Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
  1. Home
  2. Blog
  3. Enterprise
  4. Considerations for Deploying a Multi-Cloud Architecture with Kong Gateway, Kuma Service Mesh and Aviatrix
Enterprise
December 18, 2020
3 min read

Considerations for Deploying a Multi-Cloud Architecture with Kong Gateway, Kuma Service Mesh and Aviatrix

Kong
Topics
Multi CloudKong GatewayMulti Cloud
Share on Social

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo

Introduction

Building a multi-region or multi-cloud environment for your applications requires a lot of attention.

In a typical deployment, you would have an API gateway running close to the several application runtimes. You should enhance your deployment to support different regions in a given cloud, or in an even more distributed and hybrid scenario, multiple services running across other public clouds and on-premise environments.

The task gets even more challenging when we consider service mesh-based applications implementing canary releases, A/B testings, blue-green deployments, etc. Moreover, a zero-trust network requirement for distributed environments should be considered mandatory.

1. Architecting a Global, Multi-Cloud Transit Network

From the networking perspective, the multi-cloud environment should address critical requirements. For example, it should:

  • Be scalable and not require redesign or have scaling impact when it adds/removes new VPC/VNets. As such, it should avoid direct VPC/VNet peering and use a hub-and-spoke-based transit architecture.
  • Support various communication requirements, including public and private IPs, direct peering with two clouds, etc.
  • Provide a scalable networking capability to be consumed by all application components, including the API gateway and service mesh.
  • Assist additional network services, like next-gen firewall (NGFW), IPS, IDS, DPI, etc., that one can insert transparently without re-architecting any aspect of the deployment or changing the application.

In summary, we recommend pursuing three key attributes:

  1. Networking: A repeatable architecture, be it single cloud or multi-cloud
  2. Security: Flexible network architecture to implement connections across different security domains/zones
  3. Operations: Visibility, control and troubleshooting capabilities that don't require in-depth cloud knowledge

Aviatrix provides complete and easy-to-manage connectivity solutions to support all typical networking requirements for single cloud and multi-cloud application development.

2. Implementing Microservice-Based Application Topologies

From the distributed application perspective, you should consider and address all topics listed above. Furthermore, all the necessary networking connectivity requirements should be in place already so you can implement all diverse topologies on top of the multi-region/multi-cloud platform.

Among these topologies and architecture, we could mention:

  • A distributed service mesh deployment with microservices running on different clouds
  • API gateway implementing a single point of contact to microservices running on different environments and all sorts of runtimes like Linux, Docker, Kubernetes, etc.
  • Distributed API gateway layer having a control plane running on a cloud and multiple data planes across different environments and clouds

3. Referencing Architecture Layers

Kong provides technologies to implement both layers in enterprise architecture:

  • Kong API gateway: For multi-cloud and hybrid, optimized for microservices and distributed architectures
  • Kuma: A service mesh implementation for distributed service connectivity

The following picture describes a reference architecture:

Notice the reference architecture focuses on the communication between the service mesh components from the application perspective only.

With the extensible list of networking requirements listed above, we recommend implementing a multi-cloud deployment with a combination of both companies' technologies. The picture below describes an example of a hybrid application platform:

While Kong and Kuma are implementing an application platform composed of both an API gateway and service mesh, Aviatrix solves all networking connectivity idiosyncrasies across multiple clouds.

4. Controlling Your Architecture with Kong and Aviatrix

A multi-region/multi-cloud application platform implementation must deal with multiple abstraction layers, including different network infrastructure and services running across multiple runtimes.

The synergistic use of network support technologies provided by Aviatrix, combined with products designed for cloud environments provided by Kong, allows architects to create topologies for their applications to address their technical and business requirements. In other words, customers conduct the technological decision-making process for the application architecture design. The products used must support the process and not the other way around.

Topics
Multi CloudKong GatewayMulti Cloud
Share on Social
Kong

Recommended posts

The Open Banking Revolution: What it Means for Consumers and Businesses

Kong Logo
EnterpriseJuly 5, 2022

Open banking initiatives have taken flight in many economies across the globe. Predicated on the open access of banking data for the overall benefit of customer choice, Open Banking comes with many challenges — security not the least of them.  Givin

Brad Drysdale

On Connectivity and Conflict: Part 2

Kong Logo
EnterpriseJanuary 14, 2022

In Part 1 of this blog series , I broke down the "two generals problem" and shared how it affects IT leaders today. In this post, I will share the details of a specific battle from more modern history that exemplifies this concept. "Yeah, this clou

Ahmed Koshok

On Connectivity and Conflict

Kong Logo
EnterpriseJanuary 12, 2022

The Two Generals' Problem is a well-known thought experiment about how asynchronous - and potentially unreliable - communications can cause, shall we say, issues. [iframe src="" data-src="https://www.youtube.com/embed//xFMUFq8kC98" frameborder="0

Ahmed Koshok

Agentic AI Adoption Soars, Tech Job Growth Stalls, Study Shows

Kong Logo
EnterpriseSeptember 17, 2025

How is agentic AI impacting the enterprise and the workforce? New research looks at agentic adoption and potential impacts The promise of agentic AI is huge. But how is it impacting the enterprise and the developers and IT professionals most likely

Amit Dey

API Management as a Central Security Hub

Kong Logo
EnterpriseSeptember 11, 2025

While many organizations mistakenly believe a single tool can solve all their API security woes, the truth is far more complex. This blog post will dismantle the myth of the "silver bullet" and demonstrate how a comprehensive, defense-in-depth strat

Veena Rajarathna

You Might Be Doing API-First Wrong, New Analyst Research Suggests

Kong Logo
EnterpriseSeptember 3, 2025

Ever feel like you're fighting an uphill battle with your API strategy? You're building APIs faster than ever, but somehow everything feels harder. Wasn’t  API-first  supposed to make all this easier?  Well, you're not alone. And now industry analys

Heather Halenbeck

Announcing terraform-provider-konnect v3

Kong Logo
Product ReleasesAugust 22, 2025

It’s been almost a year since we released our  Konnect Terraform provider . In that time we’ve seen over 300,000 installs, have 1.7 times as many resources available, and have expanded the provider to include data sources to enable federated managem

Michael Heap

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

Platform
Kong KonnectKong GatewayKong AI GatewayKong InsomniaDeveloper PortalGateway ManagerCloud GatewayGet a Demo
Explore More
Open Banking API SolutionsAPI Governance SolutionsIstio API Gateway IntegrationKubernetes API ManagementAPI Gateway: Build vs BuyKong vs PostmanKong vs MuleSoftKong vs Apigee
Documentation
Kong Konnect DocsKong Gateway DocsKong Mesh DocsKong AI GatewayKong Insomnia DocsKong Plugin Hub
Open Source
Kong GatewayKumaInsomniaKong Community
Company
About KongCustomersCareersPressEventsContactPricing
  • Terms•
  • Privacy•
  • Trust and Compliance•
  • © Kong Inc. 2025