GraphQL Day

Zero-to-Federation in 60 Seconds: How a GraphQL Middleware Replaced 500+ Legacy APIs and Saved 3 Years of Migration

Junior Ball Room 2
Federation

When Red Hat needed to migrate hundreds of customer-facing systems away from a legacy Salesforce REST integration, the team faced a daunting reality: 500+ custom REST APIs, each hand-written to bridge Red Hat's ecosystem with Salesforce as the data source. Rebuilding them for the new architecture would take years and a massive engineering effort.

Instead, we built a lightweight GraphQL middleware that sits between Apollo Federation's supergraph and Salesforce's GraphQL API — and it changed everything.

From day zero, every Salesforce object, field, mutation, and relationship was available in Red Hat's federated supergraph. No hand-written schema. No custom resolvers. No months of API development per object.

In this talk, I'll walk through how we:

  • Auto-introspect Salesforce's GraphQL schema at runtime, even though Salesforce's own introspection endpoint is broken and non-functional - by querying the underlying introspection JSON and reconstructing a valid SDL from scratch.
  • Dynamically federate the schema by programmatically injecting Apollo Federation directives (@key, @shareable), applying naming-convention prefixes (SalesforceSupport, salesforce_support_) to prevent type collisions in the supergraph, and transparently rewriting queries using GraphQL aliases so Salesforce never sees the prefixed names.
  • Bridge two authentication systems — translating Red Hat SSO (Keycloak) JWT tokens into Salesforce OAuth access tokens on the fly, so customers authenticate once with their Red Hat identity and transparently access Salesforce data.
  • Reflect upstream changes in real time — when Salesforce's object model changes (new fields, new objects, schema modifications), the middleware's scheduled introspection picks it up and the supergraph updates automatically with zero developer intervention.

The result: what was estimated as a 3+ year migration effort was reduced to weeks. Hundreds of developers were unblocked immediately. And the entire Salesforce surface area — every object, every field, every relationship — is now queryable through a single federated GraphQL endpoint with full type safety.

This is a story about choosing the right abstraction, trusting GraphQL's composability, and how a single middleware service replaced years of planned API development.


Rigin Oommen

Red Hat LLC, Principal Software Engineer