What is an API gateway and what does it do?
Assesses fundamental understanding of Microservices conventions, runtime behavior, and memory/performance considerations.
Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.
An API gateway is the single entry point for clients, sitting in front of backend services. It typically handles:
- Request routing to the correct service.
- Authentication and authorization, terminating TLS and validating tokens.
- Rate limiting, quotas and basic request validation.
- Response aggregation or transformation, sometimes exposing a Backend for Frontend tailored to a client.
- Observability: access logs, metrics, tracing headers, correlation ids.
routes:
- path: /orders/**
uri: lb://order-service
filters: [TokenRelay, RateLimit]
Benefits are a smaller client surface and consistent cross-cutting concerns. Risks are a single point of failure, a potential bottleneck and a temptation to accumulate business logic. Keep it thin, make it highly available, and avoid coupling it to service internals. Service meshes move some of these concerns to sidecars, but the gateway usually remains the public edge.
Candidate Response Strategy & Interview Tips
- Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
- Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
- Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
- Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.