A short course on API gateways
Envoy, Kong and OpenResty side by side
All three do the same two jobs: choose a route for each request, then assemble the path sent upstream. This course hands all three the same configuration, sends the same paths through, and records where the answers differ. It does not argue that one is better — it measures what changes when you move from one to another.
/b$: Envoy matches only /b, Kong the same, but
OpenResty also matches /a/b — three regex semantics for one string. And asked to
“strip the prefix”, Envoy and OpenResty send the backend //x/y while Kong sends
/x/y.
The path
Each lesson is a 12–15 minute read with a lab that runs in the browser.
One route set, three answers
Five routes built on all three gateways, seven paths sent through. Envoy sorts nothing, the other two do. With a lab for your own routes.
Lesson 2What the backend receives
Sixteen combinations really curled, including the ones where two gateways emit a double slash. With a lab for your own rewrite rules.
How it was measured
Four containers on one Docker network: an nginx backend that echoes the
$request_uri it receives, and three gateways pointed at it. Every figure in this
course is a real curl through one of the three, with no client library in
between.
docker network create apilab
docker run -d --name apilab-echo --network apilab nginx:1.27-alpine
docker run -d --name apilab-envoy --network apilab envoyproxy/envoy:v1.31-latest …
docker run -d --name apilab-kong --network apilab -e KONG_DATABASE=off kong:3.9
docker run -d --name apilab-or --network apilab openresty/openresty:alpine
Most configurations were written as pairs in opposite orders, to separate what the gateway sorts from what the author's ordering decides. That is the only way the difference surfaced at all: Envoy sorts nothing, while the other two reorder before serving.
Both JavaScript engines in the course were checked back against those measurements: the route picker matches 74 of 74 curl results, the path assembler 16 of 16.