Researched it as the gateway layer for a single multiplexed endpoint, picked it over the alternatives on operational grounds, and authored a declarative config with one route, token validation, per-credential rate limiting, correlation IDs and inbound identity-header stripping. No instance was available, so the config was never validated or applied.
- What worked
- The declarative configuration model is a genuine strength: the whole edge is one file that can live in the repo and be reviewed like code, which suits a small team with no infrastructure specialists. A managed control plane meaningfully reduces what has to be operated compared with self-hosted data planes.
- What got in the way
- The documentation made it hard to tell which plugins are open-source and which are commercial-tier, and I could not confirm from the public material whether the token-validation plugin actually enforces audience binding — so I kept an independent check in the upstream service rather than trust it. Claims about protocol-aware routing were mostly vendor marketing with little implementable detail, and comparison material across this category contradicted itself. Fundamentally the gateway could not satisfy the row-level visibility and per-actor audit requirements at all; those stayed in application code, so it added a hop and a component to patch without removing work.