Just spun up API Shield on my edge k3s cluster. The schema validation and mTLS for APIs seem solid on paper. But I'm trying to figure out if it's actually useful beyond the basic WAF rules I already have.
I've been testing it with a simple Knative service. The automatic mTLS certificate provisioning is neat, but the real value feels like it's in the schema enforcement. Anyone actually using it in a GitOps flow? I'm curious about the operational overhead vs. just using Istio's RequestAuthentication and AuthorizationPolicy at the service mesh layer.
```yaml
# Example of the kind of Istio policy I might replace?
apiVersion: security.istio.io/v1beta1
kind: RequestAuthentication
metadata:
name: jwt-auth
spec:
selector:
matchLabels:
app: my-api
jwtRules:
- issuer: "https://securetoken.google.com/my-project"
jwksUri: "https://www.googleapis.com/service_accounts/v1/jwk/[email protected]"
```
Is API Shield's schema validation catching anything that a good OpenAPI spec lint in CI wouldn't? 🤔
yaml all the things
Oh, the "automatic mTLS certificate provisioning is neat" line got me. That's how they get you. It's neat right up until you need to debug why an internal service suddenly can't talk to another because of a silently rotated cert. Now you've got two layers of mTLS - one at the mesh (Istio) and one at the edge (API Shield). Which one failed? Enjoy the extra hop in your troubleshooting loop.
> Is API Shield's schema validation catching anything that a good OpenAPI spec lint in CI wouldn't?
Probably not. It's runtime validation duplicating build-time validation. Unless your threat model includes malicious developers committing bad OpenAPI specs, you're just moving the same check to a different, more expensive, and more opaque layer. Your CI lint gives you a clear reject in a PR; this gives you a 4xx at runtime and a log entry somewhere in your edge logging sink. Which is easier to triage?
If you already have Istio policies and a WAF, you're layering on complexity for a feature that feels designed for teams who don't have a service mesh or a proper GitOps CI pipeline. It's a checkbox for the "we need API security" slide.
monoliths are not evil