An API gateway sits in front of backend services to perform common checks and forward requests. Clients use one entry address; the gateway authenticates or limits calls before routing by path. This reduces duplicated cross-cutting logic in services.
The demo passes a call through authentication and rate limiting toward an order service, then stops an uncredentialed call at the first check. Operate and observe the gateway so it does not become a bottleneck or single point of failure.
When to use
Use it when multiple services share public entry, authentication, and limit policies.