SlideShare a Scribd company logo
[13-08-2022]
[Kochi] MuleSoft Meetup Group
API Governance
Safe Harbour Statement
● Both the speaker and the host are organizing this meet-up in individual capacity only. We are
not representing our companies here.
● This presentation is strictly for learning purposes only. Organizer/Presenter do not hold any
responsibility that same solution will work for your business requirements.
● This presentation is not meant for any promotional activities.
2
A recording of this meetup will be uploaded to events page within 24 hours.
Questions can be submitted/asked at any time in the Chat/Questions & Answers Tab.
Make it more Interactive!!!
Give us feedback! Rate this meetup session by filling feedback form at the end of the day.
We Love Feedbacks!!! Its Bread & Butter for Meetup.
Housekeeping
3
4
Organizers
⮚ 6+ Years of Experience in Integrations and API Technologies.
⮚ Certified Delivery champion MuleSoft Developer, Integration Architect
and platform Architect
⮚ 8+ Years of Experience in Integrations and API Technologies.
⮚ Certified MuleSoft Developer, Integration Architect and platform Architect.
⮚ MuleSoft Delivery Champion completed
⮚ Senior MuleSoft Developer | Integration Lead
⮚ 11+ years of Integration Experience Certified
Mulesoft Developer, Certified Mulesoft Platform
Architect
5
Speakers
Supriya Pawar
Integration Architect at
Accenture
About the Speaker:
⮚ Having 7+ years of overall experience building integration solutions.
⮚ Certified MuleSoft Developer And Architect.
About the Speaker:
⮚ 8+ Years of Experience in Integrations and API
Technologies.
⮚ Certified MuleSoft Developer, Integration Architect and
platform Architect.
⮚ MuleSoft Delivery Champion completed
Deepak Talluri
Technical Team lead
at Accenture
Agenda
API Governance Overview
What is API Governance?
01
Highs and Lows of API Governance
Benefits
05
Create Governance Profiles, Default Rule Sets, Dashboards/ Reports/
Notifications
Demo
04
Profiles, Rulesets, API Conformance, Identify APIs to govern, Adding
Asset Tags, Categories in Exchange
What’s new with API Governance on AnyPoint Platform?
02
Rulesets, Profiles, Conformance, Notifications
API Governance Key Facts
03
What is API Governance?
API governance is the practice of applying common rules and guardrails relating to API standards and security policies to your APIs.
These rules are applied through checks and validations.
• The goal of API governance is to ensure proper standardization of your APIs so that they are complete, compliant, and consistent,
and therefore easily discoverable and reusable.
API
Governance
API
Guidelines
API
Security
API Best
Practices
What’s New with API Governance
on Anypoint Platform?
Anypoint API Governance is a component of the Anypoint Platform that enables you to apply governance rules to your APIs as part of the API
lifecycle.
API Governance helps you improve your organization’s API quality by enabling you to identify conformance issues and take steps to resolve
them.
01
Publish governance rulesets in
Anypoint Exchange to share with
other developers.
Share governance best practices 02
Enable developers to apply governance
rulesets at design time in Anypoint API
Designer.
Apply consistent rules at design time
03
Automatically apply standards to
your API contract and definition
within your CI/CD pipeline.
Enforce governance within your
DevOps organization
API Governance Concepts
Governance Profiles
A governance profile applies chosen governance rulesets to a
select group of APIs. The API definitions are validated against
the governance rulesets.
• A governance profile has two statuses, Normal and At Risk,
which are based on the percentage of conformant APIs in the
governance profile.
At Risk: Less than 70% of APIs are conformant
Normal: More than 70% of APIs are conformant
Governance Rulesets
Governance rulesets are collections of rules, or
guidelines, that can be applied over the metadata
extracted from any REST API definition in the Anypoint
Platform.
• Few Examples - Internal and External best practice
guidelines - Naming conventions, Industry Specific
government standards, such as making sure your
APIs carrying sensitive data are encrypted (HTTPS).
API Conformance
API conformance indicates whether a validated API
definition passes all the required rules in one or more
governance rulesets.
 If an API definition is included in multiple governance
profiles, it must pass all the rulesets in all those profiles
to be conformant.
Note: API Conformance applies only to API Definitions that are
published in Exchange as REST APIs
Nonconformance Severity
Nonconformance severity is categorized by percentage of
passed rulesets among all required rulesets.
High Severity - 0 - 40% rulesets
passed
Medium Severity - 41% - 80% rulesets
passed
Low Severity - 81% - 99% rulesets
passed
API Governance Screenshots
1. New Tab in
Anypoint
Platform
2. Steps to create Governance
Profile
API Governance Key Facts
 These are collections of rules, or guidelines, that can be applied over
the metadata extracted from any REST API definition in the Anypoint
Platform.
 E.g: internal and external best practice guidelines, such as naming
conventions, and industry-specific government standards, such as
making sure your APIs carrying sensitive data are encrypted (HTTPS).
 Custom rulesets can be created as well and used in profiles.
 API developers or architects can apply the governance rulesets directly
to API definitions as dependencies in API Designer during the API
design phase.
 Multiple profiles can be created depending on the category of APIs.
 If an API definition is included in multiple governance profiles, it must
pass all the rulesets in all of those profiles to be conformant.
Rulesets
Profiles
API Governance Key Facts
Conformance
 The API definitions are validated against the governance rulesets and
conformance is calculated.
 API conformance applies only to API definitions that are published in
Exchange as REST APIs.
 APIs with >70% conformance are treated as “Normal"
 APIs with <70% conformance are treated as “At Risk”
 APIs are validated if they are identified by the selection criteria of at
least one of the governance profiles.
 API conformance indicates whether a validated API definition passes
all the required rules in one or more governance rulesets.
Notification
 API Owner will be notified about the Conformance of the API
 Conformance report with violations can be emailed to stake holders.
 Same report can be exported to excel
Demo
Consistency
in API specs
and the
standards
across the
platform
High Security
assured by
minimizing
risks
highlighted
by OWASP
High Quality
assured with
Anypoint Best
Practices
rules
Allows
developers to
ensure APIs
are in
conformance
at design
time
CI/CD
compatible
• Adds performance
overhead, but this
could overcome by
following design &
development best
practices
Low
Highs/Benefits
API Governance - Benefits
https://owasp.org/Top10/
https://spec.openapis.org/oas/latest.html
https://blogs.mulesoft.com/api-integration/strategy/4-ps-of-api-governance/
https://docs.mulesoft.com/api-governance/
Reference Links
Quiz Time
Introduce yourself to your neighbor
Networking Time
Thank You

More Related Content

Similar to MuleSoft_Meetup__Official_August-2022.pptx

What is APIGEE? What are the benefits of APIGEE?
What is APIGEE? What are the benefits of APIGEE?What is APIGEE? What are the benefits of APIGEE?
What is APIGEE? What are the benefits of APIGEE?
IQ Online Training
 
Gravitee API Management - Ahmet AYDIN
 Gravitee API Management  -  Ahmet AYDIN Gravitee API Management  -  Ahmet AYDIN
Gravitee API Management - Ahmet AYDIN
kloia
 
Do you know How to Effectively Test APIs.pdf
Do you know How to Effectively Test APIs.pdfDo you know How to Effectively Test APIs.pdf
Do you know How to Effectively Test APIs.pdf
AmeliaJonas2
 
Mule esb api layer
Mule esb api layerMule esb api layer
Mule esb api layer
Anand kalla
 
Mule esb api layer
Mule esb api layerMule esb api layer
Mule esb api layer
Khasim Saheb
 
Mule esb api layer
Mule esb api layerMule esb api layer
Mule esb api layer
Sunil Komarapu
 
Api Layer
Api LayerApi Layer
Api Layer
Mohammed246
 
What is Apigee.pdf
What is Apigee.pdfWhat is Apigee.pdf
What is Apigee.pdf
VishnuGone
 
WSO2 API Platform: Vision and Roadmap
WSO2 API Platform: Vision and RoadmapWSO2 API Platform: Vision and Roadmap
WSO2 API Platform: Vision and Roadmap
WSO2
 
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
Sumanth Donthi
 
API Economy - Cuomo
API Economy - Cuomo API Economy - Cuomo
API Economy - Cuomo
Prolifics
 
API Management Platform Technical Evaluation Framework
API Management Platform Technical Evaluation FrameworkAPI Management Platform Technical Evaluation Framework
API Management Platform Technical Evaluation Framework
WSO2
 
API Governance in the Enterprise
API Governance in the EnterpriseAPI Governance in the Enterprise
API Governance in the Enterprise
Apigee | Google Cloud
 
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoicaapidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
apidays
 
APIs in the Enterprise - Lessons Learned
APIs in the Enterprise - Lessons Learned APIs in the Enterprise - Lessons Learned
APIs in the Enterprise - Lessons Learned
Apigee | Google Cloud
 
Top 20 API Testing Interview Questions.pdf
Top 20 API Testing Interview Questions.pdfTop 20 API Testing Interview Questions.pdf
Top 20 API Testing Interview Questions.pdf
AnanthReddy38
 
B7 api management_enabling_digital_transformation
B7 api management_enabling_digital_transformationB7 api management_enabling_digital_transformation
B7 api management_enabling_digital_transformation
Dr. Wilfred Lin (Ph.D.)
 
Mule api
Mule  apiMule  api
Mule api
himajareddys
 
Mule api
Mule  apiMule  api
Mule api
D.Rajesh Kumar
 
Lessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API PlatformLessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API Platform
LaunchAny
 

Similar to MuleSoft_Meetup__Official_August-2022.pptx (20)

What is APIGEE? What are the benefits of APIGEE?
What is APIGEE? What are the benefits of APIGEE?What is APIGEE? What are the benefits of APIGEE?
What is APIGEE? What are the benefits of APIGEE?
 
Gravitee API Management - Ahmet AYDIN
 Gravitee API Management  -  Ahmet AYDIN Gravitee API Management  -  Ahmet AYDIN
Gravitee API Management - Ahmet AYDIN
 
Do you know How to Effectively Test APIs.pdf
Do you know How to Effectively Test APIs.pdfDo you know How to Effectively Test APIs.pdf
Do you know How to Effectively Test APIs.pdf
 
Mule esb api layer
Mule esb api layerMule esb api layer
Mule esb api layer
 
Mule esb api layer
Mule esb api layerMule esb api layer
Mule esb api layer
 
Mule esb api layer
Mule esb api layerMule esb api layer
Mule esb api layer
 
Api Layer
Api LayerApi Layer
Api Layer
 
What is Apigee.pdf
What is Apigee.pdfWhat is Apigee.pdf
What is Apigee.pdf
 
WSO2 API Platform: Vision and Roadmap
WSO2 API Platform: Vision and RoadmapWSO2 API Platform: Vision and Roadmap
WSO2 API Platform: Vision and Roadmap
 
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
API Governance and GitOps in Hybrid Integration Platform (MuleSoft)
 
API Economy - Cuomo
API Economy - Cuomo API Economy - Cuomo
API Economy - Cuomo
 
API Management Platform Technical Evaluation Framework
API Management Platform Technical Evaluation FrameworkAPI Management Platform Technical Evaluation Framework
API Management Platform Technical Evaluation Framework
 
API Governance in the Enterprise
API Governance in the EnterpriseAPI Governance in the Enterprise
API Governance in the Enterprise
 
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoicaapidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
apidays LIVE LONDON - API Standards and Governance Platform by Nicoleta Stoica
 
APIs in the Enterprise - Lessons Learned
APIs in the Enterprise - Lessons Learned APIs in the Enterprise - Lessons Learned
APIs in the Enterprise - Lessons Learned
 
Top 20 API Testing Interview Questions.pdf
Top 20 API Testing Interview Questions.pdfTop 20 API Testing Interview Questions.pdf
Top 20 API Testing Interview Questions.pdf
 
B7 api management_enabling_digital_transformation
B7 api management_enabling_digital_transformationB7 api management_enabling_digital_transformation
B7 api management_enabling_digital_transformation
 
Mule api
Mule  apiMule  api
Mule api
 
Mule api
Mule  apiMule  api
Mule api
 
Lessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API PlatformLessons in Transforming the Enterprise to an API Platform
Lessons in Transforming the Enterprise to an API Platform
 

Recently uploaded

The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
Laura Byrne
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
Product School
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Inflectra
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
Alison B. Lowndes
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
Ana-Maria Mihalceanu
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
OnBoard
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
Guy Korland
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
Product School
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Thierry Lestable
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
Prayukth K V
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
Thijs Feryn
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
UiPathCommunity
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
DianaGray10
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
Paul Groth
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
g2nightmarescribd
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
James Anderson
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
DanBrown980551
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance
 

Recently uploaded (20)

The Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and SalesThe Art of the Pitch: WordPress Relationships and Sales
The Art of the Pitch: WordPress Relationships and Sales
 
How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...How world-class product teams are winning in the AI era by CEO and Founder, P...
How world-class product teams are winning in the AI era by CEO and Founder, P...
 
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered QualitySoftware Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
Software Delivery At the Speed of AI: Inflectra Invests In AI-Powered Quality
 
Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........Bits & Pixels using AI for Good.........
Bits & Pixels using AI for Good.........
 
Monitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR EventsMonitoring Java Application Security with JDK Tools and JFR Events
Monitoring Java Application Security with JDK Tools and JFR Events
 
Leading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdfLeading Change strategies and insights for effective change management pdf 1.pdf
Leading Change strategies and insights for effective change management pdf 1.pdf
 
GraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge GraphGraphRAG is All You need? LLM & Knowledge Graph
GraphRAG is All You need? LLM & Knowledge Graph
 
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
From Daily Decisions to Bottom Line: Connecting Product Work to Revenue by VP...
 
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
Empowering NextGen Mobility via Large Action Model Infrastructure (LAMI): pav...
 
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 previewState of ICS and IoT Cyber Threat Landscape Report 2024 preview
State of ICS and IoT Cyber Threat Landscape Report 2024 preview
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
Connector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a buttonConnector Corner: Automate dynamic content and events by pushing a button
Connector Corner: Automate dynamic content and events by pushing a button
 
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMsTo Graph or Not to Graph Knowledge Graph Architectures and LLMs
To Graph or Not to Graph Knowledge Graph Architectures and LLMs
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
FIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdfFIDO Alliance Osaka Seminar: Overview.pdf
FIDO Alliance Osaka Seminar: Overview.pdf
 
Generating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using SmithyGenerating a custom Ruby SDK for your web service or Rails API using Smithy
Generating a custom Ruby SDK for your web service or Rails API using Smithy
 
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
GDG Cloud Southlake #33: Boule & Rebala: Effective AppSec in SDLC using Deplo...
 
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
LF Energy Webinar: Electrical Grid Modelling and Simulation Through PowSyBl -...
 
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdfFIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
FIDO Alliance Osaka Seminar: Passkeys and the Road Ahead.pdf
 

MuleSoft_Meetup__Official_August-2022.pptx

  • 2. Safe Harbour Statement ● Both the speaker and the host are organizing this meet-up in individual capacity only. We are not representing our companies here. ● This presentation is strictly for learning purposes only. Organizer/Presenter do not hold any responsibility that same solution will work for your business requirements. ● This presentation is not meant for any promotional activities. 2
  • 3. A recording of this meetup will be uploaded to events page within 24 hours. Questions can be submitted/asked at any time in the Chat/Questions & Answers Tab. Make it more Interactive!!! Give us feedback! Rate this meetup session by filling feedback form at the end of the day. We Love Feedbacks!!! Its Bread & Butter for Meetup. Housekeeping 3
  • 4. 4 Organizers ⮚ 6+ Years of Experience in Integrations and API Technologies. ⮚ Certified Delivery champion MuleSoft Developer, Integration Architect and platform Architect ⮚ 8+ Years of Experience in Integrations and API Technologies. ⮚ Certified MuleSoft Developer, Integration Architect and platform Architect. ⮚ MuleSoft Delivery Champion completed ⮚ Senior MuleSoft Developer | Integration Lead ⮚ 11+ years of Integration Experience Certified Mulesoft Developer, Certified Mulesoft Platform Architect
  • 5. 5 Speakers Supriya Pawar Integration Architect at Accenture About the Speaker: ⮚ Having 7+ years of overall experience building integration solutions. ⮚ Certified MuleSoft Developer And Architect. About the Speaker: ⮚ 8+ Years of Experience in Integrations and API Technologies. ⮚ Certified MuleSoft Developer, Integration Architect and platform Architect. ⮚ MuleSoft Delivery Champion completed Deepak Talluri Technical Team lead at Accenture
  • 6. Agenda API Governance Overview What is API Governance? 01 Highs and Lows of API Governance Benefits 05 Create Governance Profiles, Default Rule Sets, Dashboards/ Reports/ Notifications Demo 04 Profiles, Rulesets, API Conformance, Identify APIs to govern, Adding Asset Tags, Categories in Exchange What’s new with API Governance on AnyPoint Platform? 02 Rulesets, Profiles, Conformance, Notifications API Governance Key Facts 03
  • 7. What is API Governance? API governance is the practice of applying common rules and guardrails relating to API standards and security policies to your APIs. These rules are applied through checks and validations. • The goal of API governance is to ensure proper standardization of your APIs so that they are complete, compliant, and consistent, and therefore easily discoverable and reusable. API Governance API Guidelines API Security API Best Practices
  • 8. What’s New with API Governance on Anypoint Platform? Anypoint API Governance is a component of the Anypoint Platform that enables you to apply governance rules to your APIs as part of the API lifecycle. API Governance helps you improve your organization’s API quality by enabling you to identify conformance issues and take steps to resolve them. 01 Publish governance rulesets in Anypoint Exchange to share with other developers. Share governance best practices 02 Enable developers to apply governance rulesets at design time in Anypoint API Designer. Apply consistent rules at design time 03 Automatically apply standards to your API contract and definition within your CI/CD pipeline. Enforce governance within your DevOps organization
  • 9. API Governance Concepts Governance Profiles A governance profile applies chosen governance rulesets to a select group of APIs. The API definitions are validated against the governance rulesets. • A governance profile has two statuses, Normal and At Risk, which are based on the percentage of conformant APIs in the governance profile. At Risk: Less than 70% of APIs are conformant Normal: More than 70% of APIs are conformant Governance Rulesets Governance rulesets are collections of rules, or guidelines, that can be applied over the metadata extracted from any REST API definition in the Anypoint Platform. • Few Examples - Internal and External best practice guidelines - Naming conventions, Industry Specific government standards, such as making sure your APIs carrying sensitive data are encrypted (HTTPS). API Conformance API conformance indicates whether a validated API definition passes all the required rules in one or more governance rulesets.  If an API definition is included in multiple governance profiles, it must pass all the rulesets in all those profiles to be conformant. Note: API Conformance applies only to API Definitions that are published in Exchange as REST APIs Nonconformance Severity Nonconformance severity is categorized by percentage of passed rulesets among all required rulesets. High Severity - 0 - 40% rulesets passed Medium Severity - 41% - 80% rulesets passed Low Severity - 81% - 99% rulesets passed
  • 10. API Governance Screenshots 1. New Tab in Anypoint Platform 2. Steps to create Governance Profile
  • 11. API Governance Key Facts  These are collections of rules, or guidelines, that can be applied over the metadata extracted from any REST API definition in the Anypoint Platform.  E.g: internal and external best practice guidelines, such as naming conventions, and industry-specific government standards, such as making sure your APIs carrying sensitive data are encrypted (HTTPS).  Custom rulesets can be created as well and used in profiles.  API developers or architects can apply the governance rulesets directly to API definitions as dependencies in API Designer during the API design phase.  Multiple profiles can be created depending on the category of APIs.  If an API definition is included in multiple governance profiles, it must pass all the rulesets in all of those profiles to be conformant. Rulesets Profiles
  • 12. API Governance Key Facts Conformance  The API definitions are validated against the governance rulesets and conformance is calculated.  API conformance applies only to API definitions that are published in Exchange as REST APIs.  APIs with >70% conformance are treated as “Normal"  APIs with <70% conformance are treated as “At Risk”  APIs are validated if they are identified by the selection criteria of at least one of the governance profiles.  API conformance indicates whether a validated API definition passes all the required rules in one or more governance rulesets. Notification  API Owner will be notified about the Conformance of the API  Conformance report with violations can be emailed to stake holders.  Same report can be exported to excel
  • 13. Demo
  • 14. Consistency in API specs and the standards across the platform High Security assured by minimizing risks highlighted by OWASP High Quality assured with Anypoint Best Practices rules Allows developers to ensure APIs are in conformance at design time CI/CD compatible • Adds performance overhead, but this could overcome by following design & development best practices Low Highs/Benefits API Governance - Benefits
  • 17. Introduce yourself to your neighbor Networking Time