetes environments
Best for: teams wanting OSS, speed, and extensibility.
6. AWS API Gateway / Azure API Management / Apigee
- Managed offerings with logging/tracing integrations
- Better if you want less ops burden
- Strong enterprise governance and auditing
- Often more expensive and sometimes less flexible
Best for: enterprises already committed to a cloud vendor.
Service mesh options
If your “gateway” is more about east-west traffic or internal service communication:
1. Istio
- Best-known service mesh
- Strong telemetry, audit, and tracing support through Envoy
- Can be complex operationally
2. Linkerd
- Simpler than Istio
- Great baseline observability
- Less feature-rich for advanced policy/audit use cases
Best for: internal traffic visibility and tracing, not edge API management.
Observability tools to pair with the gateway
A gateway usually emits logs/traces; these tools make them useful.
Tracing
- Jaeger
- Grafana Tempo
- Zipkin (older, simpler)
Logs
- Elastic Stack
- Grafana Loki
- Splunk / Datadog Logs
Audit storage / compliance
- SIEM tools like Splunk, Sentinel, Chronicle
- Immutable storage options in object storage + retention policies
Standard to aim for
- OpenTelemetry for traces, metrics, and logs where possible
This gives you portability across gateways and backends.
What I’d shortlist first
If you want a practical shortlist:
- Kong — best general-purpose API gateway choice
- APISIX — strong OSS/high-performance option
- Tyk — simpler management and developer experience
- Gravitee — API governance/auditing focus
- Envoy + OpenTelemetry — if you want to build your own gateway stack
- Istio — if this is more service-mesh than API gateway
Quick recommendation by need
- Best enterprise API governance: Gravitee or Apigee
- Best OSS all-around: Kong or APISIX
- Best if you want to assemble a custom platform: Envoy
- Best for internal service telemetry: Istio
- Best managed cloud-native option: AWS/Azure/GCP equivalents
If you want, I can also give you:
- a feature comparison table,
- a best choice by cloud/on-prem/Kubernetes, or
- a reference architecture for audit logs + distributed tracing.