Chuyển đến nội dung chính

レッスン 18: API ゲートウェイ — 実際の戦闘での Kong、APISIX、Envoy

APIゲートウェイ:なぜ必要なのか、主な機能。 Kong、APISIX、Envoy ゲートウェイ、AWS API ゲートウェイを比較します。認証、レート制限、ルーティング、負荷分散を構成します。宣言型構成と GitOps。

🏗️ アーキテクチャ — レッスン 18 レッスン 18: API ゲートウェイ — Kong、APISIX、Envoy 実戦

マイクロサービスとマイクロ フロントエンドのシステム設計 — 基本から運用まで

パート 6: API ゲートウェイと BFF レイヤー

xdev.asia

はじめに

API ゲートウェイは、フロントエンドからのすべての API 呼び出しに対する 単一のエントリ ポイントです。認証、レート制限、ルーティング、監視などの横断的な問題に対応し、マイクロサービスがビジネス ロジックに集中できるように支援します。

API ゲートウェイ — すべてのリクエストに対する単一のエントリ ポイント


1. API ゲートウェイが必要な理由は何ですか?

1.1 ゲートウェイなし

❌ Client gọi trực tiếp services:

Frontend ──► User Service    (port 8001)
         ──► Product Service (port 8002)
         ──► Order Service   (port 8003)
         ──► Cart Service    (port 8004)

Vấn đề:
- Frontend phải biết địa chỉ từng service
- Mỗi service tự implement auth, rate limit, CORS
- Không có single point for monitoring/logging
- Service addresses thay đổi → frontend phải update

1.2 API ゲートウェイを使用する

✅ Single entry point:

Frontend ──► API Gateway (/api/*) ──► User Service
                                  ──► Product Service
                                  ──► Order Service

API Gateway handles:
├── Authentication (JWT verification)
├── Rate Limiting (100 req/min per user)
├── Routing (path-based → service)
├── Load Balancing (round-robin)
├── SSL Termination
├── CORS
├── Request/Response transformation
└── Monitoring & Logging

2. API ゲートウェイの比較

特長コンAPISIXエンボイ ゲートウェイAWS API GW
コアNginx/OpenRestyNginx/etcd特使代理人管理
パフォーマンス高非常に高い非常に高い高
プラグイン100+80+フィルター経由AWS ネイティブ
K8s ネイティブコングイングレスAPISIX イングレスK8s ゲートウェイ API該当なし
構成DB/宣言型etcd/YAMLK8s CRDコンソール/CF
ダッシュボードコングマネージャーApache ダッシュボード該当なしコンソール
コストオープンソースオープンソースオープンソースリクエストごとに支払う
こんな用途に最適一般高パフォーマンス、中国K8s ネイティブAWS エコシステム

3. Kong の構成

3.1 宣言型構成 (kong.yml)

_format_version: "3.0"

services:
  - name: product-service
    url: http://product-svc:8080
    routes:
      - name: product-routes
        paths:
          - /api/v1/products
        strip_path: false
    plugins:
      - name: jwt
      - name: rate-limiting
        config:
          minute: 100
          policy: redis
          redis_host: redis
      - name: cors
        config:
          origins: ["https://app.example.com"]
          methods: ["GET", "POST", "PUT", "DELETE"]

  - name: order-service
    url: http://order-svc:8080
    routes:
      - name: order-routes
        paths:
          - /api/v1/orders
    plugins:
      - name: jwt
      - name: rate-limiting
        config:
          minute: 50

3.2 主要なプラグイン

プラグイン目的
jwtJWT トークンを検証する
rate-limiting消費者ごとのレート制限
corsCORS ヘッダー
request-transformerリクエストのヘッダー/本文を変更する
response-transformer応答を変更
prometheusメトリクスエンドポイント
file-log / tcp-logロギング
ip-restrictionホワイトリスト/ブラックリスト IP

4. APISIX 構成

routes:
  - uri: /api/v1/products/*
    upstream:
      type: roundrobin
      nodes:
        "product-svc:8080": 1
    plugins:
      jwt-auth:
        key: "product-key"
      limit-req:
        rate: 100
        burst: 50
        key_type: "var"
        key: "consumer_name"

  - uri: /api/v1/orders/*
    upstream:
      nodes:
        "order-svc:8080": 1
    plugins:
      jwt-auth: {}

5. ゲートウェイのパターン

5.1 パスベースのルーティング

/api/v1/products/*  → Product Service
/api/v1/orders/*    → Order Service
/api/v1/users/*     → User Service
/api/v1/cart/*      → Cart Service

5.2 ヘッダーベースのルーティング

X-API-Version: v2 → v2 service
X-Client-Type: mobile → mobile-optimized service

5.3 カナリアルーティング

95% traffic → Product Service v1 (stable)
5% traffic  → Product Service v2 (canary)

6. API ゲートウェイの GitOps

Repository:
├── gateway/
│   ├── kong.yml (declarative config)
│   ├── plugins/
│   └── consumers/
└── .github/workflows/
    └── deploy-gateway.yml

CI/CD:
1. PR: change gateway config
2. Review: team review routing/auth changes
3. Merge: auto-apply via deck sync (Kong)
4. Monitor: check metrics after deploy

概要

  • API ゲートウェイ = すべての API 呼び出しに対する 単一のエントリ ポイント
  • 横断的な処理: 認証、レート制限、ルーティング、モニタリング
  • Kong: 汎用、成熟した、豊富なプラグイン
  • APISIX: etcd を介した高性能の動的プラグイン
  • Envoy ゲートウェイ: K8s ゲートウェイ API ネイティブ
  • GitOps: 宣言型構成、バージョン管理

次の記事: レッスン 19: GraphQL フェデレーション — マイクロ フロントエンド用の統合 API