Blog
Insights for API governance and platform teams
Ideas and patterns for shipping APIs safely—lifecycle, gateway policy, workflows, developer portal, observability, and AI agent access—without vendor lock-in.
Written for platform, security, and integration leads who run Zerq on-prem, hybrid, or cloud.
Subscribe via RSSUpdated when we publish—no inbox required.
Articles
- Self-hosting an enterprise API gateway with Docker Compose: the complete production guide
- deployment
- architecture
- docker
A complete guide to self-hosting an enterprise API gateway on Docker Compose: stack setup, TLS, env configuration, and production hardening for regulated teams.
Read article - NIS2 compliance at the API gateway: the controls regulated enterprises need
- compliance
- security
- rbac
NIS2 Article 21 compliance for regulated enterprises: how to configure RBAC, access control, audit trail, and incident detection at the API gateway layer.
Read article - Per-profile access control for AI agents at the API gateway layer
- ai-agents
- mcp
- access-control
How to configure AI agent access control at the API gateway: dedicated clients, scoped collections, method restrictions, and per-agent rate limits in Zerq.
Read article - SMART on FHIR scope validation at the API gateway: a step-by-step workflow builder guide
- healthcare
- fhir
- hipaa
Validate SMART on FHIR scopes at the API gateway layer — no custom middleware. Step-by-step workflow builder guide with real jwt_node and scope config.
Read article - AI agent API traffic: how to use gateway request logs as compliance evidence
- compliance
- ai-agents
- audit
Runtime request logs capture every AI agent API call: client identity, path, payload, status, latency. How to filter and package them as compliance evidence.
Read article - Azure API Management's control plane problem — and what regulated teams run on Azure instead
- azure
- api-gateway
- regulated-industries
Azure API Management keeps config and audit data in Microsoft's infrastructure. Here's the control plane problem for regulated industries and how to solve it.
Read article - Enrich API responses at the gateway layer using Postgres, MongoDB, and Redis workflow nodes
- workflows
- how-to
- database
Add database lookups to API responses at the gateway layer — no custom middleware. Real config for postgres_node, mongodb_node, and redis_node in Zerq.
Read article - Set up OIDC SSO and RBAC for your enterprise API gateway management platform
- security
- oidc
- rbac
Configure OIDC SSO and four-tier RBAC for enterprise API gateway administration: real env vars, role mappings, separation of duties, and a test checklist.
Read article - API gateway audit access for compliance and security teams
- compliance
- audit
- rbac
Set up dedicated audit access for compliance teams in Zerq: audit role RBAC, what auditors can see, log formats, SIEM export, and real-world audit queries.
Read article