Key Concepts:
- Open API Specification: A standard format for describing APIs, enabling machine-readable API definitions.
- F5 API Security Platform: A suite of tools for discovering, securing, and managing APIs.
- NGINX API Gateway: A high-performance API gateway for managing and securing API traffic.
- CI/CD Pipeline: An automated process for building, testing, and deploying software.
- Distributed Cloud Services: F5's platform for managing and securing applications across multiple cloud environments.
- GitHub Actions: A CI/CD platform integrated with GitHub repositories.
- NGINX One (nginx1): A management plane for NGINX instances, including API Gateways.
Deployment of Open API Specification to NGINX API Gateway via CI/CD
This demo showcases how to automate the deployment of Open API specifications, learned by F5's API Security Platform, to an NGINX API Gateway using a CI/CD pipeline. The core idea is to leverage the API discovery capabilities of F5's platform and integrate the resulting specifications into the API Gateway configuration process.
1. API Discovery and Specification Generation:
- The F5 API Security Platform discovers APIs through various methods:
- Dev-time code scanning
- Runtime traffic analysis
- Threat surface mapping with crawlers
- Combination of the above
- The discovery process generates an Open API specification based on the learned data.
- This specification is stored and versioned in F5 Distributed Cloud Services.
2. GitHub Actions Workflow:
- A GitHub Actions workflow automates the process of retrieving the Open API specification and deploying it to the NGINX API Gateway.
- The workflow programmatically pulls the specification from Distributed Cloud Services.
- It converts the specification to the format expected by NGINX.
- It deploys the converted specification to the API Gateway via NGINX One (nginx1).
3. Configuration and Parameters:
- The workflow requires specific parameters:
- Distributed Cloud API token
- Tenant name
- Namespace
- Specification name
- Specification version
- NGINX API Gateway instance ID (from NGINX One)
4. Deployment Process:
- Clone the repository containing the GitHub Actions workflow to a local machine.
- Create a new deployment branch as defined in the workflow.
- Create a version file (presumably containing version information for the deployment).
- Add, commit, and push the changes to the GitHub repository.
5. Monitoring and Verification:
- Monitor the deployment progress in GitHub Actions.
- Upon successful completion of the pipeline, verify the configuration deployment in the NGINX One UI.
6. NGINX One UI Verification:
- The NGINX One UI confirms that the Open API specification has been successfully deployed to the NGINX API Gateway instance.
Conclusion:
The demo illustrates a streamlined approach to managing Open API specifications using CI/CD practices and the F5 product portfolio. By automating the deployment of specifications learned by the F5 API Security Platform to an NGINX API Gateway, organizations can improve API security, governance, and efficiency. The integration leverages GitHub Actions and NGINX One to provide a complete and automated solution.
AI summaries can miss context or contain errors. Check important details against the original video.





