What is the advantage of using this compared to plain Nginx or Envoy? Is it just static vs. dynamic config for routing?
1. It can dynamically manage lots of TLS certificates and do the TLS/SSL terminate or use mTLS to communicate with the upstream; 2. Plugins like ACL, IP Restriction, CSRF, and Referrer Restriction restrict API access in different dimensions.
Or is mTLS only possible with client->pass through APISIX->upstream? It's not quite clear from the docs.
mTLS is both possible for client -> APISIX and APISIX -> upstream.
[1] https://gist.github.com/bzp2010/6ce0bf7c15c191029ed547245471...