# API gateway

Source: https://docs.quake.ai/resources/iac-templates/api-gateway
Markdown: https://docs.quake.ai/resources/iac-templates/api-gateway.md

---

# API gateway

This pattern composes Compute, Network, and Block Storage into a self-hosted API gateway on infrastructure you control.

## What this template does

Provisions a single instance running [Apache APISIX](https://apisix.apache.org), an open-source API gateway, that routes HTTP traffic on a floating IP to private backend services:

- Compute instance that runs APISIX and etcd in Docker, sized for gateway proxy traffic (2 vCPU and 4 GiB RAM by default)
- Private network, subnet, router, port, and security group; a floating IP on the gateway only
- A block volume mounted at `/data`, so APISIX config, etcd state, and logs live on a volume you can grow rather than on the boot disk
- cloud-init installs Docker, generates an admin API key on first boot, starts etcd bound to localhost, and seeds starter routes from `upstream_services`

The backend services stay on the private subnet with no floating IPs of their own. You add rate limits, key auth, and request shaping through the APISIX Admin API, then lock each backend security group to accept traffic only from the gateway security group.

No credential ships with this template. The instance generates the admin API key on first boot and writes it to `/root/gateway-admin-credentials` (readable only by root).

## Honest scope

This gateway runs in one region on a VM you operate. It is a regional API front door, not a global edge network: Quake AI has no anycast, no global PoPs, and no first-party managed API gateway. For geographic distribution and edge absorption, [front the origin with a third-party CDN](/docs/network/how-to/front-with-cdn).

## Alternate engines

This template leads with Apache APISIX (Apache-2.0, NGINX/LuaJIT + etcd, hot config reload, 100+ open plugins). [KrakenD](https://www.krakend.io) fits when you want a Go gateway with no database: stateless, declarative JSON config, the lightest option to operate. [Kong Gateway OSS](https://konghq.com/install) fits when you want the largest plugin ecosystem; it requires Postgres, which adds operational cost beyond the gateway VM. [Tyk OSS](https://tyk.io/docs/tyk-oss-api-gateway/) includes a dashboard and dev portal in the OSS edition. Swap the container stack in cloud-init if you prefer one of them.

## Parameters

| Parameter | Description | Default |
| --- | --- | --- |
| `key_name` | SSH keypair name (must already exist) | No default |
| `flavor_name` | Instance size (APISIX + etcd in 4 GiB) | `s1a.medium` |
| `image_name` | Operating system image | `Ubuntu-24.04` |
| `app_name` | Display name prefix for resources | `api-gateway` |
| `apisix_version` | APISIX container image tag | `3.11.0-debian` |
| `admin_port` | Admin API port (reach via SSH tunnel) | `9180` |
| `domain` | Public hostname for the gateway; empty serves HTTP on the floating IP | `""` |
| `upstream_services` | List of `{name, host, port, uri}` starter routes | `service-a` at `10.42.0.10`, `service-b` at `10.42.0.11` |
| `volume_size` | Block volume size in GiB, mounted at `/data` | `20` |
| `external_network` | External network for floating IP allocation | `PublicStatic` |
| `private_cidr` | CIDR for the private subnet | `10.42.0.0/24` |

## Ports and access

| Port | Purpose |
| --- | --- |
| 22 | Host SSH for administration |
| 80 | HTTP entry through the gateway data plane |
| 443 | HTTPS entry when TLS is configured on the gateway |
| 9180 | APISIX Admin API (not opened in the security group; use an SSH tunnel) |
| 2379 | etcd (localhost only; not in the security group) |

## When to use this pattern

Run your own API gateway on a VM you operate so client traffic hits one controlled endpoint with rate limits, key auth, and routing policy before it reaches private backend services. This is the developer-facing edge template in the edge and gateway family.

For model routing to LLM backends instead of your own services, see the sibling [inference gateway template](/resources/iac-templates/inference-gateway). For the TLS-only front door without gateway plugins, see the [edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy).

## Estimated cost

<PricingCompanion
  components={[
    { kind: "template", slug: "api-gateway", required: true },
  ]}
/>

## Template source

This is a [validated OpenTofu template](/docs/platform/validation#how-infrastructure-templates-are-checked).

<TemplateSource slug="api-gateway" />

<TemplateResourceMap template="api-gateway" format="opentofu" />

## Customize this pattern

- [Customize a template's image and flavor](/docs/automation/how-to/customize-template-image-flavor)
- [Add a block volume to a template](/docs/automation/how-to/add-volume-to-template)
- [Parameterize a template with a tfvars file](/docs/automation/how-to/parameterize-template-tfvars)

## See also

- [Deploy an API gateway with the api-gateway template](/resources/deployments/deploy-api-gateway-template)
- [Edge reverse proxy template](/resources/iac-templates/edge-reverse-proxy)
- [Edge WAF template](/resources/iac-templates/edge-waf)
- [Inference gateway template](/resources/iac-templates/inference-gateway)
- [Three-tier app template](/resources/iac-templates/three-tier-app)
