INFRASTRUCTURE

API Gateway: On Contracts, Doors and Dangers of the Outside

📅 Tuesday, September 22, 2026 🕐 10:25 AM - 10:55 AM (Buenos Aires, GMT-3) 📍 Stream rojo 💻 Online 🌐 In English
API Gateway: On Contracts, Doors and Dangers of the Outside
Over the last several years Vinted was actively working on breaking up its majestic Ruby on Rails monolith. This process resulted in a number of new, smaller-scale services, though no less majestic, introduced into Vinted’s internal infrastructure.

This came with its own challenges. Up until a year ago, most traffic that was reaching Vinted’s backend was admitted through the (true to its name) monolith, which provided authentication, authorization and routing functionality for the freshly extracted services. This, of course, couldn't last.

To address these challenges, we introduced a new infrastructure component - an API Gateway. As Vinted is striving for internal consistency and a high bar of quality for the new services, all of these expose their API through an OpenAPI contract.

This talk covers how we handle routing and security with API Gateway using Istio service mesh primitives, Gateway API (not confusing at all) and OPA to provide a level of security comparable to our dear old monolith.

Want to see the talk by Vlad Tomashpolskyi? Registration is free.

Register for free
infrastructure
This talk is presented by Vinted
Register for free