CVE commitment
Keep the APIs running while the platform under them changes.
Independent support for open-source 3scale API Management
Keep your 3scale platform secure and running through Red Hat's end-of-life period, and plan your next move without pressure. APIcast, Porta, Apisonator and Zync under support, and a migration path to a maintained gateway when you choose.
- 3scale APIcast
- 3scale Porta
- 3scale Apisonator
- 3scale Zync
- Kuadrant
- Kong
- Apache APISIX
- Gravitee
The technologies we cover
Products in this family

APIcast gateway
The NGINX and OpenResty gateway of 3scale: configuration, custom policies in Lua, performance tuning, standalone and self-managed deployments.
OpenShiftKubernetesBare metalAir-gappedOfficial support

Porta (admin and developer portal)
The Rails application behind the admin console and the developer portal: upgrades, portal customisation, account and plan management, SSO and OIDC integration.
OpenShiftKubernetesOfficial support

Apisonator (backend)
The rate-limiting and analytics backend: limits and quotas, usage analytics, Redis sizing and day-to-day operation.
OpenShiftKubernetesOfficial support

Zync and the operator
Deployment on OpenShift and Kubernetes through the 3scale operator, route synchronisation and OIDC client synchronisation with Keycloak.
OpenShiftKubernetesOfficial support

Kuadrant
The project behind Red Hat Connectivity Link, Red Hat's successor to 3scale: Gateway API on Envoy, with rate limiting and authentication as Kubernetes policies. The natural target for teams staying on OpenShift.
OpenShiftKubernetesOfficial support

Kong Gateway
Open-source gateway on NGINX with a broad plugin ecosystem; a common landing point for 3scale plans and policies.
KubernetesBare metalPrivate cloudAir-gappedOfficial support
Apache APISIX
Apache Software Foundation gateway on NGINX and etcd: dynamic routing, plugins, a dashboard and a developer portal ecosystem.
KubernetesBare metalPrivate cloudAir-gappedOfficial support

Gravitee
Open-source API management with gateway, developer portal and policy studio, and native support for OpenAPI and AsyncAPI.
KubernetesPrivate cloudOfficial support
Why it matters for data localisation
Where this family meets the CBN directive
An API gateway sits in the path of every payment: it holds the credentials of every consumer, the rate limits that protect the core, and a log of every call. Under the CBN data-localisation directive that puts it squarely in scope, together with the identity provider and the keys it uses. For 3scale customers the timing matters twice over: the hosted SaaS closes in June 2027, five months after the directive's deadline, so a hosted gateway abroad is not an option either way. A self-managed 3scale on OpenShift or Kubernetes in a Nigerian data centre, with Keycloak and Redis beside it, satisfies both, and a migration to Kuadrant, Kong, APISIX or Gravitee can be planned on the same infrastructure. Nothing here is legal advice; your compliance team should confirm the scope that applies to your institution.
The journey with NuxFamily
- 01Assess
- 02Design
- 03Build
- 04Migrate
- 05Operate
- 06Evolve
Every family is delivered through the same six-stage journey, with official 24×7 support and knowledge transfer built in.
Our expertise
Credentials, not adjectives
We have run 3scale on OpenShift for banks and insurers since the 2.x line began, from APIcast policy development in Lua to Porta upgrades under change control. We know where the Ruby, OpenResty and Redis layers break, and we can rebuild and patch them ourselves when the vendor no longer does. We have also moved whole API estates between gateways without a consumer changing a credential, which is the skill a 3scale customer will need before 2029.
Sectors
- banking
- insurance
- retail
8+
Years with these technologies
12+
Production deployments
1,500 requests per second across two data centres, with over 400 published APIs
Largest scale delivered
Official vendor support
Support tiers for this family
Essential
- Coverage
- 8×5, Nigeria business hours
- P1 response
- 8 h
- Corrective support for APIcast, Porta, Apisonator and Zync
- Security advisories for 3scale components and their dependencies
- Email and ticket portal
- Guidance on policies, plans and portal configuration
- One health check a year
Business
- Coverage
- Extended hours, 24×7 for P1
- P1 response
- 4 h
- Everything in Essential
- Patched builds: CVE backports for APIcast, Porta and Apisonator when Red Hat ships no fix
- Video calls with the engineers
- Two health checks a year
- Migration planning workshop
Mission Critical
Most chosen- Coverage
- 24×7 with a named engineer
- P1 response
- 1 h
- Everything in Business
- Named engineer who knows your gateway estate, reachable by phone
- Four health checks a year
- Full migration roadmap: assessment, inventory, policy mapping, parallel run and cut-over
- Support in audit and regulator questions about the API layer
Version policy
Response times and tier names are indicative and confirmed contractually.
Use cases
How it is used in a regulated bank
Use case 01
Keeping a payments API estate on 3scale past 2027
A bank exposes card, transfer and account APIs to partners through 3scale on OpenShift. The subscription is ending, the team that built the platform has moved on, and there is no budget for a migration before the CBN deadline. The APIs must stay secure and available for at least two more years.
Technologies
- 3scale APIcast
- 3scale Porta
- 3scale Apisonator
- Redis
Expected outcome
The platform is patched, observed and documented, and the bank decides when to migrate from a position of control rather than under a vendor deadline.
Metric: No open critical advisory older than 30 days across the estate, from the first quarter onwards
- 1Inventory the estate. Every API, plan, policy chain and consumer application is exported and reviewed against the current versions.
- 2Set the patch baseline. Components are upgraded to the last 2.x release and open advisories are closed with vendor fixes or our own builds.
- 3Instrument the platform. Gateway latency, error rates, Redis memory and backend queue depth feed a dashboard with alert thresholds.
- 4Review the policies. Custom Lua policies are read, tested and documented, and dead ones are removed.
- 5Write the runbooks. Restart, scale, rotate credentials, restore Redis and Porta: each procedure rehearsed and written down.
- 6Operate under contract. Tickets, advisories and quarterly health checks under the agreed tier, with a migration decision point each year.
Use case 02
Moving from 3scale to Kuadrant on OpenShift
Use case 03
APIcast-only support for a fintech
Reference architecture
What a compliant deployment looks like
API consumers
3scale platform
Backends and identity
Operations
Migration path
From where you are to a compliant platform
01
2 weeksAssessment
Activities
- Review the 3scale deployment: versions, components in use, custom policies and integrations
- Inventory APIs, plans, limits and consumer applications
- Check open advisories and the distance to the last 2.x release
- Deliver a written report with the support scope and a first migration opinion
02
2-3 weeksOnboarding
Activities
- Access, runbooks and the monitoring baseline for the gateway, portal and backend
- Upgrade to the last 2.x release and close open advisories
- Agree escalation paths and the named engineer on the higher tiers
03
For as long as the contract runsOngoing support
Activities
- Tickets, patches and security advisories under the agreed tier
- Health checks per year as per tier, with a written report each time
- Patched builds of APIcast, Porta and Apisonator when the vendor ships no fix
04
8-16 weeks when you decide to moveRoadmap and migration
Activities
- Decide whether to stay on 3scale or migrate, and when, with the numbers behind the decision
- Map plans and policies to the target gateway: Kuadrant, Kong, APISIX or Gravitee
- Run both gateways in parallel and cut over API by API with rollback defined
- Decommission 3scale and retain its data
FAQ
Questions architects ask us
No. NuxFamily is an independent provider supporting the open-source 3scale components released under the Apache License 2.0. We do not resell Red Hat subscriptions and we do not speak for Red Hat; we keep your platform running.
Red Hat has stated that 3scale API Management 2.x is the last major release. Full support ends on 30 June 2027, Extended Life Support for self-managed installations ends on 30 June 2029, and the hosted SaaS offering shuts down in June 2027. Check Red Hat's 3scale life-cycle page for the current wording; dates are theirs, not ours.
Yes. Our support does not depend on Red Hat's calendar: it continues for as long as your contract runs. What changes after 2029 is that every fix comes from us, which is why patched builds are part of the Business and Mission Critical tiers.
No. We support the upstream open-source code. If you hold a subscription until 2027 or 2029 you can keep it alongside our support, and we will use Red Hat's fixes while they exist.
Yes. APIcast is supported on its own, standalone or on Kubernetes, at a cost sized for one component rather than for the full platform.
The SaaS closes in June 2027, so the choice is between a self-managed 3scale under support and a migration to another gateway. We help with either: export from the SaaS, self-managed deployment in a Nigerian data centre, or a direct move to Kuadrant, Kong, APISIX or Gravitee.
Yes. Migration is a service line in its own right: assessment, API inventory, policy mapping from 3scale to the target, a parallel run and a cut-over API by API. Kuadrant, Kong, Apache APISIX and Gravitee are the usual targets; others are possible.
For payment APIs of Nigerian institutions, in Nigeria, together with its identity provider, keys and logs. That rules out a hosted gateway abroad, which for 3scale customers coincides with the SaaS shutdown. This is context, not legal advice: your compliance team confirms the scope.
3scale and Red Hat are trademarks of Red Hat, Inc. NuxFamily is an independent service provider and is not affiliated with, endorsed by or sponsored by Red Hat, Inc. Support is provided for the open-source 3scale components distributed under the Apache License 2.0.
Over two decades
Built by the team behind the platforms of Santander, ING, Bankinter and Inditex
More than twenty years designing, building and operating private clouds for institutions that cannot afford to fail, and a delivery model where we stay with you from assessment to operation.
See our track record20+
Years building private clouds
40+
Private clouds delivered
Talk to an architect about this family
Tell us where you are today and we will come back with a first view of the target architecture and the migration path.