vulns.co
/
GKData.io MCP

Apollo GraphQL · 1 min read

Apollo Federation: preserving the router-to-subgraph boundary

Explains the deployment assumption behind centralized GraphQL federation controls: internal subgraphs accept traffic only through the router. Federation coordination remains available even when ordinary client introspection is disabled. Consequently, hiding schema discovery cannot establish the service boundary on which router-enforced authorization, demand controls and operation restrictions depend.

Open the reference Architecture GuideReviewed 2026-10-03

How to use this reference

For an owned federated design, document router and subgraph responsibilities. Require network isolation and authenticated router-to-subgraph communication, retain entry-point authorization, and review resource limits and schema-change permissions as separate controls.

Before reading

  • GraphQL federation architecture
  • Service authentication and network isolation concepts

Context and limits

  • Vendor architecture guidance, not a disclosed product vulnerability or evidence about a particular deployment.
  • Disabling ordinary introspection does not replace subgraph isolation.
  • Prerequisites and the review exercise are editorial guidance.

Sources and provenance

  1. Securing Apollo Federation Subgraphs: Context and Best Practices Apollo GraphQL · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software