I'm building a high traffic API using Swagger and is looking for advice on using Swagger in a high traffic production environment. My focus is performance and security.
I have seen numerous ways of implementing Swagger in Node projects where the bulk uses two approaches:
1) Using middleware like npm-swagger-express-mw and npm-swagger-tools to intercept your routes, validate input, generate default error responses and registering routes by reading a Swagger compliant yaml or JSON file. This creates a secondary routing abstraction layer in conjunction with Express. Here's one of my "hello world" examples following such a pattern:
https://github.com/ChristianRich/swagger-api-demo
2) Using Swagger to generate the API docs only. Live app would run just fine without anything "Swagger" installed.
Would anyone with experience in this field care to share some insights? Could this raise a red flag in pen or performance testing?