A gateway can centralize routing and selected edge policy. Avoid moving all business orchestration into it and creating a new monolith at the boundary.
Before you start
You should understand HTTP, database transactions and the difference between one process and independently failing services. Draw the participants and message direction before choosing a pattern. Include timeout, duplicate delivery and recovery in the model instead of considering only successful requests.
The practical goal is to reason through this situation: The gateway authenticates and routes while domain services enforce their own authorization. Read the walkthrough first, then try the interview exercise before opening its answer. The important part is explaining the decision and its consequences, rather than remembering a definition alone.
Step-by-step walkthrough
Step 1: Assign edge responsibilities
Centralize routing and selected cross-cutting policy.
Step 2: Keep domain ownership
Inventory and payment rules remain in their owning services.
Step 3: Secure alternate access
Domain services authorize operations even when requests bypass the normal gateway.
Worked scenario
The gateway authenticates and routes while domain services enforce their own authorization.
The gateway validates an access token, but the billing service checks whether that caller may refund the particular invoice. A background consumer or internal caller may reach billing through another path. Moving all workflow logic into the gateway makes every domain change depend on that central component.
Common mistake
Trusting gateway checks alone can leave alternate internal access paths unprotected.
Verify the behavior
Test alternate paths and verify domain authorization independently of routing.
Interview exercise
Choose a gateway feature.
Answer and reasoning
Use bounded cross-cutting responsibilities and keep domain invariants within their owning services.
Continue learning
Compare the scenario with the Microservices interview questions and test your understanding with the Microservices MCQs. For terminology and implementation details, consult the reference material.