Prompt
What API gateway should I use for rate limiting and observability?
Latest observation
Oct 5, 2026
OpenAI APIWeb search: off
If your main goals are rate limiting and observability, the best API gateway depends on your stack and how much ops burden you want.
Good default choices
1) Kong Gateway
Best if you want a strong open-source option with lots of plugins.
- Rate limiting: built-in, flexible
- Observability: good support for Prometheus, OpenTelemetry, logging plugins
- Pros: mature, widely used, good ecosystem
- Cons: advanced features can push you toward paid tiers
Best for: teams that want a battle-tested gateway and plugin-based extensibility.
2) NGINX Plus / NGINX Open Source
Best if you want performance and simplicity.
- Rate limiting: very solid at the proxy layer
- Observability: decent, especially with Prometheus/OpenTelemetry integrations
- Pros: fast, stable, familiar
- Cons: less “API-management” friendly than dedicated gateways; feature depth varies by edition
Best for: high-throughput environments and teams already comfortable with NGINX.
3) Envoy Gateway / Envoy Proxy
Best if you’re in a cloud-native / Kubernetes environment.
- Rate limiting: strong, especially with external rate limit services
- Observability: excellent, especially with OpenTelemetry
- Pros: modern, highly extensible, great telemetry
- Cons: more complex to operate than simpler gateways
Best for: Kubernetes-first platform teams.
4) AWS API Gateway / Azure API Management / Google Cloud API Gateway
Best if you want managed service and minimal ops.
- Rate limiting: good native throttling
- Observability: integrated with cloud logs/metrics/tracing
- Pros: low maintenance, easy integration with cloud ecosystem
- Cons: vendor lock-in, can get expensive, less flexible for deep customization
Best for: teams that prefer managed cloud services.
My practical recommendation
- Small/medium team, self-hosted: Kong Gateway
- Kubernetes-native platform: Envoy Gateway
- Managed cloud environment: AWS API Gateway (or your cloud’s equivalent)
- Performance-first, simple proxy needs: NGINX
For observability, look for support for:
- OpenTelemetry
- Prometheus metrics
- Structured access logs
- Distributed tracing headers
- Dashboards/alerting integration
For rate limiting, make sure it supports:
- Per-route and per-consumer limits
- Burst handling
- Distributed rate limiting across replicas
- IP, token, user, API-key based policies
- Custom quotas and sliding windows if needed
If you tell me:
- your cloud/provider,
- whether you use Kubernetes,
- expected traffic volume,
- self-hosted vs managed,
…I can recommend a specific gateway setup.