Design the entry tier for a public API that authenticates callers, enforces per-client rate limits, and protects a fleet of backend services from overload.
Design a public-facing API gateway: the single front door for a public API consumed by many third-party clients, each with an API key. The gateway is responsible for admitting traffic, enforcing per-client rate limits, and forwarding accepted requests to backend application servers, while shielding those backends and the datastore from abusive or bursty traffic.
The central challenge is that rate-limit state must be consistent across every gateway instance: a client's quota is global, not per-instance, so two gateway nodes handling the same client's requests must share a single view of that client's usage. A rate limiter whose counters live only in one node's memory will let a client exceed their quota simply by spreading requests across nodes.
Lay out the architecture: how requests enter, where rate limiting happens, how limit state is shared across gateway instances, and how accepted traffic reaches the backends and the datastore. Then document the API surface, your capacity assumptions, and the trade-offs.