Apache-2.0🖥️ Self-hostable

Kong Gateway

Kong Gateway

Kong Gateway is an open-source, cloud-native API gateway built on top of NGINX and OpenResty. It sits between clients and your backend services, handling traffic routing, authentication, rate limiting, request and response transformation, and observability in one place. Originally created by Kong Inc. (formerly Mashape), it is one of the most widely deployed open API gateways, with a sprawling plugin ecosystem that extends the core without forking the codebase.

Key Features

  • Plugin architecture — a rich marketplace of plugins for authentication (key, JWT, OAuth 2.0, OpenID Connect, LDAP), rate limiting, caching, transformation, and logging, plus the ability to write your own in Lua.
  • Traffic control — powerful routing, load balancing, circuit breaking, and dynamic request/response transformation based on headers, paths, and query params.
  • Admin REST API — manage every gateway configuration (services, routes, plugins, consumers) programmatically via a declarative admin API, perfect for GitOps and automation.
  • Horizontal scalability — stateless data-plane nodes behind a control plane let you scale traffic capacity linearly by adding instances.
  • Kubernetes-native — the Kong Ingress Controller manages gateway configuration through standard Kubernetes CRDs and Ingress resources.
  • Observability — request logging, metrics (Prometheus), distributed tracing, and health checks give you visibility into every request that crosses the gateway.

Why Use Kong?

Kong is a solid choice when you need a production-grade traffic layer that centralises authentication, security, and policy enforcement across many microservices. Because the core is pure open source (Apache-2.0) and configuration is API-driven, it fits both small self-hosted deployments and large Kubernetes fleets without licensing surprises at scale.

Use Cases

  • Exposing and securing many backend microservices behind a single, consistent entry point.
  • Enforcing rate limits, quotas, and API-key or JWT authentication for public or partner APIs.
  • Centralising request logging and metrics for every service you operate.
  • Running a Kong Ingress Controller inside Kubernetes to route and protect cluster ingress.

Platform

Linux · macOS · Docker · Kubernetes · Kong Gateway also runs on ARM, with corporate packages for Red Hat, Windows, and Debian/Ubuntu.

Licence

Apache-2.0 — the Kong Gateway OSS distribution is fully open source; commercial enterprise plugins are optional.

Website

konghq.com

Explore More Categories

Sign In

Register

Reset Password

Please enter your username or email address, you will receive a link to create a new password via email.