Google Cloud

API Management — API Gateway & Apigee

Put a managed gateway in front of serverless backends, and know when the heavier product is justified.

GCP has two, at very different weights.

A reception desk in front of a locked floor. Visitors are checked and signed in, and the lift will not take anyone up who did not come past the desk.

Key Concepts

1
    API Gateway   lightweight, serverless, cheap. Fronts Cloud Run,
                  Functions and App Engine. Config is OpenAPI.
    Apigee        full API management platform: monetisation,
                  developer portal, analytics, policy engine.
                  Enterprise pricing.
2
API Gateway is configured as an OpenAPI document.
    paths:
      /orders:
        post:
          x-google-backend:
            address: https://orders-abc.run.app
          security:
            - firebase: []
3
That single file defines routing, the backend and the auth requirement — there is no separate policy language.
4
Authentication options.
    API keys        identify the caller, meter usage. Not a secret.
    Firebase / Auth0 / Okta  JWT validated at the gateway
    Google ID token service-to-service
    service account the gateway calls the backend as itself
5
The gateway should call a private backend. Deploy Cloud Run with ingress restricted to internal and the gateway's service account, so nobody can bypass the gateway by calling the Run URL directly. Forgetting this is the common mistake — the gateway enforces auth while the backend sits open.
6
Quotas and rate limits are declared per method and per consumer project, which is how you stop one client exhausting the backend.
7
Apigee is a different class of product. It adds a policy pipeline comparable to other clouds' gateways, a developer portal, API products and monetisation, deep analytics, and hybrid deployment. It is the right answer when APIs are the product and there are external paying consumers — and considerable overkill for internal service routing.
8
Choosing. Internal or simple public APIs over serverless backends: API Gateway. A public API programme with partners, plans and billing: Apigee.
9
Cloud Endpoints is the older ESP-based option, still seen in existing projects and largely superseded by API Gateway for new work.
10
What the interviewer is probing.1. "API Gateway or Apigee?" Probing: proportionality. Stalls: "Apigee, it is the full product." Moves up: API Gateway for internal or simple public APIs over serverless backends; Apigee when APIs are a product with external consumers, plans and monetisation.
11
2. "How do you stop callers bypassing the gateway?" Probing: the mistake people make. Stalls: "Keep the URL secret." Moves up: restrict Cloud Run ingress to internal and allow only the gateway's service account as invoker, so a direct call returns 403.
12
3. "Are API keys authentication?" Probing: a security distinction. Stalls: "Yes." *Moves up:* no — they identify and meter a caller; authentication needs a JWT or ID token, and a key in a mobile app is not a secret.
13
4. "How is API Gateway configured?" Probing: the format. Stalls: "A policy language." *Moves up:* an OpenAPI document with x-google-backend, so routing, backend and auth live in one file.