REVERSE PROXY +
LOAD BALANCER +
API GATEWAY
When I first heard terms like proxy, reverse proxy, load balancer, and API gateway, I honestly thought: "Aren’t they all just middlemen"
They are all middle layers. But they exist for very different reasons. And if you’re building serious backend systems, especially microservices, understanding the difference is not optional.
Proxy (Forward Proxy) – Client Side Bodyguard
A proxy (specifically a forward proxy) sits between client and the internet.
The client talks to the proxy.
The proxy talks to the server.
The server never sees the real client directly.
Real-world analogy
Think of it like your company’s office internet.
You request google.com. Your request goes to company proxy first.
Proxy decides: allowed / blocked / logged.
Then it forwards to the internet.
What it’s used for
- check_circle Hiding client identity
- check_circle Content filtering
- check_circle Corporate firewall rules
- check_circle Bypassing geo restriction
Example
Browser → Proxy → Internet
In config:
export http_proxy=http://proxy.company.com:8080
In Java:
Proxy proxy = new Proxy(Proxy.Type.HTTP, new InetSocketAddress("proxy.company.com", 8080));
URLConnection connection = new URL("http://example.com").openConnection(proxy);Key mindset: Proxy protects and controls the CLIENT
Reverse Proxy – Server Side Gatekeeper
Now flip the direction. A reverse proxy sits in front of your servers.
Client → Reverse Proxy → Backend Server
Client doesn’t know your real backend server. This is where things get interesting.
The reverse proxy can:
Forward request
It forwards traffic to backend services.
location /api/ {
proxy_pass http://localhost:8080;
}Client hits:
https://myapp.com/api/users
Nginx forwards to:
http://localhost:8080/api/users
Backend server doesn’t need to expose itself publicly.
Do SSL termination
Instead of configuring SSL in every backend service, you let reverse proxy handle HTTPS.
Client → HTTPS → Reverse Proxy
Reverse Proxy → HTTP → Backend
Goal:
- check_circle Centralized certificate management
- check_circle Less complexity in microservices
- check_circle Better performance
Example in Nginx:
server {
listen 443 ssl;
ssl_certificate cert.pem;
ssl_certificate_key key.pem;
location / {
proxy_pass http://backend;
}
}Do caching
Reverse proxy can cache responses.
If /products rarely changes:
Client 1 → fetch from backend
Client 2 → reverse proxy returns cached response
Key mindset: Reverse proxy protects and optimizes the SERVER.
Add headers
Hide internal architecture
Load Balancer – Traffic Distributor
Now imagine you scale. You have 5 backend instances.
How do you distribute traffic?
That’s where Load Balancer comes in.
Client → Load Balancer → Multiple Servers
Load Balancer can:
Traffic Distribution
Which server gets this request?
Common algorithms: Round Robin, Least Connections, IP Hash
Example:
Server A, Server B, Server C
Requests go:
A → B → C → A → B → C
Health Check
Is that server healthy?
Load balancer continuously checks:
GET /health
If server responds 200 OK → healthy
If not → removed from rotation
Spring Boot example:
@GetMapping("/health")
public String health() {
return "OK";
}Failover
If one server dies, who replaces it?
If one server crashes, Load balancer automatically routes traffic to healthy nodes.
User never notices. That’s production-grade architecture.
Key mindset: Load balancer ensures availability and scalability.
API Gateway – Smart Front Door for Microservices
Now we enter microservices world. You have: User Service, Order Service, Payment Service, Notification Service.
You don’t want client to call each service directly.
Client → API Gateway → Microservices
It’s not just forwarding traffic. It adds business-level control.
API Gateway can:
Authentication
Gateway verifies JWT before request reaches service.
Example filter in Spring Cloud Gateway
@Bean
public GlobalFilter authFilter() {
return (exchange, chain) -> {
String token = exchange.getRequest().getHeaders().getFirst("Authorization");
// validate token
return chain.filter(exchange);
};
}Backend services don’t need to re-check auth repeatedly.
Rate Limiting
Prevent abuse.
Example rule: Max 100 requests per minute per IP
If exceeded → 429 Too Many Requests
Analytics & Monitoring
We can do: Log request count, Measure latency, Track API usage per client, Detect abuse.
That’s business visibility.
Key mindset: API Gateway adds intelligence and policy control.