This message was deleted.
# announcements
s
This message was deleted.
c
It’s very common to use a proxy server in front of api server to handle authentication and rate limiting for security
Btw what environment are you deploying to? Is it on aws ec2, a K8s cluster or something else?
g
Right now the project is considered a PoC and it will be in a Docker host
I was thinking take a look to Kong API Gateway to solve this, I know I can put an nginx to handle https but I still need auth...just trying to choose a tool that provide both of them
Maybe just HTTP Basic Authentication from nginx do the trick
c
Nginx supports many authentication mechanism via plugin, JWT is also a good option for this. If your team is already using Kong, it’s definitely going to make this easier, cc @Guanlan Dai
g
Hi @Guillermo Alvarado , I’m the engineering lead behind Kong, you can find a detailed guide to enable JWT for your API with Kong: https://konghq.com/blog/jwt-kong-gateway
👍 2
Also Kong can handle HTTPS with Let’s Encrypt or any other ACMEv2 intergation, and tons of other auth plugins include basic auth: https://docs.konghq.com/hub/#authentication
👍 2
g
Thanks folks @Guanlan Dai@Chaoyu!