Google Cloud
API Management — API Gateway & Apigee
Put a managed gateway in front of serverless backends, and know when the heavier product is justified.
GCP has two, at very different weights.
A reception desk in front of a locked floor. Visitors are checked and signed in, and the lift will not take anyone up who did not come past the desk.
Key Concepts
1
API Gateway lightweight, serverless, cheap. Fronts Cloud Run,
Functions and App Engine. Config is OpenAPI.
Apigee full API management platform: monetisation,
developer portal, analytics, policy engine.
Enterprise pricing.2
API Gateway is configured as an OpenAPI document.
paths:
/orders:
post:
x-google-backend:
address: https://orders-abc.run.app
security:
- firebase: []3
That single file defines routing, the backend and the auth requirement — there is no separate policy language.
4
Authentication options.
API keys identify the caller, meter usage. Not a secret.
Firebase / Auth0 / Okta JWT validated at the gateway
Google ID token service-to-service
service account the gateway calls the backend as itself5
The gateway should call a private backend. Deploy Cloud Run with ingress restricted to internal and the gateway's service account, so nobody can bypass the gateway by calling the Run URL directly. Forgetting this is the common mistake — the gateway enforces auth while the backend sits open.
6
Quotas and rate limits are declared per method and per consumer project, which is how you stop one client exhausting the backend.
7
Apigee is a different class of product. It adds a policy pipeline comparable to other clouds' gateways, a developer portal, API products and monetisation, deep analytics, and hybrid deployment. It is the right answer when APIs are the product and there are external paying consumers — and considerable overkill for internal service routing.
8
Choosing. Internal or simple public APIs over serverless backends: API Gateway. A public API programme with partners, plans and billing: Apigee.
9
Cloud Endpoints is the older ESP-based option, still seen in existing projects and largely superseded by API Gateway for new work.
10
What the interviewer is probing.1. "API Gateway or Apigee?" Probing: proportionality. Stalls: "Apigee, it is the full
product." Moves up: API Gateway for internal or simple public APIs over serverless backends;
Apigee when APIs are a product with external consumers, plans and monetisation.
11
2. "How do you stop callers bypassing the gateway?" Probing: the mistake people make.
Stalls: "Keep the URL secret." Moves up: restrict Cloud Run ingress to internal and allow only
the gateway's service account as invoker, so a direct call returns 403.
12
3. "Are API keys authentication?" Probing: a security distinction. Stalls: "Yes." *Moves
up:* no — they identify and meter a caller; authentication needs a JWT or ID token, and a key in a
mobile app is not a secret.
13
4. "How is API Gateway configured?" Probing: the format. Stalls: "A policy language." *Moves
up:* an OpenAPI document with x-google-backend, so routing, backend and auth live in one file.