Prev Next

API / Apollo Gateway Interview questions

How can you implement rate limiting at the Apollo Gateway or Router level?

The right approach differs a bit depending on whether you're running Router or the older Node.js Gateway.

Apollo Router supports request-level rate limiting directly in its configuration for GraphOS Enterprise plans, and can also be extended with a Rhai script or an external coprocessor that inspects each request's context and rejects/delays it based on custom logic (e.g., per-API-key limits).

# router.yaml (illustrative)
rhai:
  scripts: ./scripts
  main: rate_limit.rhai

It's also common, with either Gateway or Router, to put an edge proxy or API gateway (Envoy, Kong, or a cloud load balancer) in front that does token-bucket rate limiting before a request ever reaches the federation layer.

Apollo Gateway, being "just" an Apollo Server data source layer, typically relies on an upstream Express/Fastify rate-limiting middleware, or an Apollo Server plugin that checks request context against a limiter (like a Redis-backed token bucket) before letting the request proceed to the query planner.

Which of these is a common way to add custom rate-limiting logic directly inside Apollo Router?
For Apollo Gateway specifically, what is a typical way to add rate limiting, given it's built on Apollo Server?

More Related questions...

What is Apollo Gateway? What is GraphQL Federation? What is a subgraph in Apollo Federation? What is a supergraph in Apollo Federation? What is the difference between Apollo Server and Apollo Gateway? What is Apollo Federation 2? What are entities in Apollo Federation? What is the @key directive used for? What is schema composition in Apollo Federation? What is managed federation? What is Apollo Studio / GraphOS? What is Rover CLI used for? What is a query plan? What are the main directives used in Apollo Federation? What is the difference between Apollo Gateway and Apollo Router? Why do we use Apollo Federation instead of GraphQL schema stitching? How does Apollo Gateway compose a supergraph? How does the @external directive work? How does the @requires directive work? How does the @provides directive work? What is the difference between @shareable and @override? When should you use Apollo Router instead of Apollo Gateway? How do you configure Apollo Gateway with Apollo Server? What happens when a subgraph is unavailable at runtime? How does Apollo Gateway handle authentication and authorization? Why doesn't Apollo Gateway support GraphQL subscriptions as robustly as Apollo Router does? What is the difference between Federation 1 and Federation 2? How do you debug query planning issues in Apollo Gateway? What is the difference between IntrospectAndCompose and managed federation in Apollo Gateway? How can you optimize Apollo Gateway performance? Explain the lifecycle of a GraphQL request through Apollo Gateway? Explain the internal working of entity resolution using _entities and reference resolvers? What is the difference between a monolithic GraphQL server and a federated Apollo Gateway architecture? How does Apollo Gateway handle errors returned by subgraphs? What is the purpose of the _service and _entities fields in a federated subgraph schema? How do you implement custom middleware or plugins in Apollo Gateway? What are contract variants in GraphOS? How do you handle the N+1 query problem when a field spans multiple subgraphs? What is the difference between @override and @external for migrating fields? How does Apollo Gateway / Router handle caching? Explain the execution flow of a federated query spanning three subgraphs? Which is better and why: Apollo Router or Apollo Gateway, for a high-throughput production system? How do you secure inter-service communication between the gateway and subgraphs? What are Automatic Persisted Queries (APQ) and how do they work with Apollo Gateway? How do you handle versioning and backward compatibility of subgraph schemas? What is the difference between self-hosted Apollo Router and the GraphOS Router (cloud)? How do you troubleshoot composition errors when publishing a new subgraph schema? Explain the internal working of query plan caching? How can you implement rate limiting at the Apollo Gateway or Router level? What is the future direction of Apollo Gateway compared to Apollo Router?
Show more question and Answers...


Comments & Discussions