Development › Gateway
API Gateway
NestLaravel 1.0 update: proxy routes requireauth:sanctum, every call to a service is HMAC-signed (per-servicesecret), bearer tokens are not forwarded andforward_authdefaults tofalse. Services reject unsigned calls. See SECURITY.md and ARCHITECTURE.md.
apps/api is the platform API Gateway.
Portals and external clients talk only to the gateway. New microservices are not exposed publicly; they are registered behind the gateway and reached by proxy (sync) or Kafka (async).
Portals / mobile / partners
│
▼
apps/api (GATEWAY)
├── Auth / Users (local modules — identity stays here)
├── /api/v1/orders/** → orders-service (when enabled)
├── /api/v1/payments/** → payments-service (when enabled)
└── /api/v1/notifications/** → notifications-service
│
├── HTTP proxy (sync)
└── Kafka / Outbox (async events)#Responsibilities of the gateway
| Concern | Where |
|---|---|
| Public HTTP entry | apps/api only |
| Login / tokens / roles | Auth module (local) |
| Correlation / request IDs | Gateway middleware |
| Route to microservice | config/gateway.php + GatewayProxy |
| Business domain after extract | Downstream Laravel service |
#Local vs remote
- Start local — implement a module inside
apps/api(php artisan make:module Orders). - Extract later — move the module to
apps/orders-service(or a new repo). - Register in gateway — set
GATEWAY_ORDERS_ENABLED=trueandORDERS_SERVICE_URL=.... - Remove local routes for that prefix so the proxy owns
/api/v1/orders/*.
#Register a microservice
Edit apps/api/config/gateway.php (or env):
GATEWAY_ORDERS_ENABLED=true
ORDERS_SERVICE_URL=http://127.0.0.1:8001
# Docker DNS: http://orders-service:8000Public call:
GET /api/v1/orders/123
Authorization: Bearer {sanctum-token}Gateway forwards to:
GET http://orders-service:8000/api/v1/orders/123
Authorization: Bearer {same-token}
X-Correlation-ID: …
X-Request-ID: …
X-Forwarded-By: platform-api-gateway#Inspect registry
GET /api/gateway/servicesLists configured services and whether each proxy is enabled.
#Rules
- Portals never call microservice URLs directly.
- Auth stays on the gateway; services trust the forwarded Bearer token (or later mTLS / internal JWT).
- Prefer Kafka for fan-out; use gateway HTTP proxy only when the client needs a synchronous response.
- Do not chain gateway → A → B → C for one request.