An API Gateway built from scratch in Go — no framework, just net/http, MySQL, and Redis.
| 🧭 Dynamic Routing | Matches requests to backend services by path & method, wildcards included |
| 🔐 JWT Authentication | Login issues a token; protected routes enforce role-based access |
| ⚖️ Weighted Load Balancing | Smooth weighted round-robin across multiple backend instances |
| 💓 Live Health Checks | Background scheduler pulls unhealthy targets out of rotation automatically |
| ⚡ Redis Caching | Per-route response caching with configurable TTL |
| 🛑 Rate Limiting | Token-bucket limiting per client, configurable per route |
| 🌐 CORS Handling | Configurable allowed origins, methods, headers |
| 🔄 Hot-Reloadable Config | Routing rules update live from YAML — zero restarts |
| 🗄️ MySQL User Store | Real login flow, bcrypt-hashed passwords |
flowchart TD
A["🌍 Incoming Request"] --> B["🌐 CORS Middleware"]
B --> C["📝 Logger Middleware"]
C --> D["🔐 JWT Auth Middleware"]
D --> E["🛑 Rate Limiter"]
E --> F{"⚡ Cached in Redis?"}
F -- "Yes" --> G["✅ Return Cached Response"]
F -- "No" --> H["⚖️ Weighted Round-Robin"]
H --> I{"💓 Target Healthy?"}
I -- "No" --> H
I -- "Yes" --> J["➡️ Reverse Proxy to Backend"]
J --> K["💾 Cache Response (if enabled)"]
K --> L["📤 Response to Client"]
flowchart LR
subgraph Client
U["Client / Browser"]
end
subgraph Gateway["⚡ GoGateway"]
R["Router"]
MW["Middleware Stack<br/>CORS · Auth · Rate Limit · Logging"]
LB["Load Balancer<br/>Weighted Round-Robin"]
HC["Health Checker<br/>Cron Scheduler"]
end
subgraph Data["Data Layer"]
DB[("🗄️ MySQL<br/>Users")]
RD[("⚡ Redis<br/>Cache")]
end
subgraph Backends["Backend Services"]
S1["Service A"]
S2["Service B"]
S3["Service C"]
end
U --> R --> MW --> LB
LB --> S1
LB --> S2
LB --> S3
HC -.monitors.-> S1
HC -.monitors.-> S2
HC -.monitors.-> S3
MW <--> DB
MW <--> RD