The API Gateway Maturity Matrix: Where Do You Rank? - Joel Hans, ngrok
Joel Hans, ngrok
KubeCon + CloudNativeCon Europe 2025 · Session
Overview
In this insightful KubeCon EU talk, Joel Hans, a Developer Advocate at ngrok, introduced the API Gateway Maturity Matrix, a practical framework designed to help organizations self-assess the state of their API gateway implementation. The talk addresses a common challenge faced by engineering teams: navigating the overwhelming array of features offered by modern API gateways and strategically determining which capabilities to prioritize for maximum impact. Hans emphasizes that the goal is not to enable every feature, but rather to identify the "next big thing" that provides the highest return on investment (ROI) based on an organization's specific needs and current stage of development.

Key moments
- 0:00 Introduction and the growing complexity problem
- 2:00 The problem: No way to self-assess API Gateway
- 3:30 Who this API Gateway matrix is for
- 4:30 Core philosophy: Prioritize, don't maximize features
- 6:00 Inspiration from the CNCF Cloud Native Maturity Model
- 6:40 Explanation of CNCF Maturity Model levels and dimensions
The API Gateway Maturity Matrix: Where Do You Rank?
Speakers: Joel Hans, Developer Advocate, ngrok
Conference: KubeCon EU
YouTube: https://www.youtube.com/watch?v=EOQ8qNstD8I
Overview
In this insightful KubeCon EU talk, Joel Hans, a Developer Advocate at ngrok, introduced the API Gateway Maturity Matrix, a practical framework designed to help organizations self-assess the state of their API gateway implementation. The talk addresses a common challenge faced by engineering teams: navigating the overwhelming array of features offered by modern API gateways and strategically determining which capabilities to prioritize for maximum impact. Hans emphasizes that the goal is not to enable every feature, but rather to identify the "next big thing" that provides the highest return on investment (ROI) based on an organization's specific needs and current stage of development.
Hans highlights the critical role of the API gateway as the "front door" to an organization's entire platform and business. As services proliferate and teams scale, an unmanaged or inconsistently configured API gateway can quickly become a source of chaos, security vulnerabilities, and developer friction. This matrix provides a structured roadmap, enabling platform engineers, CTOs, and DevOps professionals to move beyond ad-hoc solutions towards a more well-managed, secure, and developer-friendly API infrastructure. It encourages a conscious, phased approach to adoption, transforming the API gateway from a potential bottleneck into an accelerator for innovation.
The matrix is presented as a valuable tool for both consumers and builders of API gateways. For consumers, it offers a path to understand their current standing and explore future improvements. For builders, it provides insights into user journeys and ergonomic considerations, guiding product development to lead customers towards better practices without adding unnecessary complexity. Ultimately, Hans aims to foster a community around this model, encouraging collaborative refinement and real-world data contribution to make the framework even more robust and universally applicable.
Background
▶ Watch: Introduction and the growing complexity problem (0:00)
The genesis of the API Gateway Maturity Matrix stems from a pervasive problem in modern software development: the uncontrolled growth of complexity around API ingress. Joel Hans opens his talk with a relatable story of a "little baby Kubernetes cluster" that, over time, accumulates a mix of services, external integrations (like marketing sites on /blog paths), developer documentation, and API versioning challenges (V1 to V2 deprecations, rewrites, redirects). This organic, often uncoordinated expansion leads to a "moving target" scenario, leaving platform engineers feeling overwhelmed by a "rock slide" of problems and CTOs grappling with insurmountable chaos. The underlying issue, Hans argues, is a lack of a clear self-assessment mechanism for API gateways.
Hans drew inspiration from the CNCF Cloud Native Maturity Model, a broader framework outlining five levels of adoption—Build, Operate, Scale, Improve, and Adapt—across dimensions like people, technology, and business outcomes. While valuable, the CNCF model provides a high-level "forest" view of cloud-native culture and general implementation. Hans identified a need for a more granular, tactical model focused specifically on API gateways, which he describes as "one specific tree" within that forest. His objective was to distill the principles of maturity into actionable capabilities and requirements pertinent to the technical functions of an API gateway.
The problem persists because organizations often struggle to discern which of the myriad features offered by API gateways are truly beneficial for their current stage. This leads to either underutilization of powerful capabilities or a chaotic attempt to implement everything at once, resulting in technical debt and operational burden. Hans defines maturity not by the age of a product or the sheer number of features used, but by the "journey of adoption"—the flexibility of built systems to adapt to new problems and the ergonomics of enabling new capabilities. The core shift in maturity, according to Hans, is moving from engineers building API gateways solely for their own immediate problems to enabling others across the organization, all while maintaining essential control over this critical "front door" to their services. Without a structured assessment tool like the matrix, organizations are left to navigate this complexity reactively, often incurring significant costs in time, effort, and security vulnerabilities.
Key Findings
▶ Watch: Who this API Gateway matrix is for (3:30)
The central contribution of Joel Hans's talk is the API Gateway Maturity Matrix itself, a comprehensive framework for self-assessment and strategic planning. This matrix is built upon two core components:
- Five Maturity Levels: Borrowed and adapted from the CNCF Cloud Native Maturity Model, these levels describe an organization's progression in API gateway adoption:
- Build: Pre-production, basic ingress/reverse proxy, manual configuration, mixed approaches.
- Operate: Patching holes, ensuring new service deployments behind the gateway, standardizing.
- Scale: Smooth, efficient operation for growth, avoiding common pitfalls.
- Improve: Defining security, policy, and governance, addressing emerging needs at scale.
- Adapt: Innovating without over-engineering, future-proofing, revisiting decisions.
- Five Dimensions (Capability Threads): These represent distinct technical and operational areas within an API gateway's functionality:
- Traffic Management: How requests are routed, load balanced, and controlled.
- Authentication & Security: How access is granted, identities are verified, and threats are mitigated.
- Observability & Debugging: How the gateway provides insights into performance, errors, and usage.
- Developer & Team Experience: How easily developers can onboard, deploy, and manage services through the gateway.
- Governance & Compliance: How policies, standards, and regulatory requirements are enforced.
A key finding is that organizations often exhibit uneven maturity across these dimensions. Hans illustrates this with hypothetical "Acme Corp" examples, showing how a two-person startup might go "deep" on Traffic Management and Authentication early on, while neglecting Developer Experience or Governance. As the company grows to 50 or 200 people, their "radar" of maturity expands, often in response to specific challenges—for instance, rapidly advancing in Observability to address high error rates, or skyrocketing in Governance & Compliance due to an acquisition in a different regulatory environment.
Crucially, the matrix highlights that achieving "level 5 in all things" is neither a realistic nor a necessary goal. The primary value lies in identifying current strengths and weaknesses, understanding the landscape of available capabilities, and prioritizing the "next best ROI" investment. This prevents both under-investment and over-engineering, promoting a measured and strategic approach to API gateway evolution. The matrix serves as a powerful diagnostic tool, helping teams understand where they stand and where they should focus their efforts to enhance security, efficiency, and developer enablement.
Technical Deep Dive
▶ Watch: Core philosophy: Prioritize, don't maximize features (4:30)
The API Gateway Maturity Matrix dissects the complex landscape of API gateway capabilities across five levels of maturity and five distinct dimensions. Joel Hans elaborates on the technical evolution within each dimension, providing a roadmap for progress.
Traffic Management
At the Build level, organizations often start with rudimentary ingress solutions, a basic reverse proxy, or even direct port forwarding to expose services. Configurations are typically manual and static, leading to a "mix-and-match" scenario. As they move to Operate, the focus shifts to patching these initial holes, ensuring that new services are consistently deployed behind the API gateway rather than allowing ad-hoc exposure. The Scale phase emphasizes smooth operation and avoiding "foot guns" that can arise with increasing traffic and service count. In the Improve stage, traffic management becomes sophisticated, handling complex scenarios like API version deprecation (e.g., V1 to V2), advanced rewrites, and redirects to manage a dynamic service landscape. Finally, at the Adapt level, the API gateway enables dynamic, developer-driven traffic management, allowing developers to ship new functionalities with robust routing controls without direct infrastructure team intervention, often incorporating "very fancy things" like advanced load balancing algorithms or canary deployments as a standard practice.
Authentication & Security
The journey for Authentication & Security begins at Build with essential authentication methods (e.g., OAuth) embedded directly within individual services. This fragmented approach leads to inconsistency, increased security vulnerabilities, and a heavy maintenance burden for infrastructure teams. The Operate level marks a crucial shift towards centralizing authentication management within the API gateway. This becomes the single point for enforcing zero trust fundamentals, protecting APIs regardless of which team builds or deploys them. As organizations reach Scale, standardizing security on the API gateway transforms it from a potential bottleneck into an accelerator. Developers can ship services quickly, knowing that the gateway will handle authentication and authorization consistently. The Improve and Adapt phases see the API gateway facilitating developer self-service for security configurations, while infrastructure teams maintain centralized control and policy enforcement, ensuring robust protection across a rapidly expanding service ecosystem.
Observability & Debugging
Initially, at the Build stage, the API gateway primarily functions as a basic data source for logs. However, its position as the entry point for all external requests quickly makes it the go-to place for debugging actions. In the Operate and Scale levels, the API gateway evolves into a central monitoring point for key performance indicators (KPIs) such as response times, error rates, and usage patterns. This significantly increases its value by consolidating critical operational insights. The Improve and Adapt phases represent a "featurerich golden path" for observability. This includes providing more comprehensive metrics, enhanced dashboards, and sophisticated error handling capabilities directly through the API gateway. Hans even touches on emerging capabilities like AI-driven anomaly detection and automated Root Cause Analysis (RCA), suggesting these as future frontiers for API gateway observability. This advanced visibility helps platform teams proactively identify and resolve issues, further accelerating development cycles.
Developer & Team Experience
At the Build level, the absence or underutilization of an API gateway often results in ad-hoc, inconsistent ingress patterns, leading to a poor developer experience. The transition to Operate focuses on establishing a repeatable process and standardized patterns for ingress. While this might not immediately translate to a dramatic improvement in developer experience, it lays the groundwork for significant downstream effects. As organizations progress to Scale and Improve, the API gateway becomes instrumental in onboarding internal developers onto a standardized system. The challenge here is striking a balance between offering an "easy button" for common use cases and supporting "power users" who require flexibility for their "special snowflake" services. The Adapt level signifies a state where all ingress-related processes are codified, enabling the API gateway to support diverse teams and their unique requirements effectively, preventing developer friction and fostering efficient deployment workflows.
Governance & Compliance
Governance & Compliance is often a dimension that lags in early maturity, as it typically becomes a pressing concern only when external factors intervene. At the Build level, it might not be a problem at all. However, as an organization scales, external customers or partners may "come knocking," demanding specific compliance features (e.g., geo-blocking, robust API versioning, data residency controls). This often forces a rapid acceleration from level one or two to level four, as seen in the Acme Corp example where an acquisition in a different regulatory environment necessitated a sudden leap in governance. The Scale and Improve phases are characterized by "pendulum swings" between infrastructure teams seeking control and developers pushing for speed. The objective is to codify these requirements, ensuring that despite inherent conflicts, the API gateway is ready to support teams with necessary policies and controls. At the Adapt level, governance is seamlessly integrated, enabling the organization to innovate and grow without leading the API gateway into a state of "utter chaos," proactively managing policies and regulatory adherence.
Hans illustrates these progressions using "Acme Corp" scenarios and radar charts, demonstrating how a two-person startup, a 50-person startup, and a 200-developer machine might display different maturity profiles, emphasizing that a balanced, needs-driven approach is superior to aiming for maximum maturity in every single dimension.
Demo / Proof of Concept
▶ Watch: Inspiration from the CNCF Cloud Native Maturity Model (6:00)
While this talk didn't feature a live technical demonstration of an API gateway in action or a proof of concept for a specific vulnerability, Joel Hans effectively demonstrated the utility and application of the API Gateway Maturity Matrix through illustrative conceptual examples.
His "demo" primarily revolved around the fictional "Acme Corp," presented at various stages of growth: a two-person technical co-founder team, a 50-person startup, and a 200-developer machine. For each stage, Hans utilized radar charts (resembling Pokémon stats, chosen with the help of his daughters) to visually represent Acme Corp's maturity across the five dimensions of the matrix.
For instance, the two-person Acme Corp initially showed deep maturity in Traffic Management and Authentication & Security, reflecting early priorities in getting services online and secure. However, other dimensions like Developer Experience and Governance & Compliance remained at lower levels. As Acme Corp grew to 50 people, the radar chart expanded, indicating progress in areas like Observability (moving past basic logs to structured logs) and Developer Experience (due to automation and infrastructure as code). The charts visually conveyed how organizations prioritize based on immediate needs, such as addressing late responses or error rates by focusing on observability.
The most striking "demonstration" came with the 200-developer Acme Corp, which had acquired another company operating in a different regulatory environment. This scenario dramatically showcased how external factors can force rapid maturity jumps; the governance and compliance dimension shot up from level one or two to level four almost overnight. This effectively illustrated Hans's point that maturity is not a linear, uniform progression but a dynamic process driven by business requirements and the need to find the "next best ROI" for API gateway investments. These visual aids served as a clear and engaging way to demonstrate how the matrix can be used for self-assessment and strategic planning.
Defensive Implications
▶ Watch: Explanation of CNCF Maturity Model levels and dimensions (6:40)
The API Gateway Maturity Matrix offers crucial insights and actionable strategies for defenders, particularly platform engineers, infrastructure teams, and security architects. By providing a structured framework, it helps organizations build more resilient, secure, and manageable API infrastructures.
- Strategic Self-Assessment and Prioritization: Defenders can use the matrix to conduct a thorough self-assessment of their current API gateway implementation. This allows them to identify critical gaps in areas like Authentication & Security, Observability, and Governance. By understanding their current maturity level across each dimension, teams can strategically prioritize investments and feature enablement, focusing on capabilities that offer the highest defensive ROI rather than blindly activating all features. This prevents the "this is fine" scenario of accumulating technical debt and unmanaged complexity.
- Centralized Security Enforcement: The matrix strongly advocates for centralizing authentication and security at the API gateway. Moving essential OAuth services and other authentication methods out of individual services and into the gateway reduces inconsistency, minimizes the attack surface, and simplifies security policy enforcement. This enables the implementation of zero trust fundamentals, ensuring that all API requests are authenticated and authorized at the edge, regardless of the backend service or development team. This standardization acts as an accelerator for developers, as they no longer need to embed security logic, while providing strong, consistent protection.
- Enhanced Observability and Incident Response: An API gateway at higher maturity levels transforms into a powerful defensive tool for observability and debugging. By leveraging the gateway as a central monitoring point for KPIs like response times, error rates, and usage patterns, defenders gain critical insights into the health and security of their APIs. Implementing structured logs, comprehensive metrics, and advanced dashboards directly through the gateway significantly improves the ability to detect anomalies, debug issues, and respond to incidents faster. The potential for AI-driven anomaly detection and automated RCA further strengthens defensive posture by proactively identifying and mitigating threats.
- Codified Governance and Compliance: The matrix underscores the importance of integrating governance and compliance into the API gateway strategy. Defenders can proactively codify policies for API versioning, access control, data handling, and regulatory adherence. This is particularly crucial for organizations operating in diverse regulatory environments or undergoing acquisitions, where rapid shifts in compliance requirements can occur. By embedding these controls into the gateway, teams can enforce consistent policies across all APIs, reducing the risk of non-compliance and ensuring data integrity and privacy.
- Cultivating a Secure Developer Experience: A mature API gateway fosters a developer experience that naturally guides developers towards secure practices. By offering a "golden path" for ingress that includes built-in security, observability, and governance, the API gateway becomes an attractive option for developers. This reduces the likelihood of developers bypassing the gateway or implementing insecure workarounds, effectively making security "the easy way." Balancing "easy button" functionality with support for complex power-user needs ensures that the gateway remains a central, secure component of the development workflow.
In essence, the API Gateway Maturity Matrix empowers defenders to move from reactive firefighting to proactive, strategic security posture management. It provides the clarity needed to make informed decisions about API gateway capabilities, ensuring that this critical "front door" is not only robust and scalable but also a formidable line of defense against evolving threats.
Key Takeaways
- Strategic Self-Assessment is Crucial: The API Gateway Maturity Matrix offers a structured framework for organizations to self-assess their API gateway adoption across five levels (Build, Operate, Scale, Improve, Adapt) and five dimensions (Traffic Management, Auth & Security, Observability, DevEx, Governance & Compliance). This helps identify current strengths and weaknesses, guiding future investments.
- Maturity is About ROI, Not Feature Overload: The goal is not to achieve "level 5 in all things" or enable every possible feature. Instead, maturity involves strategically identifying and prioritizing capabilities that provide the highest return on investment (ROI) for the organization's current problems and business needs, avoiding unnecessary complexity and technical debt.
- Centralize Security for Consistency and Control: Consolidating authentication and security policies on the API gateway is paramount. This approach reduces inconsistency across services, simplifies the implementation of zero trust fundamentals, and protects APIs regardless of their origin, transforming the gateway into an accelerator for development rather than a security bottleneck.
- Leverage for Comprehensive Observability: The API gateway should evolve into a central hub for observability and debugging. Beyond basic logging, it should provide comprehensive metrics, dashboards, and advanced error handling. Future capabilities may include AI-driven anomaly detection and automated Root Cause Analysis (RCA), significantly enhancing operational insights and incident response.
- Foster a Positive Developer Experience: A mature API gateway contributes to a "golden path" for developers, offering an "easy button" for common ingress patterns while still supporting the flexibility required by "power users." This balance encourages consistent adoption, standardizes deployment, and streamlines the development workflow.
- Integrate Governance and Compliance Proactively: Governance and compliance often become critical rapidly due to external factors like customer demands or acquisitions. Integrating codified policies for API versioning, access control, and regulatory adherence into the API gateway architecture is vital for scaling effectively and preventing chaos, ensuring control as the organization grows.
About the Speaker(s)
Joel Hans is a Developer Advocate at ngrok. He is known for his passion for storytelling and uses this skill to demystify complex technical concepts and challenges. His background includes a significant contribution to the CNCF Cloud Native Maturity Model, for which he took notes and wrote a report for the CNCF's end-user community. This experience directly inspired his work on the API Gateway Maturity Matrix, as he sought to create a more focused, tactical model for a specific piece of technology. Hans is a strong proponent of community involvement and open-source collaboration, actively encouraging audience members to contribute to and refine the API Gateway Maturity Matrix project on GitHub. This KubeCon EU presentation marked his first talk of this particular kind, highlighting his dedication to sharing knowledge and fostering collective improvement within the cloud-native community.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Joel Hans from ngrok delivered a surprisingly substantive framework with his API Gateway Maturity Matrix. Despite being a vendor talk, it largely avoids marketing fluff, offering a genuinely actionable tool for platform engineers and CTOs to assess and strategically evolve their API gateway implementations. The matrix provides a clear roadmap for prioritizing features, centralizing security, and improving developer experience, making it a valuable resource for anyone grappling with API ingress chaos. Its strength lies in its practical impact and structured approach to a common, complex problem.
Heather Calloway (CISO) — STRONG ACCEPT
Joel Hans's API Gateway Maturity Matrix provides a highly practical and relevant framework for assessing and strategically managing an organization's API gateway implementation. It effectively bridges the gap between technical capabilities and critical business concerns like security, governance, and developer experience, making it an invaluable tool for CISOs and platform leaders to prioritize investments and clarify risk ownership at a fundamental control point of the business.