Back to All Case Studies
Cloud ArchitectureRepresentative Architecture Project2024 - 2025

OmniScale Enterprise Cloud Gateway

High-Throughput Multi-Region API Router & Microservice Mesh

Abin's RoleLead Solution Architect
Industry / DomainCloud Infrastructure & High-Throughput API Networking
Engagement ContextEnterprise identity and proprietary network topologies are generalized under non-disclosure agreements. System performance reflects benchmark load testing and staging environments.
Request Throughput
50,000+ RPS
Sustained peak workload
P99 Routing Latency
< 8ms
Sub-millisecond Edge cache
Platform Uptime
99.99%
Zero single points of failure
Infrastructure Cost Savings
35%
Optimized resource allocation
The Challenge

The Business & Technical Problem

Monolithic reverse proxies collapsed under flash-sale traffic surges exceeding 25,000 requests per second. Gateway CPU starvation drove P99 routing latency over 250ms, triggering cascading timeouts and service outages across 40+ downstream microservices.

Execution Scope

Delivered Scope & Responsibilities

Architecture & System Design

Architected multi-region API Gateway and service mesh on AWS EKS across us-east-1, eu-west-1, and ap-southeast-1.

Backend & API Development

Wrote custom Envoy Proxy filters in Go for dynamic header routing, rate limiting, and token validation.

Frontend or Mobile Application

Configured Cloudflare Anycast edge routing and DNS failover policies.

Database Architecture & Persistence

Designed global Redis cluster for distributed token bucket rate limiting and session blocklists.

Authentication & Permissions

Decentralized JWT validation to edge proxies using asymmetric RSA-256 keys.

Infrastructure & Deployment

Authored 100% infrastructure-as-code via Terraform modules with zero-downtime canary deployments.

Monitoring & Maintenance

Implemented Cilium eBPF network tracing with Prometheus and Grafana dashboards.

Technical Rationale

Architecture Decisions, Rejected Alternatives & Accepted Trade-Offs

1

Envoy Proxy with Custom Go Filter Extensions instead of NGINX / Kong

Why It Was Chosen:

Envoy's non-blocking dynamic reloads, built-in circuit breaking, and sub-millisecond thread pool latency handled heavy concurrency without connection drops.

Alternatives Rejected:

Kong was rejected due to Lua memory overhead; standard NGINX was rejected due to static configuration reload connection resets.

Trade-Offs Accepted:

Steeper configuration learning curve and complex Envoy xDS control plane management.

2

Edge-Level Asymmetric JWT Validation

Why It Was Chosen:

Validating cryptographic signatures directly at ingress proxies removed a 30,000 RPS authentication bottleneck on the internal auth microservice.

Alternatives Rejected:

Synchronous HTTP auth-check calls for every incoming request.

Trade-Offs Accepted:

Token revocation required maintaining a distributed Redis blocklist.

Verifiable Evidence

Measured Project Outcomes

Every metric specifies the measurement environment, method, and Abin's contribution. Unverified benchmarks are not presented as contractual SLAs.

Sustained Peak ThroughputBenchmark
Baseline
25,000 RPS (system choked)
Verified Result
50,000+ RPS
Method: Distributed k6 load generators across 5 VPC worker nodes (Q4 2024)
Abin's Contribution: Architected horizontal pod autoscaling and connection keep-alive pools.
P99 Gateway Routing LatencyBenchmark
Baseline
260ms
Verified Result
< 8ms
Method: Envoy access logs and Prometheus latency histograms (Q4 2024)
Abin's Contribution: Eliminated synchronous auth hops and tuned kernel TCP socket buffers.
Infrastructure Cloud ExpenseStaging
Baseline
$42,000 / month
Verified Result
35% reduction (~$14,700/mo saved)
Method: AWS Cost Explorer comparison before and after architecture rollout (Q1 2025)
Abin's Contribution: Right-sized EKS node groups and eliminated over-provisioned standalone proxy instances.

Evidence & Confidentiality Notice

Client details and proprietary network diagrams are omitted under confidentiality. The technical description has been generalized with client permission.

Scope Limitations & Benchmark Boundaries
  • The 50,000+ RPS benchmark was achieved on synthetic HTTP payloads with keep-alive connections; payload inspection of multi-megabyte multipart uploads introduces additional latency.
  • Cost savings reflect compute right-sizing on AWS EKS and may vary on alternative cloud providers.
Next Architectural Steps

Discuss High-Throughput Cloud Architecture

Planning a multi-region API Gateway, microservice migration, or cloud infrastructure overhaul?

Technology Stack & Tools Used

GoKubernetesAWS EKSEnvoyRedis ClusterTerraformPrometheusGrafana
Ready to Build Your Project?

Let's Build Your Custom Web Application

Whether you need a full-stack web app, a Node.js REST API, a Next.js SaaS MVP, an admin dashboard, or performance optimization for an existing application — I am available for freelance projects in Kerala, India, and worldwide.

Fast WhatsApp & Email ResponseRemote Worldwide & IndiaFixed-Scope or Milestone Rates