Distributed SystemsGolangMulti-TenantSecurity

VantageEdge

Multi-Tenant API Gateway

Multi-tenant API gateway in Go that routes requests to tenant-registered origins by subdomain. Clerk JWT and scoped API-key auth, Redis-shared rate limiting and response caching, health-aware load balancing, and config pushed from a separate control plane over gRPC, instrumented with Prometheus and OpenTelemetry.

GogRPCPostgreSQLRedisOpenTelemetryDockerNext.jsTypeScript

// why this exists

Most gateway side projects stop at 'nginx reverse proxy with a database.' This one is multi-tenant from the ground up, and the gateway itself never touches Postgres on the request path. It holds a short-TTL config cache synced over gRPC from a separate control plane, so a compromised or misconfigured gateway replica can't read or write tenant data it doesn't need in the first place.

~70K req/s, +0.5ms p50 over a direct call

// numbers, not adjectives

Full request pipeline, one gateway, 64 connections, median of 3 runs

PathThroughputp50p99
Passthrough proxy~70K req/s0.8ms2.7ms
Response cache hit (Redis)~37K req/s1.7ms2.7ms
Rate limited (Redis token bucket)~16K req/s3.7ms7.3ms
Origin direct (baseline)~170K req/s0.3ms1.2ms

// how it's built

Routing & Load Balancing

  • Tenant subdomain to route to origin pool
  • Weighted, round robin, least connections or IP hash per route
  • Per-origin health checks at each origin's own interval

Auth, Limits & Cache

  • Clerk JWT + scoped API keys
  • Redis token bucket shared across gateway replicas
  • Per-route Redis response cache policies

Config & Observability

  • Gateway never reads Postgres on the request path
  • Config pushed over gRPC, live in ~2ms (p50)
  • Prometheus metrics, OpenTelemetry traces to Jaeger