SlideShare a Scribd company logo
Unified Management
of Ingress and Egress
Across Multiple API
Gateways
Sanjeewa Malalgoda
Director, Engineering
WSO2
Arshardh Ifthikar
Technical Lead
WSO2
Agenda
3
● The Growing Complexity of API Ecosystems
● Complexities with Centralized and Federated API Management
● The Need for a Single Control Plane with Gateway Federation
● Demonstration 1: Behavior of the Unified API Control Plane (ACP) with
Multiple Gateways
● Ingress/Egress API Management
● Demonstration 2: AI Gateway principles and the functionality of AI/LLM
APIs
● Future Roadmap
● Key Takeaways & Next Steps
The Growing Complexity of API
Ecosystems
APIs are everywhere. As organizations scale, they deploy multiple API
gateways
● Different security requirements of different teams.
● For different cloud environments
● Now, even AI-specific gateways
● To comply with various protocols and platforms
But with this growth comes complexity: inconsistent policies, fragmented
security, and siloed observability. How can we bring order to this chaos?
That’s where unified ingress and egress management comes in.
7
Decentralized API Management
● Independent Control: Each team manages its own APIs and related assets.
● Team-Specific Policies: Security, access, and governance vary across teams.
● Distributed Traffic Routing: APIs use different gateways, portals, etc.
● Custom Infrastructure: Teams provision their own hosting, databases, and
networking.
● Flexible Processes: API design and standards differ based on team
preferences.
● Quick Deployments: New APIs and gateways can be added without central
approval.
8
Concerns with Decentralized API Management
Lack of Standardization – Inconsistent security, governance, and documentation across
teams.
Security Risks – Increased exposure to vulnerabilities without centralized control.
Compliance Challenges – Difficult to enforce regulatory and policy adherence.
Scalability Issues – Managing multiple APIs across different teams can create
inefficiencies.
Observability & Monitoring – Harder to track usage, errors, and performance metrics.
Versioning & Dependency Conflicts – Risk of breaking changes across interconnected
services.
Increased Operational Overhead – More effort required for coordination and
maintenance.
9
10
This is too much trouble. I
am going to Centralize all
my APIs to a single
platform!
Centralized API Management
● Single Control: One team manages all APIs from a central platform.
● Policy & Security: Rules, access, and security are set and enforced centrally.
● Traffic Routing: All API requests go through a main gateway.
● Infrastructure Setup: The central team provides hosting, databases, and
networking.
● Standardized Process: APIs follow common design and governance rules.
● Approval Needed: Adding new APIs or gateways requires central team
approval.
11
Concerns with Centralized API Management
Slow onboarding – New APIs, gateways, and policies take time to approve.
Limited team flexibility – Teams must wait for central decisions.
Generic solutions – One-size-fits-all approach may not suit all teams.
Single point of failure – Central issues can disrupt all APIs.
Innovation bottlenecks – Strict approvals slow experimentation.
Scalability issues – Central team struggles as APIs grow.
High operational overhead – Heavy workload on the central team.
Lack of team autonomy – Limited control over API development.
Slow adoption of new tech – Hard to integrate emerging API tools.
12
What if there was a
middle path ?
This is where the requirement for a
Unified API Control Plane comes in
13
The Need for a Central Control Plane
Challenges with API Sprawl:
● Organizations use multiple API gateways across different environments
(AWS, Kubernetes, Solace, etc.)
● Lack of a single control plane leads to inconsistency in policy enforcement,
security, and monitoring
Key Questions to Answer:
● How can we centrally manage different gateways?
● How do we ensure security, governance, and operational efficiency at scale
across multiple gateways?
Why Do We Need Central Control Plane?
15
A Single Control Plane for API Gateways
What is an API Control Plane (ACP)?
A centralized system to manage multiple API
gateways, gateway deployments and enforce
policies
16
Key Capabilities of ACP:
● Unified ingress and egress management
● Policy governance across all environments
● Observability and analytics
Capabilities Of API Control Plane
17
● Policy Management – Security, rate limits, authentication, governance.
● Multi-Gateway Support – Manage WSO2, AWS, Apigee, Kong etc.
● API Discovery – Centralized registry for all APIs.
● Observability – Monitoring, logging, tracing, analytics.
● Access Control – Multi-tenant RBAC for teams and users.
● Automation – CI/CD, policy enforcement, gateway provisioning.
● Hybrid & Multi-Cloud – Sync across on-prem, cloud, multi-cloud.
● Self-Service – Teams manage APIs within governance rules.
18
API Control Plane
WSO2 Immutable
Gateway
WSO2 Universal
Gateway
WSO2 Kubernetes
Gateway
K8s native design,
Lightweight, Envoy based
Offline mode,
Immutability, Edge
Gateway
Inbuilt mediation, Range of
protocols
Federated Gateways
AWS API Gateway
API Management Software
Gateway Federation
Gateway Federation and Multi-Gateway Management
The Challenge
● No centralized management, requiring
separate configurations and monitoring
● Inconsistent security policies across
multiple gateways
● Fragmented traffic control causing
inefficiencies
● Varied configurations and UI increasing
complexity
20
Gateway Federation and Multi-Gateway Management
How Gateway Federation Solves It
● Single control plane for centralized
management
● Unified security and policy enforcement
● Multi-gateway support across WSO2 and
third-party gateways
● Federated traffic management for routing
and security
● Standardized configuration and UI for
consistency
21
Gateway
AWS Gateway
How We Extend Gateway Support: Agent Framework
22
API Management Software
API Control Plane
WSO2
Immutable
Gateway
WSO2 Universal
Gateway
WSO2
Kubernetes
Gateway
K8s native design,
Lightweight, Envoy
based
Offline mode,
Immutability, Edge
Gateway
Inbuilt mediation,
Range of protocols
Federated
Gateway 01
AWS API Gateway
Agent
Federated
Gateway 03
Custom Gateway Agent
Custom Gateway
Federated
Gateway 02
Solace Gateway Agent
Demo 01
Behavior of the Unified API Control Plane (ACP) with
Multiple Gateways
23
The Scenario
Company: ForbizLogic, a fast-
growing enterprise with services
running across multiple clouds and
regions.
Challenge: They have different API
gateways across AWS, and on-prem
data centers. Managing policies,
security, and traffic is fragmented.
24
25
Eventing
APIs
Team
Financial
Services
Team
Other IT
Teams
Gateway AWS Gateway
WSO2 Universal
Gateway
WSO2
Kubernetes
Gateway Europe APAC
Requirement to use
Solace Broker to apply
QoS for eventing APIs
Services are in k8s. Looking
for k8s native gateway for
their APIs
Some cloud services are
running on AWS. Need a
GW closer to services
Need a wide variety of
protocols and mediation
capabilities, 2 regions
ForbizLogic
Unified Control Plane
Ingress/Egress API Management
What is an Ingress API?
Controls API traffic entering the
organization
Ensures security, authentication, and
access control
Why Organizations Need It?
Standardized API exposure
Secure and compliant access control
Securing API Traffic Coming In
27
Governing Outbound API Consumption
What is an Egress API?
Controls API traffic leaving the
organization
Enforces governance on external API
consumption
Why It’s Critical for Organizations?
Secure outbound API calls
Cost management and compliance
28
Use Cases:
AI APIs (Azure, OpenAI, Mistral)
Third-party CRM & messaging APIs
● Salesforce
● Twilio
● Slack
29
Ingress/Egress
API Invocation
Flow
Kubernetes
WSO2 AI Gateway governs, optimizes, and
secures Generative AI API usage with
flexible deployment and multi-provider
support for seamless AI integration.
● Token-based rate limiting
● AI-specific analytics
● Multi-provider support
● Adaptive request handling
● AI guardrails with request/response
mediation
30
Egress API Management: AI
Gateway
Demo 02
AI Gateway principles and the functionality of AI/LLM
APIs
31
The Scenario
Company: DeepCrestAI, a SaaS provider offering AI-powered document
processing and customer support.
Challenge: They rely on Azure OpenAI but face issues with:
● Overloaded models – GPT-4o deployment gets overwhelmed, leading to
higher latencies.
● Failover risk – If GPT-4o goes down, there's no fallback.
● Cost inefficiency – All requests go to GPT-4o, even when GPT-4o-mini
suffices for some cases.
● Rate limits – The app exceeds Azure’s request quotas. Certain applications
utilize more tokens than others.
● No Observability as to what is happening
● In case one Azure region fails, there is no backup to a different region
32
WSO2 Egress
AI
Gateway
Azure OpenAI
(Europe)
33
GPT 4o
Deployment
GPT 4o-mini
Deployment
Azure OpenAI
(US)
GPT 4o
Deployment
GPT 4o-mini
Deployment
AI-powered
Documentation
Processor Application
Backend
AI-powered Customer
Support Application
Backend
?
Unified Control
Plane
Future Roadmap
Future Roadmap
● Multi Vendor Routing Support for AI
Gateway
● Additional Egress API types will be added in
the future
● Additional Federated Types Support (eg:
Kong)
● In case there are changes in External
Gateways our Agents will be versioned to
bridge them.
35
Key Takeaways & Next Steps
● Unified API management simplifies operations – Centralizing ingress and
egress governance reduces complexity across multiple API gateways.
● Consistent security and policies – A unified control plane ensures uniform
enforcement of authentication, rate limiting, and compliance rules.
● Enhanced observability and analytics – Real-time monitoring across all API
gateways provides better insights for performance and security.
● Scalability & future-proofing – A unified approach makes it easier to integrate
new gateways, cloud services, and AI-based APIs.
Key Takeaways
37
Next Steps
● Evaluate your current API gateway landscape – Identify gaps in ingress
and egress management.
● Explore control plane solutions – Assess tools that can unify policies and
monitoring across multiple gateways.
● Start with a phased implementation – Test unification on a subset of
gateways before scaling up.
● Monitor & optimize – Continuously refine policies based on usage
patterns and performance data.
38
Upcoming API Management
Sessions
Upcoming API Management Sessions
40
● Conference Day 3 (Thursday, March 20th)
Question Time!
4
Thank you!
Ad

More Related Content

Similar to WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API Gateways (20)

Practical Data Mesh: Building Decentralized Data Architectures with Event Str...
Practical Data Mesh: Building Decentralized Data Architectures with Event Str...Practical Data Mesh: Building Decentralized Data Architectures with Event Str...
Practical Data Mesh: Building Decentralized Data Architectures with Event Str...
Harshana Martin
 
Practical Data Mesh: Building Decentralized Data Architectures with Event Stream
Practical Data Mesh: Building Decentralized Data Architectures with Event StreamPractical Data Mesh: Building Decentralized Data Architectures with Event Stream
Practical Data Mesh: Building Decentralized Data Architectures with Event Stream
Eva Mave Ng
 
Managing the Complexity of Microservices Deployments
Managing the Complexity of Microservices DeploymentsManaging the Complexity of Microservices Deployments
Managing the Complexity of Microservices Deployments
Apigee | Google Cloud
 
API Management within a Microservice Architecture
API Management within a Microservice ArchitectureAPI Management within a Microservice Architecture
API Management within a Microservice Architecture
WSO2
 
API Management Within a Microservices Architecture
API Management Within a Microservices Architecture API Management Within a Microservices Architecture
API Management Within a Microservices Architecture
Nadeesha Gamage
 
MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...
MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...
MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...
Jitendra Bafna
 
MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...
MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...
MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...
Jitendra Bafna
 
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Hamida Rebai Trabelsi
 
Extend soa with api management spoug- Madrid
Extend soa with api management   spoug- MadridExtend soa with api management   spoug- Madrid
Extend soa with api management spoug- Madrid
Vinay Kumar
 
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
API Gateway How-To: The Many Ways to Apply the Gateway PatternAPI Gateway How-To: The Many Ways to Apply the Gateway Pattern
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
VMware Tanzu
 
Madrid MuleSoft Meetup #11.pptx
Madrid MuleSoft Meetup #11.pptxMadrid MuleSoft Meetup #11.pptx
Madrid MuleSoft Meetup #11.pptx
jorgelebrato
 
Anypoint API Manager Custom Policies & Best Practices
Anypoint API Manager Custom Policies & Best PracticesAnypoint API Manager Custom Policies & Best Practices
Anypoint API Manager Custom Policies & Best Practices
MuleSoft Meetups
 
Anypoint new features_coimbatore_mule_meetup
Anypoint new features_coimbatore_mule_meetupAnypoint new features_coimbatore_mule_meetup
Anypoint new features_coimbatore_mule_meetup
MergeStack
 
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
WSO2
 
Microservices & anypoint service mesh calgary mule soft meetup
Microservices & anypoint service mesh   calgary mule soft meetupMicroservices & anypoint service mesh   calgary mule soft meetup
Microservices & anypoint service mesh calgary mule soft meetup
Jimmy Attia
 
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
WSO2- OSC Korea - Accelerating Digital Businesses with APIsWSO2- OSC Korea - Accelerating Digital Businesses with APIs
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
WSO2
 
MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...
MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...
MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...
Jitendra Bafna
 
API, Integration, and SOA Convergence
API, Integration, and SOA ConvergenceAPI, Integration, and SOA Convergence
API, Integration, and SOA Convergence
Kasun Indrasiri
 
Modernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIsModernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIs
Apigee | Google Cloud
 
apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...
apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...
apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...
apidays
 
Practical Data Mesh: Building Decentralized Data Architectures with Event Str...
Practical Data Mesh: Building Decentralized Data Architectures with Event Str...Practical Data Mesh: Building Decentralized Data Architectures with Event Str...
Practical Data Mesh: Building Decentralized Data Architectures with Event Str...
Harshana Martin
 
Practical Data Mesh: Building Decentralized Data Architectures with Event Stream
Practical Data Mesh: Building Decentralized Data Architectures with Event StreamPractical Data Mesh: Building Decentralized Data Architectures with Event Stream
Practical Data Mesh: Building Decentralized Data Architectures with Event Stream
Eva Mave Ng
 
Managing the Complexity of Microservices Deployments
Managing the Complexity of Microservices DeploymentsManaging the Complexity of Microservices Deployments
Managing the Complexity of Microservices Deployments
Apigee | Google Cloud
 
API Management within a Microservice Architecture
API Management within a Microservice ArchitectureAPI Management within a Microservice Architecture
API Management within a Microservice Architecture
WSO2
 
API Management Within a Microservices Architecture
API Management Within a Microservices Architecture API Management Within a Microservices Architecture
API Management Within a Microservices Architecture
Nadeesha Gamage
 
MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...
MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...
MuleSoft Surat Meetup#41 - Universal API Management, Anypoint Flex Gateway an...
Jitendra Bafna
 
MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...
MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...
MuleSoft Surat Virtual Meetup#16 - Anypoint Deployment Option, API and Operat...
Jitendra Bafna
 
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Azure Spring Clean 2024 event - Azure API Management: Architecting for Perfor...
Hamida Rebai Trabelsi
 
Extend soa with api management spoug- Madrid
Extend soa with api management   spoug- MadridExtend soa with api management   spoug- Madrid
Extend soa with api management spoug- Madrid
Vinay Kumar
 
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
API Gateway How-To: The Many Ways to Apply the Gateway PatternAPI Gateway How-To: The Many Ways to Apply the Gateway Pattern
API Gateway How-To: The Many Ways to Apply the Gateway Pattern
VMware Tanzu
 
Madrid MuleSoft Meetup #11.pptx
Madrid MuleSoft Meetup #11.pptxMadrid MuleSoft Meetup #11.pptx
Madrid MuleSoft Meetup #11.pptx
jorgelebrato
 
Anypoint API Manager Custom Policies & Best Practices
Anypoint API Manager Custom Policies & Best PracticesAnypoint API Manager Custom Policies & Best Practices
Anypoint API Manager Custom Policies & Best Practices
MuleSoft Meetups
 
Anypoint new features_coimbatore_mule_meetup
Anypoint new features_coimbatore_mule_meetupAnypoint new features_coimbatore_mule_meetup
Anypoint new features_coimbatore_mule_meetup
MergeStack
 
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
The Best of Both Worlds: Introducing WSO2 API Manager 4.0.0
WSO2
 
Microservices & anypoint service mesh calgary mule soft meetup
Microservices & anypoint service mesh   calgary mule soft meetupMicroservices & anypoint service mesh   calgary mule soft meetup
Microservices & anypoint service mesh calgary mule soft meetup
Jimmy Attia
 
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
WSO2- OSC Korea - Accelerating Digital Businesses with APIsWSO2- OSC Korea - Accelerating Digital Businesses with APIs
WSO2- OSC Korea - Accelerating Digital Businesses with APIs
WSO2
 
MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...
MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...
MuleSoft Surat Meetup#48 - Anypoint API Governance (RAML, OAS and Async API) ...
Jitendra Bafna
 
API, Integration, and SOA Convergence
API, Integration, and SOA ConvergenceAPI, Integration, and SOA Convergence
API, Integration, and SOA Convergence
Kasun Indrasiri
 
Modernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIsModernizing an Existing SOA-based Architecture with APIs
Modernizing an Existing SOA-based Architecture with APIs
Apigee | Google Cloud
 
apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...
apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...
apidays London 2023 - Overengineering Weakens your API Security, Dr. David Va...
apidays
 

More from WSO2 (20)

Platformless Modernization with Choreo.pdf
Platformless Modernization with Choreo.pdfPlatformless Modernization with Choreo.pdf
Platformless Modernization with Choreo.pdf
WSO2
 
Application Modernization with Choreo for the BFSI Sector
Application Modernization with Choreo for the BFSI SectorApplication Modernization with Choreo for the BFSI Sector
Application Modernization with Choreo for the BFSI Sector
WSO2
 
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
Choreo - The AI-Native Internal Developer Platform as a Service: OverviewChoreo - The AI-Native Internal Developer Platform as a Service: Overview
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
WSO2
 
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
WSO2
 
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2
 
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2
 
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - Building Secure Customer Experience AppsWSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2
 
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2
 
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2
 
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on CodeWSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2
 
WSO2Con 2025 - Architecting Cloud-Native Applications
WSO2Con 2025 - Architecting Cloud-Native ApplicationsWSO2Con 2025 - Architecting Cloud-Native Applications
WSO2Con 2025 - Architecting Cloud-Native Applications
WSO2
 
Mastering Intelligent Digital Experiences with Platformless Modernization
Mastering Intelligent Digital Experiences with Platformless ModernizationMastering Intelligent Digital Experiences with Platformless Modernization
Mastering Intelligent Digital Experiences with Platformless Modernization
WSO2
 
Accelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with PlatformlessAccelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with Platformless
WSO2
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2
 
architecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdfarchitecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdf
WSO2
 
Driving Innovation: Scania's API Revolution with WSO2
Driving Innovation: Scania's API Revolution with WSO2Driving Innovation: Scania's API Revolution with WSO2
Driving Innovation: Scania's API Revolution with WSO2
WSO2
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
WSO2
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
WSO2
 
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
WSO2
 
WSO2CON 2024 Slides - Unlocking Value with AI
WSO2CON 2024 Slides - Unlocking Value with AIWSO2CON 2024 Slides - Unlocking Value with AI
WSO2CON 2024 Slides - Unlocking Value with AI
WSO2
 
Platformless Modernization with Choreo.pdf
Platformless Modernization with Choreo.pdfPlatformless Modernization with Choreo.pdf
Platformless Modernization with Choreo.pdf
WSO2
 
Application Modernization with Choreo for the BFSI Sector
Application Modernization with Choreo for the BFSI SectorApplication Modernization with Choreo for the BFSI Sector
Application Modernization with Choreo for the BFSI Sector
WSO2
 
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
Choreo - The AI-Native Internal Developer Platform as a Service: OverviewChoreo - The AI-Native Internal Developer Platform as a Service: Overview
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
WSO2
 
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
WSO2
 
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2
 
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2
 
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - Building Secure Customer Experience AppsWSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2
 
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2
 
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2
 
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on CodeWSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2
 
WSO2Con 2025 - Architecting Cloud-Native Applications
WSO2Con 2025 - Architecting Cloud-Native ApplicationsWSO2Con 2025 - Architecting Cloud-Native Applications
WSO2Con 2025 - Architecting Cloud-Native Applications
WSO2
 
Mastering Intelligent Digital Experiences with Platformless Modernization
Mastering Intelligent Digital Experiences with Platformless ModernizationMastering Intelligent Digital Experiences with Platformless Modernization
Mastering Intelligent Digital Experiences with Platformless Modernization
WSO2
 
Accelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with PlatformlessAccelerate Enterprise Software Engineering with Platformless
Accelerate Enterprise Software Engineering with Platformless
WSO2
 
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital TransformationWSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
WSO2
 
architecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdfarchitecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdf
WSO2
 
Driving Innovation: Scania's API Revolution with WSO2
Driving Innovation: Scania's API Revolution with WSO2Driving Innovation: Scania's API Revolution with WSO2
Driving Innovation: Scania's API Revolution with WSO2
WSO2
 
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data PlatformLess Is More: Utilizing Ballerina to Architect a Cloud Data Platform
Less Is More: Utilizing Ballerina to Architect a Cloud Data Platform
WSO2
 
Modernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using BallerinaModernizing Legacy Systems Using Ballerina
Modernizing Legacy Systems Using Ballerina
WSO2
 
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
WSO2CON 2024 - Unlocking the Identity: Embracing CIAM 2.0 for a Competitive A...
WSO2
 
WSO2CON 2024 Slides - Unlocking Value with AI
WSO2CON 2024 Slides - Unlocking Value with AIWSO2CON 2024 Slides - Unlocking Value with AI
WSO2CON 2024 Slides - Unlocking Value with AI
WSO2
 
Ad

Recently uploaded (20)

Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.
hpbmnnxrvb
 
Rusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond SparkRusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond Spark
carlyakerly1
 
Big Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur MorganBig Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Impelsys Inc.
 
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager APIUiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPathCommunity
 
How analogue intelligence complements AI
How analogue intelligence complements AIHow analogue intelligence complements AI
How analogue intelligence complements AI
Paul Rowe
 
Procurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptxProcurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptx
Jon Hansen
 
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-UmgebungenHCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
panagenda
 
AI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global TrendsAI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global Trends
InData Labs
 
Role of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered ManufacturingRole of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered Manufacturing
Andrew Leo
 
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
BookNet Canada
 
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded DevelopersLinux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Toradex
 
AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...
AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...
AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...
SOFTTECHHUB
 
Build Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For DevsBuild Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For Devs
Brian McKeiver
 
Increasing Retail Store Efficiency How can Planograms Save Time and Money.pptx
Increasing Retail Store Efficiency How can Planograms Save Time and Money.pptxIncreasing Retail Store Efficiency How can Planograms Save Time and Money.pptx
Increasing Retail Store Efficiency How can Planograms Save Time and Money.pptx
Anoop Ashok
 
DevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptx
DevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptxDevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptx
DevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptx
Justin Reock
 
Electronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploitElectronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploit
niftliyevhuseyn
 
Into The Box Conference Keynote Day 1 (ITB2025)
Into The Box Conference Keynote Day 1 (ITB2025)Into The Box Conference Keynote Day 1 (ITB2025)
Into The Box Conference Keynote Day 1 (ITB2025)
Ortus Solutions, Corp
 
Cyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of securityCyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of security
riccardosl1
 
Drupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy ConsumptionDrupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy Consumption
Exove
 
Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.Greenhouse_Monitoring_Presentation.pptx.
Greenhouse_Monitoring_Presentation.pptx.
hpbmnnxrvb
 
Rusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond SparkRusty Waters: Elevating Lakehouses Beyond Spark
Rusty Waters: Elevating Lakehouses Beyond Spark
carlyakerly1
 
Big Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur MorganBig Data Analytics Quick Research Guide by Arthur Morgan
Big Data Analytics Quick Research Guide by Arthur Morgan
Arthur Morgan
 
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Enhancing ICU Intelligence: How Our Functional Testing Enabled a Healthcare I...
Impelsys Inc.
 
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager APIUiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPath Community Berlin: Orchestrator API, Swagger, and Test Manager API
UiPathCommunity
 
How analogue intelligence complements AI
How analogue intelligence complements AIHow analogue intelligence complements AI
How analogue intelligence complements AI
Paul Rowe
 
Procurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptxProcurement Insights Cost To Value Guide.pptx
Procurement Insights Cost To Value Guide.pptx
Jon Hansen
 
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-UmgebungenHCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
HCL Nomad Web – Best Practices und Verwaltung von Multiuser-Umgebungen
panagenda
 
AI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global TrendsAI and Data Privacy in 2025: Global Trends
AI and Data Privacy in 2025: Global Trends
InData Labs
 
Role of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered ManufacturingRole of Data Annotation Services in AI-Powered Manufacturing
Role of Data Annotation Services in AI-Powered Manufacturing
Andrew Leo
 
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
Transcript: #StandardsGoals for 2025: Standards & certification roundup - Tec...
BookNet Canada
 
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded DevelopersLinux Support for SMARC: How Toradex Empowers Embedded Developers
Linux Support for SMARC: How Toradex Empowers Embedded Developers
Toradex
 
AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...
AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...
AI EngineHost Review: Revolutionary USA Datacenter-Based Hosting with NVIDIA ...
SOFTTECHHUB
 
Build Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For DevsBuild Your Own Copilot & Agents For Devs
Build Your Own Copilot & Agents For Devs
Brian McKeiver
 
Increasing Retail Store Efficiency How can Planograms Save Time and Money.pptx
Increasing Retail Store Efficiency How can Planograms Save Time and Money.pptxIncreasing Retail Store Efficiency How can Planograms Save Time and Money.pptx
Increasing Retail Store Efficiency How can Planograms Save Time and Money.pptx
Anoop Ashok
 
DevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptx
DevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptxDevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptx
DevOpsDays Atlanta 2025 - Building 10x Development Organizations.pptx
Justin Reock
 
Electronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploitElectronic_Mail_Attacks-1-35.pdf by xploit
Electronic_Mail_Attacks-1-35.pdf by xploit
niftliyevhuseyn
 
Into The Box Conference Keynote Day 1 (ITB2025)
Into The Box Conference Keynote Day 1 (ITB2025)Into The Box Conference Keynote Day 1 (ITB2025)
Into The Box Conference Keynote Day 1 (ITB2025)
Ortus Solutions, Corp
 
Cyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of securityCyber Awareness overview for 2025 month of security
Cyber Awareness overview for 2025 month of security
riccardosl1
 
Drupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy ConsumptionDrupalcamp Finland – Measuring Front-end Energy Consumption
Drupalcamp Finland – Measuring Front-end Energy Consumption
Exove
 
Ad

WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API Gateways

  • 1. Unified Management of Ingress and Egress Across Multiple API Gateways
  • 3. Agenda 3 ● The Growing Complexity of API Ecosystems ● Complexities with Centralized and Federated API Management ● The Need for a Single Control Plane with Gateway Federation ● Demonstration 1: Behavior of the Unified API Control Plane (ACP) with Multiple Gateways ● Ingress/Egress API Management ● Demonstration 2: AI Gateway principles and the functionality of AI/LLM APIs ● Future Roadmap ● Key Takeaways & Next Steps
  • 4. The Growing Complexity of API Ecosystems
  • 5. APIs are everywhere. As organizations scale, they deploy multiple API gateways ● Different security requirements of different teams. ● For different cloud environments ● Now, even AI-specific gateways ● To comply with various protocols and platforms But with this growth comes complexity: inconsistent policies, fragmented security, and siloed observability. How can we bring order to this chaos? That’s where unified ingress and egress management comes in. 7
  • 6. Decentralized API Management ● Independent Control: Each team manages its own APIs and related assets. ● Team-Specific Policies: Security, access, and governance vary across teams. ● Distributed Traffic Routing: APIs use different gateways, portals, etc. ● Custom Infrastructure: Teams provision their own hosting, databases, and networking. ● Flexible Processes: API design and standards differ based on team preferences. ● Quick Deployments: New APIs and gateways can be added without central approval. 8
  • 7. Concerns with Decentralized API Management Lack of Standardization – Inconsistent security, governance, and documentation across teams. Security Risks – Increased exposure to vulnerabilities without centralized control. Compliance Challenges – Difficult to enforce regulatory and policy adherence. Scalability Issues – Managing multiple APIs across different teams can create inefficiencies. Observability & Monitoring – Harder to track usage, errors, and performance metrics. Versioning & Dependency Conflicts – Risk of breaking changes across interconnected services. Increased Operational Overhead – More effort required for coordination and maintenance. 9
  • 8. 10 This is too much trouble. I am going to Centralize all my APIs to a single platform!
  • 9. Centralized API Management ● Single Control: One team manages all APIs from a central platform. ● Policy & Security: Rules, access, and security are set and enforced centrally. ● Traffic Routing: All API requests go through a main gateway. ● Infrastructure Setup: The central team provides hosting, databases, and networking. ● Standardized Process: APIs follow common design and governance rules. ● Approval Needed: Adding new APIs or gateways requires central team approval. 11
  • 10. Concerns with Centralized API Management Slow onboarding – New APIs, gateways, and policies take time to approve. Limited team flexibility – Teams must wait for central decisions. Generic solutions – One-size-fits-all approach may not suit all teams. Single point of failure – Central issues can disrupt all APIs. Innovation bottlenecks – Strict approvals slow experimentation. Scalability issues – Central team struggles as APIs grow. High operational overhead – Heavy workload on the central team. Lack of team autonomy – Limited control over API development. Slow adoption of new tech – Hard to integrate emerging API tools. 12
  • 11. What if there was a middle path ? This is where the requirement for a Unified API Control Plane comes in 13
  • 12. The Need for a Central Control Plane
  • 13. Challenges with API Sprawl: ● Organizations use multiple API gateways across different environments (AWS, Kubernetes, Solace, etc.) ● Lack of a single control plane leads to inconsistency in policy enforcement, security, and monitoring Key Questions to Answer: ● How can we centrally manage different gateways? ● How do we ensure security, governance, and operational efficiency at scale across multiple gateways? Why Do We Need Central Control Plane? 15
  • 14. A Single Control Plane for API Gateways What is an API Control Plane (ACP)? A centralized system to manage multiple API gateways, gateway deployments and enforce policies 16 Key Capabilities of ACP: ● Unified ingress and egress management ● Policy governance across all environments ● Observability and analytics
  • 15. Capabilities Of API Control Plane 17 ● Policy Management – Security, rate limits, authentication, governance. ● Multi-Gateway Support – Manage WSO2, AWS, Apigee, Kong etc. ● API Discovery – Centralized registry for all APIs. ● Observability – Monitoring, logging, tracing, analytics. ● Access Control – Multi-tenant RBAC for teams and users. ● Automation – CI/CD, policy enforcement, gateway provisioning. ● Hybrid & Multi-Cloud – Sync across on-prem, cloud, multi-cloud. ● Self-Service – Teams manage APIs within governance rules.
  • 16. 18 API Control Plane WSO2 Immutable Gateway WSO2 Universal Gateway WSO2 Kubernetes Gateway K8s native design, Lightweight, Envoy based Offline mode, Immutability, Edge Gateway Inbuilt mediation, Range of protocols Federated Gateways AWS API Gateway API Management Software
  • 18. Gateway Federation and Multi-Gateway Management The Challenge ● No centralized management, requiring separate configurations and monitoring ● Inconsistent security policies across multiple gateways ● Fragmented traffic control causing inefficiencies ● Varied configurations and UI increasing complexity 20
  • 19. Gateway Federation and Multi-Gateway Management How Gateway Federation Solves It ● Single control plane for centralized management ● Unified security and policy enforcement ● Multi-gateway support across WSO2 and third-party gateways ● Federated traffic management for routing and security ● Standardized configuration and UI for consistency 21
  • 20. Gateway AWS Gateway How We Extend Gateway Support: Agent Framework 22 API Management Software API Control Plane WSO2 Immutable Gateway WSO2 Universal Gateway WSO2 Kubernetes Gateway K8s native design, Lightweight, Envoy based Offline mode, Immutability, Edge Gateway Inbuilt mediation, Range of protocols Federated Gateway 01 AWS API Gateway Agent Federated Gateway 03 Custom Gateway Agent Custom Gateway Federated Gateway 02 Solace Gateway Agent
  • 21. Demo 01 Behavior of the Unified API Control Plane (ACP) with Multiple Gateways 23
  • 22. The Scenario Company: ForbizLogic, a fast- growing enterprise with services running across multiple clouds and regions. Challenge: They have different API gateways across AWS, and on-prem data centers. Managing policies, security, and traffic is fragmented. 24
  • 23. 25 Eventing APIs Team Financial Services Team Other IT Teams Gateway AWS Gateway WSO2 Universal Gateway WSO2 Kubernetes Gateway Europe APAC Requirement to use Solace Broker to apply QoS for eventing APIs Services are in k8s. Looking for k8s native gateway for their APIs Some cloud services are running on AWS. Need a GW closer to services Need a wide variety of protocols and mediation capabilities, 2 regions ForbizLogic Unified Control Plane
  • 25. What is an Ingress API? Controls API traffic entering the organization Ensures security, authentication, and access control Why Organizations Need It? Standardized API exposure Secure and compliant access control Securing API Traffic Coming In 27
  • 26. Governing Outbound API Consumption What is an Egress API? Controls API traffic leaving the organization Enforces governance on external API consumption Why It’s Critical for Organizations? Secure outbound API calls Cost management and compliance 28 Use Cases: AI APIs (Azure, OpenAI, Mistral) Third-party CRM & messaging APIs ● Salesforce ● Twilio ● Slack
  • 28. WSO2 AI Gateway governs, optimizes, and secures Generative AI API usage with flexible deployment and multi-provider support for seamless AI integration. ● Token-based rate limiting ● AI-specific analytics ● Multi-provider support ● Adaptive request handling ● AI guardrails with request/response mediation 30 Egress API Management: AI Gateway
  • 29. Demo 02 AI Gateway principles and the functionality of AI/LLM APIs 31
  • 30. The Scenario Company: DeepCrestAI, a SaaS provider offering AI-powered document processing and customer support. Challenge: They rely on Azure OpenAI but face issues with: ● Overloaded models – GPT-4o deployment gets overwhelmed, leading to higher latencies. ● Failover risk – If GPT-4o goes down, there's no fallback. ● Cost inefficiency – All requests go to GPT-4o, even when GPT-4o-mini suffices for some cases. ● Rate limits – The app exceeds Azure’s request quotas. Certain applications utilize more tokens than others. ● No Observability as to what is happening ● In case one Azure region fails, there is no backup to a different region 32
  • 31. WSO2 Egress AI Gateway Azure OpenAI (Europe) 33 GPT 4o Deployment GPT 4o-mini Deployment Azure OpenAI (US) GPT 4o Deployment GPT 4o-mini Deployment AI-powered Documentation Processor Application Backend AI-powered Customer Support Application Backend ? Unified Control Plane
  • 33. Future Roadmap ● Multi Vendor Routing Support for AI Gateway ● Additional Egress API types will be added in the future ● Additional Federated Types Support (eg: Kong) ● In case there are changes in External Gateways our Agents will be versioned to bridge them. 35
  • 34. Key Takeaways & Next Steps
  • 35. ● Unified API management simplifies operations – Centralizing ingress and egress governance reduces complexity across multiple API gateways. ● Consistent security and policies – A unified control plane ensures uniform enforcement of authentication, rate limiting, and compliance rules. ● Enhanced observability and analytics – Real-time monitoring across all API gateways provides better insights for performance and security. ● Scalability & future-proofing – A unified approach makes it easier to integrate new gateways, cloud services, and AI-based APIs. Key Takeaways 37
  • 36. Next Steps ● Evaluate your current API gateway landscape – Identify gaps in ingress and egress management. ● Explore control plane solutions – Assess tools that can unify policies and monitoring across multiple gateways. ● Start with a phased implementation – Test unification on a subset of gateways before scaling up. ● Monitor & optimize – Continuously refine policies based on usage patterns and performance data. 38
  • 38. Upcoming API Management Sessions 40 ● Conference Day 3 (Thursday, March 20th)

Editor's Notes

  • #4: We’ll focus on WSO2 API Manager as our platform of choice to demonstrate AI’s role in API management. From design to governance, we will leverage AI capabilities within WSO2 to improve efficiency and security.
  • #23: https://docs.google.com/document/d/19CIyKazeFywngxdCVjP53j6QIHx9aaasvBelb_u40wg/edit?usp=sharing
  • #28: Egress apis existed even before, but now with AI and Messaging it’s importance is felt significantly.
  • #31: https://docs.google.com/document/d/19CIyKazeFywngxdCVjP53j6QIHx9aaasvBelb_u40wg/edit?usp=sharing
  • #32: Keys can be hidden from teams
  • #34: We’ve explored how AI-driven capabilities enhance API management across various stages, from design and testing to governance and branding. WSO2 API Manager integrates AI to automate repetitive tasks, improve security, and optimize API performance. Now, it's time to apply these learnings! Explore WSO2’s AI-powered features in your own API projects, experiment with branding automation, governance enforcement, and AI-driven documentation, and continue innovating in the API space. Thank you for joining this session! Any questions?
  • #36: We’ve explored how AI-driven capabilities enhance API management across various stages, from design and testing to governance and branding. WSO2 API Manager integrates AI to automate repetitive tasks, improve security, and optimize API performance. Now, it's time to apply these learnings! Explore WSO2’s AI-powered features in your own API projects, experiment with branding automation, governance enforcement, and AI-driven documentation, and continue innovating in the API space. Thank you for joining this session! Any questions?