Home / Companies / Apollo / Blog / Post Details
Content Deep Dive

Securing Apollo Federation Subgraphs: Context and Best Practices

Blog post from Apollo

Post Details
Company
Date Published
Author
David Walter
Word Count
751
Company Posts That Month
5
Language
English
Hacker News Points
-
Post removed?
No
Summary

Securing Apollo Federation subgraphs is critical to maintaining a robust security framework as AI tools increasingly expose vulnerabilities in publicly accessible services. The architectural design of Apollo Federation dictates that subgraphs remain internal services accessed only through a central router, which serves as the core point for security enforcement by providing access control, demand management, and operation safelisting. This internal-only access is crucial to prevent bypassing security measures and exposing sensitive coordination mechanisms. Key security practices include keeping subgraphs inaccessible from the public internet, disabling introspection in production, and implementing authentication and authorization at the router level. Additional measures such as data validation, pagination, setting operation limits, and monitoring through observability tools are recommended to safeguard the infrastructure. The overarching principle is that subgraphs must only be accessed via the router to enable centralized governance and protect against potential API sprawl and exploitation.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 3 2,104 424 141 -21%
OpenTelemetry 1 269 57 34 -21%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.