Split-plane architecture
Management, machine-facing services, and the request path have separate jobs and separate connections.
Security
Each plane gets only the access it needs. Consumer traffic never reaches the management plane. Gateway pods hold no database connection. Every deployment is validated first.
Security posture
Start with topology. Then add identity, authorization, validation, signed content, audit, and runtime policy.
Management, machine-facing services, and the request path have separate jobs and separate connections.
Published bundles cannot be edited. An environment picks a revision, and that choice is recorded.
Gateway pods get compiled config only. No database credentials, no authoring workspace.
Platform controls
Runtime identity
The gateway backend owns the consumer registry and token services. Gateways cache what they resolve, within set bounds, and fail closed when a security-sensitive lookup misses.
Verify credentials and tokens before a request reaches a route.
Signed requests and client certificates for machine-to-machine calls.
IP rules, request size, request validation, bot detection, and threat protection.