4 ms·
What is the advantage of using this compared to plain Nginx or Envoy? Is it just static vs. dynamic config for routing?
by splix 4y ago
What is the advantage of using this compared to plain Nginx or Envoy? Is it just static vs. dynamic config for routing?
- moonming 4y agoIn addition to dynamic, Apache APISIX has the advantage of developing plugins in Java, Go, Python, Wasm. While Nginx uses C, Envoy uses C++ and Wasm.
- chenjunxu 4y agoYou can use APISIX API Gateway as a traffic entrance to process all business data, including dynamic routing, dynamic upstream, dynamic certificates, A/B testing, canary release, blue-green deployment, limit rate, defense against malicious attacks, metrics, monitoring alarms, service observability, service governance, etc.
- chao-zhang 4y agoApache APISIX also has several security features to help reinforce API security. For instance: 1. It can dynamically manage lots of TLS certificates and do the TLS/SSL terminate or use mTLS to communicate with the upstream; 2. Plugins like ACL, IP Restriction, CSRF, and Referrer Restriction restrict API access in different dimensions.
- adamckay 4y agoIs it possible to perform mTLS from client->APISIX gateway and pass on the verified certificate details to the upstream (e.g. via headers)? Or is mTLS only possible with client->pass through APISIX->upstream? It's not quite clear from the docs.
- chao-zhang 4y agoIt's feasible while you have to write a bit of code to assemble the certificate details to the API request (e.g., request headers, or query string). mTLS is both possible for client -> APISIX and APISIX -> upstream.
- bzp2010 4y agoAs a complement to the first reply, I created a simple DEMO that will implement your needs and I placed it on the GitHub gist [1]. [1] https://gist.github.com/bzp2010/6ce0bf7c15c191029ed54724547195b4 https://gist.github.com/bzp2010/6ce0bf7c15c191029ed547245471...