API Gateway & Ingress (Apache APISIX)
Okustera API Gateway and Ingress is powered by Apache APISIX, providing ultra-low latency, dynamic traffic routing, automated SSL/TLS termination, Web Application Firewall (WAF) threat inspection, rate limiting, and canary traffic shifting.
APISIX operates directly at the edge of the Okustera tenant Kubernetes cluster, dynamically synchronizing routing rules via ApisixRoute CRDs and the official Terraform provider.

Key Capabilities
- Dynamic Ingress Routing: Zero-reload rule updates without dropping existing TCP sockets or in-flight requests.
- Automated SSL/TLS Termination: Automatic certificate lifecycle management through
cert-manager(Let's Encrypt or private CA ClusterIssuers) paired withApisixTls, enforcing HTTP-to-HTTPS (308 Permanent Redirect) and HSTS. - Web Application Firewall (WAF): Deep packet inspection powered by ModSecurity and OWASP Core Rule Set (CRS 3.3+) mitigating SQL Injection (SQLi), Cross-Site Scripting (XSS), and malicious payloads with
DetectionOnlyandBlockingmodes. - Canary & Blue/Green Deployments: Weight-based traffic splitting, HTTP header matching (
X-Canary: true), and cookie-based sticky sessions. - Enterprise Security & Governance: Granular token-bucket rate limiting, IP restriction, CORS management, forward authentication, and Prometheus metrics telemetry.
Web Application Firewall (WAF) & Threat Inspection
Okustera incorporates OWASP ModSecurity Core Rule Set protection at both the public edge controller and APISIX ingress gateway layers:
- DetectionOnly Mode: Inspects incoming HTTP request URIs, query strings, headers, and request bodies against OWASP CRS attack signatures. Violations are recorded to the central audit log without interrupting traffic, allowing safe tuning and baseline traffic profiling.
- Blocking Mode: Actively defends endpoints by immediately terminating matched attack vectors with an
HTTP 403 Forbiddenresponse and an attack correlation ID.
Automated SSL/TLS & Ingress Routing
When TLS is enabled on a route:
- The control plane requests an X.509 certificate from the specified
ClusterIssuer(e.g.,letsencrypt-prodor internal staging CA). - The issued certificate is synchronized into a Kubernetes TLS secret.
- An
ApisixTlsresource binds the certificate to the domain's SNI, while edge ingress enforces TLS 1.2/1.3 and HSTS (max-age=31536000).
Canary Traffic Splitting
The APISIX traffic-split plugin allows gradual releases of new application versions to mitigate operational risk:
apiVersion: apisix.apache.org/v2
kind: ApisixRoute
metadata:
name: order-service-route
namespace: default
spec:
http:
- name: canary-traffic
match:
hosts:
- api.okustera.com
paths:
- /orders*
backends:
- serviceName: order-service-stable
servicePort: 8080
weight: 90
- serviceName: order-service-canary
servicePort: 8080
weight: 10
plugins:
- name: limit-count
enable: true
config:
count: 1000
time_window: 60
rejected_code: 429
key: remote_addr
AI Gateway & LLM Streaming Extensions (Phase 8 Alignment)
The Apache APISIX gateway is extended in Phase 8: AI Inference PaaS to serve as a high-throughput AI Gateway:
- Unbuffered Streaming SSE: Configures
proxy_buffering: "off"and extended client read timeouts (600s) to stream token deltas in real time with sub-50ms Time-to-First-Token (TTFT). - Intelligent Model Payload Routing: Inspects incoming JSON request bodies (
"model": "...") and routes requests dynamically across autoscaled vLLMRayServiceinstances and embedding endpoints. - Fast Admission & Guardrail Routing (Kev-0.8B): Synchronously queries the Kev admission router in under 15ms, dropping prompt injections immediately (
HTTP 403 Forbidden) and tagging request headers withX-AI-Route(iac_devops,deep_reasoning,openstack_api). - Semantic Prompt Caching: Integrates with Valkey DBaaS (
omc-valkey) to return identical or semantically equivalent prompt completions in under 5ms with zero GPU overhead. - Token-Level FinOps: Automatically extracts
usage.prompt_tokensandusage.completion_tokensfrom response bodies and streams billing records to FinOps, Metering & Billing.
apiVersion: apisix.apache.org/v2
kind: ApisixRoute
metadata:
name: ai-inference-route
namespace: default
spec:
http:
- name: ai-chat-stream
match:
hosts:
- ai.okustera.com
paths:
- /v1/chat/completions
backends:
- serviceName: vllm-llama-70b-head-svc
servicePort: 8000
plugins:
- name: proxy-rewrite
enable: true
config:
headers:
set:
X-Accel-Buffering: "no"
- name: key-auth
enable: true
- name: limit-count
enable: true
config:
count: 600
time_window: 60
rejected_code: 429
key: consumer_name
Multi-Tenant Ingress Architecture & Tenant Gateways
In Okustera, API Gateway routing enforces strict multi-tenant boundary isolation between the central cloud control plane and individual tenant environments:
Multi-Tenant Scoping Rules
- Strict Project Scoping: Every route declared in the portal or via Terraform is explicitly tagged with
project_id. - Zero Leakage: Admin users logged into the platform portal only view platform control-plane routes by default, while tenant users strictly view their own isolated ingress routes.
- Dual-Layer Edge Protection: Edge Ingress terminates public TLS and applies OWASP CRS inspection before proxying traffic directly into the tenant's dedicated APISIX cluster.
Declarative Management via Terraform
The official Okustera Terraform provider manages APISIX ingress routes, automated TLS certificates, and WAF inspection rules directly in IaC:
resource "okustera_apisix_route" "api_endpoint" {
name = "public-customer-api"
domain = "api.okustera.com"
path = "/api/v1/*"
upstream = {
service_name = "customer-service"
port = 8080
timeout = 15
}
# Automated SSL/TLS with cert-manager
tls_enabled = true
cluster_issuer = "letsencrypt-prod"
# OWASP Core Rule Set WAF Protection
waf_enabled = true
waf_mode = "DetectionOnly" # Or "Blocking" for enforcement
# Rate Limiting & CORS
rate_limit = {
requests_per_minute = 300
burst = 50
}
cors_enabled = true
}
Learn more in the Terraform Resource Reference.