Skip to content

API Gateway ​

Route, secure and rate-limit traffic to your servers, apps and databases at the edge — with custom domains, automatic TLS and a built-in WAF — without running your own reverse proxy.

Creating a gateway ​

  1. Open API Gateway → Create.
  2. Choose a plan — plans are sized by throughput (max requests/sec) rather than raw compute.
  3. Pick shared (a slot on the platform's multi-tenant edge, fastest to provision) or dedicated (your own gateway instance with its own public IPv4/IPv6, for workloads that need isolation or a static IP).
  4. Optionally attach the gateway to a private network so it can reach backend resources (servers, databases, apps) over your tenant overlay instead of the public internet.

Routes ​

Add routes from the gateway's Routes tab:

  • Domain — a custom domain (optional; a gateway also serves on its raw IP) or subdomain. Verification is optional — an unverified domain still routes, with a warning.
  • Path — the URL path to match.
  • Upstream — pick a server, app or database from a resource picker, or enter a raw host:port. Routing to a private upstream requires the gateway to be attached to that resource's network.

TLS certificates for verified custom domains are issued and renewed automatically.

WAF and rate limiting ​

Every route can be configured with:

  • Rate limiting — cap requests per second per client.
  • WAF rules — block common attack patterns (SQL injection, path traversal, scanner signatures) before they reach your backend.
  • Custom headers, timeouts and caching, configured per route.

Managing in place ​

Gateway configuration changes are applied live from the console — there's no separate admin subdomain or SSH access needed. A YAML editor is available for advanced configuration alongside the guided UI.

See also ​