Rate limiting, routing, transformation, and policy enforcement at the edge. Gateway architecture patterns for high-throughput, regulated financial services platforms.
A practical walkthrough of IBM API Connect and DataPower Gateway: components, request lifecycle, deployment via the apic CLI, OpenAPI assembly policies, OAuth and mTLS, HA topology, and the operational patterns that keep regulated financial APIs reliable at scale.
A production-grade walkthrough of Kong Gateway and Envoy Proxy for financial services: FAPI 2.0 and mTLS configuration, Redis-backed rate limiting, dark-launch migration patterns from commercial gateways, and the topology decisions that survive a SAMA security audit.
VPC private integrations, WAF rule tuning for ISO 20022 payloads, Lambda authoriser design for FAPI 2.0 and mTLS, usage plans for partner quotas, and the access-log pipeline that satisfies a SAMA security review.
Apollo Federation 2 subgraph SDL, Apollo Router configuration, Kong GraphQL rate-limiting, schema registry governance, persisted queries, and the incremental federation rollout pattern for a banking integration estate with multiple domain teams.
Sliding window Lua script on Redis, Kong rate-limiting-advanced with multi-window AIS config, IBM API Connect rate plans for PIS and AIS, adaptive limiting under load, and bypass prevention patterns for regulated open banking APIs.