Skip to main content
Version: 2.0.0

ADR 014: Select API-Management Solution

Date: 2025-09-18 Status: Accepted

Decision Makers: @DerLinne @luckey @cr0ssing

Context​

We need a central API-Management, which is powerful to fulfill all requirements and is open-source. In civitas v1, Apache APISIXApache APISIXAn open-source API gateway for traffic management, security and observability. In CIVITAS/CORE it is used as the centralized entrypoint to route and protect externally exposed APIs. was used for this. Although APISIXsApache APISIXAn open-source API gateway for traffic management, security and observability. In CIVITAS/CORE it is used as the centralized entrypoint to route and protect externally exposed APIs. documentation is not always completely intuitive, the solution is very powerful and versatile.

Checked Architecture Principles​

  • [full] Model-centric data flow – Configurable-as-code via API or CRDs (not preferred)
  • [full] Distributed architecture with unified user experience
  • [full] Modular design - very good integratable with other components of the platform like: KeycloakKeycloakAn open-source Identity and Access Management (IAM) solution providing SSO and OAuth2/OpenID Connect flows. In CIVITAS/CORE it is used to authenticate users and issue JWTs., prometheus, loki, …
  • [full] Integration capability through defined interfaces
  • [full] Open source as the default – Fully open source managed by Apache Foundation.
  • [full] Cloud-native architecture – Official containers, Kubernetes-ready, supports HA and horizontal scaling.
  • [full] Prefer standard solutions over custom development
  • [full] Self-contained deployment
  • [full] Technological consistency to ensure maintainability
  • [full] Multi-tenancy – Realms enable strong tenantTenantAn isolated organizational partition that owns Data pools, Datasets, Users, Groups, and Roles. All access rules exist within their Tenant, and the Tenant is the widest Scope of a Role. Currently, one Tenant corresponds to the Platform. isolation
  • [full] Security by design

Decision​

APISIXApache APISIXAn open-source API gateway for traffic management, security and observability. In CIVITAS/CORE it is used as the centralized entrypoint to route and protect externally exposed APIs. should be used as API-Management. It worked very well in v1, is well maintained, and still satisfies all our required features. It is fully manageable at runtime via API and therefore very well integratable.

Consequences​

All external interfaces are routed over APISIXApache APISIXAn open-source API gateway for traffic management, security and observability. In CIVITAS/CORE it is used as the centralized entrypoint to route and protect externally exposed APIs.. External UI Components without own OIDC Integration, should use the same way.

Alternatives​

  • Kong: Also powerful, but a bit more commercial character

See also​