Kong

Kong


Beginner

Q1: What is Kong?

Kong is an API gateway platform for routing, securing, and observing API traffic.

Q2: Why use Kong?

Centralizes API access control, authentication, rate limiting, and traffic policies.

Q3: What problem does API gateway solve?

Provides a single controlled entry point for many backend services.

Q4: Kong Gateway open-source vs enterprise?

OSS provides core gateway features; enterprise adds advanced governance/analytics features.

Q5: What is data plane in Kong?

Proxy nodes handling live API traffic.

Q6: What is control plane in Kong?

Management/configuration plane distributing policies/routes to data planes (mode dependent).

Q7: What is a Service in Kong?

Represents an upstream API/service abstraction.

Q8: What is a Route in Kong?

Defines how incoming requests match and map to a Service.

Q9: Route matching criteria examples?

Host, path, method, headers, SNI (depending protocol/config).

Q10: What is an Upstream in Kong?

Logical load-balanced pool of backend targets.

Q11: What is Target in Kong?

Individual backend endpoint (IP/host:port) inside an Upstream.

Q12: Why separate Service/Route/Upstream concepts?

Clear decoupling of traffic entry, policy, and backend resolution.

Q13: What is a Plugin in Kong?

Reusable policy/filter extending gateway behavior.

Q14: Common Kong plugin examples?

Rate limiting, key-auth, JWT, OIDC, ACL, CORS, request-transformer, logging.

Q15: What is Consumer in Kong?

Identity entity representing API client/app/user.

Q16: Why use Consumers?

Attach credentials, ACLs, and per-client policies.

Q17: What is credential in Kong?

Auth material linked to consumer (API key, JWT secret, cert, etc.).

Q18: What is declarative config in Kong?

YAML/JSON config defining gateway state (DB-less workflows common).

Q19: DB mode vs DB-less mode?

DB mode stores config in database; DB-less loads full declarative state directly.

Q20: Why DB-less mode?

Simplicity, GitOps friendliness, and immutable config patterns.

Q21: What is Kong Admin API?

API for managing gateway configuration and entities.

Q22: Why secure Admin API strictly?

It controls traffic/security policies for entire gateway.

Q23: What is Kong Manager?

Web UI for managing Kong entities (edition/feature availability varies).

Q24: What is TLS termination in Kong?

Kong handles HTTPS and forwards to upstream over configured protocol.

Q25: What is SNI in Kong/TLS context?

Select certificate based on requested server name.

Q26: What is mTLS at gateway?

Require client certificates for strong mutual authentication.

Q27: What is CORS plugin use?

Manage browser cross-origin request policies centrally.

Q28: What is rate limiting plugin use?

Throttle requests per consumer/ip/credential/window.

Q29: Why rate limit?

Protect upstreams from abuse and accidental overload.

Q30: What is request transformation plugin use?

Modify headers/body/path/query before upstream forwarding.

Q31: What is response transformation use?

Adjust outbound responses for compatibility/security needs.

Q32: What is logging plugin use?

Export request/response metadata to observability systems.

Q33: What is upstream timeout?

Max connect/read/write time before gateway aborts request.

Q34: Why timeout tuning matters?

Prevents hung connections and preserves gateway capacity.

Q35: What is retry behavior?

Gateway retries failed upstream requests under configured rules.

Q36: Retry risk?

Can amplify load during partial failures if misconfigured.

Q37: What is circuit breaker concept (upstream health)?

Avoid routing to repeatedly failing targets (implementation/plugin/pattern dependent).

Q38: What is health check in Kong upstreams?

Active/passive checks determining target availability.

Q39: Why health checks are important?

Route traffic only to healthy backends.

Q40: What is load balancing strategy examples?

Round-robin, least-connections, consistent-hashing (capabilities vary by setup/version).

Q41: What is sticky session pattern?

Use hashing/cookies to keep client routed consistently.

Q42: Sticky session tradeoff?

Session continuity vs uneven distribution risk.

Q43: Beginner anti-pattern with Kong?

Putting all APIs/routes/plugins in one unmanaged shared namespace.

Q44: Another beginner anti-pattern?

Exposing Admin API publicly.

Q45: Beginner security baseline?

Private admin plane, TLS everywhere, least-privilege credentials.

Q46: Beginner reliability baseline?

Multiple gateway replicas and upstream health checks.

Q47: Beginner observability baseline?

Track latency, status codes, throughput, auth failures.

Q48: Beginner governance baseline?

Standard route naming/plugin baseline templates.

Q49: What is decK in Kong ecosystem?

Tool for declarative config sync/diff for Kong state management.

Q50: Why use decK?

GitOps-style versioned, repeatable gateway configuration workflows.

Q51: What is Konnect (Kong platform concept)?

Managed control-plane/SaaS style management offering (feature availability dependent).

Q52: Why managed control plane can help?

Operational simplification and centralized governance.

Q53: What is workspace concept (edition-dependent)?

Logical configuration isolation for teams/tenants.

Q54: Why workspace isolation?

Reduce multi-team blast radius and config collisions.

Q55: Beginner workflow principle?

Treat gateway config as code with PR reviews.

Q56: Beginner architecture principle?

Separate ingress traffic concerns from service business logic.

Q57: Beginner collaboration principle?

Platform team defines guardrails, app teams onboard via templates.

Q58: Beginner incident principle?

Document 401/403/429/5xx gateway triage playbooks.

Q59: Beginner scaling principle?

Start simple with standardized plugin bundles.

Q60: Beginner best practice?

Run Kong as critical edge infrastructure, not just proxy middleware.

Intermediate

Q61: What is plugin execution order concern?

Multiple plugins can interact; order affects final behavior.

Q62: Why plugin order matters?

Auth, transform, and rate-limit precedence changes outcomes/security.

Q63: What is global plugin vs scoped plugin?

Global applies to all traffic; scoped applies to service/route/consumer.

Q64: Scoped plugin benefit?

Fine-grained policy without unintended platform-wide impact.

Q65: What is consumer group concept (if available)?

Group-based policy assignment for multiple consumers.

Q66: What is ACL plugin?

Allow/deny API access based on consumer group membership.

Q67: What is key-auth vs JWT auth difference?

API key lookup vs token signature/claims validation.

Q68: What is OIDC plugin role?

Delegate authentication/authorization to identity provider via OIDC flows.

Q69: OIDC gateway benefit?

Centralized auth integration for many APIs.

Q70: OIDC caution?

Token validation/caching/introspection settings must match risk and scale.

Q71: What is request size limiting?

Block oversized payloads to protect upstreams/resources.

Q72: What is bot/abuse mitigation at gateway?

Rate limits, IP reputation, auth hardening, anomaly controls.

Q73: What is canary release using Kong?

Route subset traffic to new upstream targets by weights/headers.

Q74: What is blue/green via Kong?

Switch routes/upstream targets from old to new environment.

Q75: What is traffic mirroring concept?

Send copy of traffic to shadow upstream for validation.

Q76: Why traffic mirroring useful?

Test new versions without affecting client responses.

Q77: What is upstream mTLS?

Gateway authenticates to upstream with client certs.

Q78: Why upstream TLS/mTLS matters?

Protect service-to-service data and identity, not just edge traffic.

Q79: What is certificate rotation challenge?

Avoid downtime while renewing many certs/keys.

Q80: Rotation best practice?

Automate issuance, staged deployment, and expiry alerting.

Q81: What is intermediate anti-pattern?

Per-route custom plugins without standard baseline controls.

Q82: Better policy model?

Global minimum security baseline + scoped additive overrides.

Q83: What is declarative drift?

Live gateway config differs from Git-declared desired state.

Q84: Drift mitigation with decK?

Regular diff/sync and CI policy checks before apply.

Q85: What is Kong Ingress Controller (KIC)?

Kubernetes controller translating Ingress/Gateway resources into Kong config.

Q86: Why use Kong with Kubernetes?

Unified gateway policies with K8s-native declarative workflows.

Q87: KIC vs standalone Kong config?

KIC derives from K8s resources; standalone often direct Admin API/declarative config.

Q88: What is CRD-based config in Kong K8s?

Custom resources expressing plugins/consumers/routes beyond basic Ingress.

Q89: What is Gateway API relation with Kong?

Modern K8s traffic API often supported via controller integration patterns.

Q90: What is DB migration concern in Kong DB mode?

Versioned schema migrations must be coordinated during upgrades.

Q91: What is hybrid mode concept in Kong?

Separated control plane and data plane communication architecture.

Q92: Hybrid mode benefit?

Central config governance with distributed low-latency data planes.

Q93: Hybrid mode security concern?

Control/data plane mTLS and cert lifecycle must be robust.

Q94: What is rate limit storage strategy impact?

Local vs central counters affect consistency/performance tradeoffs.

Q95: What is auth cache tuning concern?

Cache improves latency but affects revocation immediacy.

Q96: What is intermediate observability baseline?

Per-route latency percentiles, plugin error rates, upstream health trends.

Q97: What is distributed tracing integration?

Propagate trace context and export spans for end-to-end visibility.

Q98: Why trace gateway hops?

Identify edge vs upstream latency contributors quickly.

Q99: What is log redaction need at gateway?

Prevent sensitive headers/tokens/PII leakage to logs.

Q100: What is intermediate security baseline?

Private admin/control plane, strong authN plugins, mTLS where needed.

Q101: What is intermediate reliability baseline?

HA gateway clusters, health checks, tested failover.

Q102: What is intermediate governance baseline?

Config-as-code, policy linting, approval workflows.

Q103: Intermediate maturity signal?

Teams onboard APIs through standardized templates with low incident rate.

Q104: What is intermediate cost principle?

Optimize plugin usage and logging volume to control overhead.

Q105: What is intermediate scaling principle?

Segment traffic domains and avoid one massive shared gateway when needed.

Q106: What is intermediate operations principle?

Use canary config rollouts for high-risk gateway changes.

Q107: What is intermediate architecture principle?

Separate external, partner, and internal API gateway lanes.

Q108: What is intermediate collaboration principle?

Platform team owns paved road; API teams own service contracts.

Q109: What is intermediate compliance principle?

Audit API access policy changes and credential lifecycle events.

Q110: What is intermediate resilience principle?

Design upstream fallback and timeout budgets explicitly.

Q111: What is intermediate migration principle?

Move legacy edge logic incrementally into gateway policies.

Q112: What is intermediate quality principle?

Automated tests for route matching and auth/rate-limit behavior.

Q113: What is intermediate delivery principle?

Promote gateway config from dev to prod with immutable artifacts.

Q114: What is intermediate trust principle?

Treat every plugin/config update as security-relevant change.

Q115: What is intermediate tenancy principle?

Use workspaces/projects/namespaces for team isolation.

Q116: What is intermediate incident principle?

Classify failures by edge auth, routing, upstream, or platform layer.

Q117: What is intermediate SLO principle?

Define latency/error objectives per API class at gateway edge.

Q118: What is intermediate policy principle?

Enforce minimum TLS and auth requirements by default.

Q119: What is intermediate capacity principle?

Load test peak traffic with plugin stack enabled.

Q120: What is intermediate backlog principle?

Continuously remove one-off route exceptions.

Q121: What is intermediate platform principle?

Document golden plugin combinations and anti-patterns.

Q122: What is intermediate safety principle?

Restrict who can modify global plugins/routes.

Q123: What is intermediate lifecycle principle?

Automate cert/key/client credential rotation schedules.

Q124: What is intermediate telemetry principle?

Correlate gateway metrics with upstream app SLOs.

Q125: Intermediate best practice?

Build Kong as a governed API platform, not ad-hoc proxy config.

Advanced

Q126: What is Kong at enterprise scale challenge?

Balancing central governance with team autonomy across many APIs and regions.

Q127: What is multi-region Kong architecture pattern?

Regional data planes with centralized or federated control planes.

Q128: What is active-active gateway strategy?

Serve traffic simultaneously from multiple regions for resilience/performance.

Q129: What is active-passive strategy?

Primary region handles traffic; secondary takes over on failure.

Q130: What is global traffic steering relation?

DNS/GSLB/CDN directs clients to healthy/nearest gateway region.

Q131: What is control-plane blast radius?

Misconfiguration can affect every connected data plane/API.

Q132: Blast-radius mitigation?

Scoped workspaces, staged rollouts, policy validation, regional segmentation.

Q133: What is plugin supply-chain risk?

Compromised custom/community plugin can execute at critical edge path.

Q134: Plugin supply-chain mitigation?

Signed artifacts, code review, restricted plugin allowlist, runtime hardening.

Q135: What is zero-trust API gateway posture?

Strong identity verification and least privilege for every request path.

Q136: What is fine-grained authorization pattern?

Gateway enforces coarse authN; services enforce domain-specific authZ.

Q137: Why not only gateway authorization?

Business-context authorization often requires service-local logic/data.

Q138: What is token exchange/delegation concern?

Improper downstream token propagation can widen privilege exposure.

Q139: Mitigation for token propagation risk?

Audience scoping, token minimization, short TTL, secure header handling.

Q140: What is data privacy risk at gateway?

Sensitive payload/header logging and transformation leakage.

Q141: Privacy mitigation?

Redaction, field-level masking, minimal log retention, encrypted transport/storage.

Q142: What is API product governance with Kong?

Cataloging APIs, plans, quotas, and lifecycle controls (tooling/edition dependent).

Q143: What is monetization/plan enforcement concept?

Rate/quota tiers and consumer entitlements for partner/public APIs.

Q144: What is noisy-neighbor issue in shared gateway?

One tenant/API consumes disproportionate resources affecting others.

Q145: Noisy-neighbor mitigation?

Isolation pools, resource limits, per-tenant quotas, dedicated gateways.

Q146: What is gateway capacity planning key metrics?

RPS, p95/p99 latency, connection counts, plugin CPU overhead, error budget burn.

Q147: Why plugin overhead benchmarking is critical?

Complex chains can significantly increase latency/cost.

Q148: What is chaos testing for gateways?

Inject upstream failures, latency spikes, cert issues, and CP/DP disconnects.

Q149: Why chaos tests matter for Kong?

Validate resilience and fail-safe behavior under realistic faults.

Q150: What is CP/DP partition behavior concern?

Data planes continue with last-known config; drift/change propagation pauses.

Q151: Operational mitigation for CP/DP partitions?

Alerting, config freeze policies, reconnection runbooks.

Q152: What is disaster recovery for Kong platform?

Backup config/state, restore control plane, verify data plane sync and cert trust.

Q153: Why DR rehearsal is mandatory?

Edge outages affect all APIs; untested recovery is high risk.

Q154: What is policy-as-code for Kong?

Automated checks ensuring route/plugin/security compliance before deployment.

Q155: Example policy checks?

No public route without auth, TLS required, no unsafe plugins globally.

Q156: What is canary config rollout pattern?

Apply changes to subset gateway nodes/routes before fleet-wide rollout.

Q157: What is rollback trigger for gateway config?

SLO degradation or auth/routing error spike after release.

Q158: What is observability gold standard for Kong?

Unified metrics/logs/traces with per-route, per-consumer, per-plugin visibility.

Q159: What is DORA/SRE relevance for API gateways?

Measure change safety/velocity and operational reliability of edge platform.

Q160: What is compliance evidence in gateway operations?

Audit trail of policy changes, credential issuance, access decisions, incident actions.

Q161: What is segregation of duties pattern?

Separate platform admins, security policy approvers, API publishers.

Q162: What is advanced anti-pattern?

Embedding excessive business transformations in gateway layer.

Q163: Better boundary principle?

Gateway handles cross-cutting concerns; business logic stays in services.

Q164: What is hybrid cloud Kong challenge?

Consistent policy and identity across heterogeneous networking environments.

Q165: Mitigation for hybrid inconsistency?

Standardized config pipelines and environment-specific controlled overlays.

Q166: What is final reliability principle?

Gateway must fail predictably and preserve core API availability under stress.

Q167: What is final security principle?

Every edge path must enforce strong auth, transport security, and least privilege.

Q168: What is final governance principle?

Standardize API onboarding with automated guardrails and auditable exceptions.

Q169: What is final architecture principle?

Design for isolation domains matching risk, tenancy, and traffic profile.

Q170: What is final operations principle?

Continuously test upgrades, failover, and rollback at platform scale.

Q171: What is final collaboration principle?

Platform and API teams co-own consumer experience and security posture.

Q172: What is final scaling principle?

Segment gateways before shared-control complexity becomes bottleneck.

Q173: What is final compliance principle?

Retain tamper-evident logs for auth, policy, and admin actions.

Q174: What is final performance principle?

Optimize plugin chains and upstream interactions using real traffic data.

Q175: What is final trust principle?

Protect control plane and config pipeline as crown-jewel assets.

Q176: What is final product principle?

Treat gateway capabilities as internal product with roadmap and SLAs.

Q177: What is final migration principle?

Move legacy edge controls incrementally with measurable safety gates.

Q178: What is final resilience principle?

Plan for region, control-plane, and upstream dependency failures explicitly.

Q179: What is final strategy principle?

Prefer declarative, tested, Git-driven gateway operations.

Q180: Final maturity principle?

Kong excellence is secure, observable, and governable API traffic control at scale.

Bonus: Minimal decK-Style Declarative Snippet (Conceptual)

_format_version: "3.0"
services:
  - name: payments
    url: http://payments.default.svc.cluster.local:8080
    routes:
      - name: payments-route
        paths: ["/payments"]
plugins:
  - name: rate-limiting
    service: payments
    config:
      minute: 300
      policy: local