Amazon Web Services

API Gateway — Managed HTTP Front Door

Put a managed API layer in front of Lambda or containers, with auth, throttling and validation handled before your code runs.

API Gateway terminates the HTTP request and handles the work you would otherwise write in every service.

The reception desk of an office building. Visitors are checked against the guest list, signed in, and limited to a sensible number at once — so the people upstairs only ever deal with those who should be there.

Key Concepts

1
    client -> API Gateway -> Lambda / ALB / any HTTP endpoint
                 |
          auth, throttling, validation, caching, logging
2
Two flavours, and the choice comes up in interviews.
    REST API   more features: request validation, API keys, usage plans,
               WAF, caching, per-method settings. Higher price.
    HTTP API   roughly 70% cheaper and lower latency, with JWT auth
               built in. Fewer features. The default for new work.
3
Authorisation has three options.
    IAM            service-to-service, signed with SigV4
    Cognito / JWT  user-facing apps, token validated at the edge
    Lambda authorizer  your own logic, result cached by policy TTL
4
A Lambda authorizer runs before your handler, so an unauthenticated request never reaches your code or your database.
5
Throttling protects what is behind it.
    account limit    10,000 requests/second by default
    per-stage        set a ceiling for the whole API
    usage plan       per-API-key limits for different customers
6
Exceeding it returns 429 Too Many Requests, which is the answer to "how do you stop one client taking the service down".
429 Too Many Requests
7
Stages map to environments.
    /dev   /staging   /prod      each with its own variables and throttles
8
Request validation rejects bad input at the gateway, against a JSON Schema model, so malformed payloads never cost you a Lambda invocation.
9
The watch-outs. The integration timeout is 29 seconds maximum, so a long job must go asynchronous and return a job id. Payloads are capped at 10 MB. And caching is charged per hour whether or not it is used.
10
When not to use it. For a simple public service on containers, an ALB is cheaper and has no 29-second limit. API Gateway earns its cost when you want the auth, keys and throttling without building them.
11
What the interviewer is probing.1. "REST API or HTTP API?" Probing: whether you know the trade. Stalls: "REST, it is the full one." Moves up: HTTP API is cheaper and faster with JWT auth built in; REST adds request validation, API keys, usage plans and caching — pick by the features you need.
12
2. "A job takes two minutes. How do you expose it?" Probing: the 29-second limit. Stalls: "Raise the timeout." Moves up: you cannot — the integration timeout is 29 seconds, so accept the request, return 202 with a job id, and process asynchronously.
13
3. "How do you stop one client taking the service down?" Probing: throttling. Stalls: "Scale the backend." Moves up: usage plans with per-key limits and stage throttling, which return 429 before the backend is reached.
14
4. "When is an ALB the better choice?" Probing: whether you can argue against the service. Stalls: "Never." Moves up: for plain container traffic with no need for keys, quotas or managed auth — it is cheaper and has no 29-second cap.