Prompt
Should I put API gateway policies at the edge or inside each service?
Latest observation
Usually: put cross-cutting API gateway policies at the edge, and put service-specific enforcement inside each service.
Good candidates for the edge (API gateway)
Use the gateway for things that are uniform across many services and benefit from central control:
- Authentication / token validation
- Basic authorization checks, if they’re coarse-grained
- Rate limiting / throttling / quotas
- Request size limits
- IP allow/deny lists
- TLS termination
- Routing, versioning, and path-based traffic shaping
- Logging, correlation IDs, and basic observability
- Caching for safe, read-heavy endpoints
Good candidates inside each service
Put enforcement inside services for things that are domain-specific or must be authoritative:
- Fine-grained authorization
- Business rules and validation
- Ownership checks and tenant boundaries
- Data-level access control
- Idempotency handling
- Audit logic tied to the domain
- Anything that must still hold if the gateway is bypassed
Why not only at the gateway?
Because the gateway is an entry point, not a trust boundary you should rely on exclusively. Internal calls, misconfigurations, direct service access, or future architecture changes can bypass it. If a rule is important to correctness or security, enforce it again in the service.
Practical rule of thumb
- Gateway = perimeter policy
- Service = domain policy
- If a policy protects the business, verify it in the service
- If a policy protects the platform, centralize it at the gateway
Example
If you have “only premium users can export reports”:
- Gateway can block obviously unauthenticated or over-quota requests.
- The report service must still check whether the user actually has premium access.
Recommended approach
A layered model works best:
- Gateway handles common, reusable controls.
- Services enforce the rules they own.
- Optional shared policy libraries or policy engines help keep logic consistent.
If you want, I can also give you a decision matrix for specific policies like auth, rate limiting, tenant isolation, and schema validation.