Back to articles
Technology Insight

Building a Centralized API Gateway Platform with Apache APISIX on VPS for Microservices Management

June 3, 2026

Introduction to Modern Microservices Architecture

In the contemporary digital landscape, transitioning from monolithic architectures to microservices has become a standard practice for enterprises seeking scalability, agility, and resilience. However, decomposing a large application into dozens or hundreds of independent services introduces a new set of challenges. Managing service-to-service communication, ensuring security uniformity, and handling cross-cutting concerns like rate limiting, authentication, and logging can quickly become overwhelming.

This is where a centralized API Gateway becomes indispensable. Acting as a single entry point for all client requests, an API Gateway abstracts the underlying microservices infrastructure, routing traffic efficiently while enforcing global policies. Among the open-source solutions available today, Apache APISIX stands out as a high-performance, cloud-native API gateway that delivers exceptional speed, low latency, and dynamic configuration capabilities.

Why Choose Apache APISIX on a VPS?

When implementing an API Gateway, organizations often debate between fully managed cloud services and self-hosted solutions. Building your centralized API Gateway using Apache APISIX on a Virtual Private Server (VPS) offers a perfect balance of cost-efficiency, absolute data sovereignty, and architectural flexibility.

Key Advantages of Apache APISIX:

  • Ultra-low Latency: Built on top of Nginx and OpenResty, APISIX handles massive concurrent requests with sub-millisecond processing overhead.
  • Dynamic Configuration: Utilizing etcd as its configuration center, APISIX allows hot-reloading of routes, upstream services, and plugins without restarting the gateway service, ensuring zero downtime.
  • Rich Plugin Ecosystem: It features over 80 built-in plugins covering authentication, security, traffic control, and observability, drastically reducing custom development time.

By hosting Apache APISIX on a high-quality VPS, you eliminate vendor lock-in, significantly lower monthly infrastructure costs compared to cloud-native managed gateways, and retain full control over your network topology and security configurations.

Architectural Overview: Centralized Gateway Pattern

In a centralized API Gateway design, the gateway sits firmly between external clients (mobile apps, web apps, third-party integrations) and internal microservices. Instead of clients interacting directly with individual service endpoints, they send requests to the APISIX instance on your VPS.

The fundamental principle of this architecture is encapsulation. The internal microservices network remains private and secure, while only the API Gateway is exposed to the public internet.

Apache APISIX utilizes an architecture separated into a data plane and a control plane. The data plane handles the actual traffic routing and policy execution, while the control plane (powered by etcd) manages configuration synchronization. This ensures that even if the configuration store experiences temporary disruption, the data plane continues to route traffic seamlessly based on cached configurations.

Step-by-Step Deployment of Apache APISIX on VPS

Setting up Apache APISIX on a modern Linux VPS (such as Ubuntu 22.04 LTS or 24.04 LTS) is highly streamlined when using Docker and Docker Compose. This containerized approach ensures environment isolation and simplifies future upgrades.

Step 1: Preparing the VPS Environment

First, connect to your VPS via SSH and ensure system packages are fully updated. Install Docker and Docker Compose if they are not already present on the system:

sudo apt update && sudo apt upgrade -y
sudo apt install docker.io docker-compose -y
sudo systemctl enable --now docker

Step 2: Cloning the APISIX Docker Repository

Apache provides an official repository containing Docker Compose templates optimized for various use cases. Clone the repository and navigate to the working directory:

git clone [https://github.com/apache/apisix-docker.git](https://github.com/apache/apisix-docker.git)
cd apisix-docker/example

Step 3: Launching the Services

The default example configuration spins up Apache APISIX, etcd, and the APISIX Dashboard. Execute the following command to start the stack in detached mode:

docker-compose -p apisix up -d

Verify that all containers are running properly by executing docker ps. You should see containers for apisix-dashboard, apisix, and etcd active and listening on their respective ports.

Configuring Routes and Upstream Microservices

With Apache APISIX running on your VPS, you can now begin configuring routes to manage your microservices. This can be achieved either programmatically via the Admin REST API or visually through the APISIX Dashboard (typically accessible via port 9000).

Defining an Upstream Service

An Upstream in APISIX represents your actual backend microservices. To create a highly available configuration, you can specify multiple target nodes for load balancing. For instance, if you have a Payment Service running on internal IP addresses, you configure it as follows via the Admin API:

curl "[http://127.0.0.1:9180/apisix/admin/upstreams/1](http://127.0.0.1:9180/apisix/admin/upstreams/1)" \
-H "X-API-KEY: edd1c9f034335f136f87ad84b625c8f1" \
-X PUT -d '
{
  "type": "roundrobin",
  "nodes": {
    "10.0.0.5:8080": 1,
    "10.0.0.6:8080": 1
  }
}'

Creating a Dynamic Route

Once the upstream is defined, you create a Route to map public URL paths to that specific upstream. The following command binds public requests targeting /api/v1/payments/* to our freshly configured Upstream ID 1:

curl "[http://127.0.0.1:9180/apisix/admin/routes/1](http://127.0.0.1:9180/apisix/admin/routes/1)" \
-H "X-API-KEY: edd1c9f034335f136f87ad84b625c8f1" \
-X PUT -d '
{
  "uri": "/api/v1/payments/*",
  "upstream_id": "1"
}'

Any incoming traffic to your VPS on the APISIX HTTP port matching this URI pattern will now automatically be load-balanced across your private payment microservices.

Enhancing Security and Traffic Control via Plugins

A centralized gateway is more than just a proxy router; it serves as your primary line of defense. Apache APISIX enables granular, plug-and-play management of cross-cutting concerns directly at the gateway layer, shielding your backend microservices from malicious activity and resource exhaustion.

Implementing Key-Auth Authentication

Instead of building authentication logic inside every single microservice, activate the key-auth plugin on your public routes. APISIX will validate the API keys before passing requests downstream, rejecting unauthorized calls immediately at the perimeter.

Enforcing Rate Limiting

To prevent Denial of Service (DoS) attacks or abuse of your APIs, apply the limit-count plugin. This restricts the number of requests a specific client can make within a designated timeframe (e.g., maximum 100 requests per minute):

"plugins": {
  "limit-count": {
    "count": 100,
    "time_window": 60,
    "rejected_code": 429,
    "key": "remote_addr"
  }
}

Production Best Practices for Apache APISIX on VPS

Operating an API Gateway in production requires meticulous attention to stability, monitoring, and security hardening. Consider the following industry best practices:

  1. Secure the Control Plane: Never expose port 9180 (Admin API) or port 9000 (Dashboard) directly to the public internet. Use a strict firewall (such as UFW or cloud security groups) to restrict access only to trusted administrative IP addresses or wrap them behind a secure VPN.
  2. Enable TLS/SSL: Secure all client-to-gateway communication. Use APISIX's native SSL support or configure a reverse proxy like Nginx/Certbot to terminate Let's Encrypt certificates directly at the VPS border.
  3. Externalize etcd Storage: For high-availability production clusters, back up your etcd database regularly or utilize a managed etcd cluster to ensure configuration data is never lost during VPS maintenance.
  4. Implement Observability: Enable plugins such as prometheus and zipkin to export telemetry data. Monitoring metrics like request volume, error rates, and latency profiles allows operations teams to identify bottlenecks instantly.

Conclusion

Building a centralized API Gateway platform with Apache APISIX on a VPS provides modern businesses with a powerful, cost-efficient, and highly scalable foundation for managing microservices. By centralizing routing, authentication, and traffic control, you offload critical complexity from your backend development teams, enabling them to focus entirely on core business logic. With its cloud-native architecture, lightning-fast execution, and flexible plugin system, Apache APISIX empowers you to maintain enterprise-grade infrastructure directly under your own operational control.

Building a Centralized API Gateway Platform with Apache APISIX on VPS for Microservices Management | DPTCloud