API lifecycle control

DevPortal

Turn API intent into governed, versioned and observable gateway delivery.

OpenAPI-first
Contract admission
GitOps-native
Auditable changes
Gateway-aware
Kong and Gloo

The product

One operating model for every API change.

DevPortal gives producers, consumers and platform teams a shared workflow without collapsing their responsibilities into one service.

Every request is admitted against ownership, policy and gateway capabilities before it can create infrastructure change.

Lifecycle

Intent becomes evidence.

Each stage produces a durable result that can be inspected, approved and replayed.

  1. 01

    Define

    OpenAPI contract, exposure target and policy intent.

  2. 02

    Validate

    Ownership, semantics, secret references and provider capabilities.

  3. 03

    Approve

    Policy gates and production decisions remain explicit.

  4. 04

    Deliver

    Versioned manifests flow through GitLab and Argo CD.

  5. 05

    Operate

    Health, drift, events and rollback stay observable.

Composable architecture

Deploy only the control planes you need.

01

Portal API

The product and consumer control plane.

  • Application and managed identity registration
  • API validation, publication, promotion and rollback
  • Subscriptions, credentials and policy waivers
  • Durable Operations and audit evidence
02

Portal Operator

The gateway fleet control plane.

  • Compatibility preview before provisioning
  • Gateway deployment or adoption
  • GitOps reconciliation and drift inspection
  • Zone-level lifecycle and decommissioning

Independent by design. Portal API remains useful without gateway provisioning. Portal Operator can be introduced when the platform is ready to manage gateway instances.

Provider-aware delivery

A portable intent, a faithful target.

CapabilityKongGloo Gateway
RoutingGateway API and Kong resourcesGateway API and Gloo policies
Traffic policyOSS and Enterprise-aware pluginsTrafficPolicy materialization
ProvisioningDeploy or adopt Kong instancesDeploy or adopt Gloo instances
SafetyReject unsupported semanticsReject unsupported semantics

Operational outcomes

Built for change, recovery and proof.

Version every publication

Restore a known successful API version without reconstructing intent.

See execution, not just status

Follow validation, merge requests, resources, reconciliation and events.

Keep secrets out of contracts

Use managed references while Keycloak enforces tenant-aware access.

A controlled path to production

Make API delivery repeatable without making it opaque.

Return to overview