Measuring and enforcing API usage in a multi-tenant computing environment
In some implementations, the techniques described herein relate to a method including: receiving, at an API gateway, an API request from an API client; extracting, by the API gateway, a client identity associated with the API request; checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity; determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.
1 . A method comprising:
receiving, at an API gateway, an API request from an API client;
extracting, by the API gateway, a client identity associated with the API request;
checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity;
determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and
applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.
2 . The method of claim 1 , extracting the client identity further comprising obtaining identity information from one or more of an authentication token, an API key, or a client certificate associated with the API request.
3 . The method of claim 1 , checking the ALOs further comprising retrieving, by the API gateway, the ALOs for the client from a distributed cache; and using the retrieved ALOs to evaluate the usage limits for the client.
4 . The method of claim 1 , determining that the API request falls outside the acceptable usage limits further comprising comparing current usage metrics of the client against thresholds specified in the ALOs.
5 . The method of claim 1 , processing the API request further comprising forwarding the API request to an appropriate backend service based on an API endpoint and routing rules defined in the API gateway.
6 . The method of claim 1 , applying the ALA action further comprising one or more of: throttling the API request to limit a rate of requests from the client to a predefined threshold, rejecting the API request and returning an error response indicating a reason for rejection, triggering an alert including a policy violation, or blocking the client from submitting future API requests.
7 . The method of claim 1 , further comprising: updating API Level Indicator (ALI) metrics associated with the client, the ALI metrics representing one or more of actual usage metrics including a number of requests made, a total response bandwidth, a number of errors encountered, and a latency of the requests; and storing the ALI metrics in a distributed cache for monitoring and analyzing API usage.
8 . A non-transitory computer-readable storage medium for tangibly storing computer program instructions capable of being executed by a computer processor, the computer program instructions defining steps of:
receiving, at an API gateway, an API request from an API client;
extracting, by the API gateway, a client identity associated with the API request;
checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity;
determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and
applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.
9 . The non-transitory computer-readable storage medium of claim 8 , extracting the client identity further comprising obtaining identity information from one or more of an authentication token, an API key, or a client certificate associated with the API request.
10 . The non-transitory computer-readable storage medium of claim 8 , checking the ALOs further comprising retrieving, by the API gateway, the ALOs for the client from a distributed cache; and using the retrieved ALOs to evaluate the usage limits for the client.
11 . The non-transitory computer-readable storage medium of claim 8 , determining that the API request falls outside the acceptable usage limits further comprising comparing current usage metrics of the client against thresholds specified in the ALOs.
12 . The non-transitory computer-readable storage medium of claim 8 , processing the API request further comprising forwarding the API request to an appropriate backend service based on an API endpoint and routing rules defined in the API gateway.
13 . The non-transitory computer-readable storage medium of claim 8 , applying the ALA action further comprising one or more of: throttling the API request to limit a rate of requests from the client to a predefined threshold, rejecting the API request and returning an error response indicating a reason for rejection, triggering an alert including a policy violation, or blocking the client from submitting future API requests.
14 . The non-transitory computer-readable storage medium of claim 8 , the steps further comprising: updating API Level Indicator (ALI) metrics associated with the client, the ALI metrics representing one or more of actual usage metrics including a number of requests made, a total response bandwidth, a number of errors encountered, and a latency of the requests; and storing the ALI metrics in a distributed cache for monitoring and analyzing API usage.
15 . A device comprising:
a processor; and
a non-transitory computer-readable medium storing program instructions that, when executed by the processor, cause the processor to perform steps of:
receiving, at an API gateway, an API request from an API client;
extracting, by the API gateway, a client identity associated with the API request;
checking, by the API gateway, API Level Objectives (ALOs) associated with the client identity, the ALOs defining acceptable usage limits for the client identity;
determining, by the API gateway, that the API request falls outside the acceptable usage limits defined by the ALOs; and
applying, by the API gateway, an API Level Agreement (ALA) action, the ALA action specifying an action to be taken when an ALO is breached.
16 . The device of claim 15 , extracting the client identity further comprising obtaining identity information from one or more of an authentication token, an API key, or a client certificate associated with the API request.
17 . The device of claim 15 , checking the ALOs further comprising retrieving, by the API gateway, the ALOs for the client from a distributed cache; and using the retrieved ALOs to evaluate the usage limits for the client.
18 . The device of claim 15 , determining that the API request falls outside the acceptable usage limits further comprising comparing current usage metrics of the client against thresholds specified in the ALOs.
19 . The device of claim 15 , processing the API request further comprising forwarding the API request to an appropriate backend service based on an API endpoint and routing rules defined in the API gateway.
20 . The device of claim 15 , applying the ALA action further comprising one or more of: throttling the API request to limit a rate of requests from the client to a predefined threshold, rejecting the API request and returning an error response indicating a reason for rejection, triggering an alert including a policy violation, or blocking the client from submitting future API requests.