
Google Named a Leader in the 2019 Gartner Magic Quadrant for Full Life Cycle API Management
READ FULL INTRODOWNLOAD AGAIN4174
Of your peers have already downloaded this article
3:30 Minutes
The most insightful time you'll spend today!
Centralized Analytics: Apigee and Cloud Run API Management

901
Of your peers have already read this article.
3:30 Minutes
The most insightful time you'll spend today!
Most enterprise companies enforce strict requirements for how APIs should be exposed to the public internet that require centralized handling of the authentication credentials, the collection of metrics metrics and other classic API management capabilities. Before the introduction of sidecars in Cloud Run, developers either had to implement these requirements within the service itself or add a full-lifecycle API management platform in front of their service as described in a previous blog post.
In this post we want to demonstrate a new way to fulfill the requirement for API management in Cloud Run. Specifically we want to look at how the recently announced multi-container feature in Cloud Run enables a sidecar pattern that can be used by developers of Cloud Run services to add pre-packaged API management capabilities. This includes self-service developer onboarding in a developer portal, credential validation and quota enforcements. As an additional operational benefit the described solution also adds centralized analytics and metrics for APIs that are exposed via Cloud Run.
Our solution for adding API management capabilities for Cloud Run is provided by the following three components:
- The Cloud Run service that hosts a traditional RESTful web application and is fronted by a vanilla Envoy proxy.
- An Apigee Envoy Adapter aka. Remote service that runs in GKE Autopilot and acts as a policy decision point PDP for Envoy’s external authorization filter and is responsible for accepting or rejecting calls to the Cloud Run service.
- An Apigee API Platform that is used to manage the API lifecycle of the Cloud Run service. Apigee also offers a turn-key developer portal where developers can obtain access credentials to access an API.
The user journey of an incoming request to our new Cloud Run Service with API management looks as follows:
- An API Developer self-registers in the Apigee Developer Portal and obtains access credentials for the API
- They call the Cloud Run endpoint and provide their credential for authentication
- In Cloud Run service the Envoy proxy container intercepts the request and initiates a gRPC call to the Apigee Envoy adapter to authenticate the client.
- The Apigee Envoy adapter verifies the request’s credentials and identifies the corresponding API product as defined in Apigee. The Envoy adapter also verifies the call quota associated with the client and sends the analytics data and access logs back to the control plane.
- If the credentials are valid and the client hasn’t exhausted their call quota the Apigee Envoy adapter forwards the request to its co-located container in the Cloud Run service.

The step by step instructions for how to configure the architecture above can be found in this blog post.
Starting from a pre-existing Apigee installation the Apigee Envoy adapter is used to connect back to the Apigee runtime and control plane for accessing the API product definitions to link the incoming requests to the issued credentials and quotas. The Apigee remote service component can be replicated for high availability and is shared between multiple Cloud Run services that require a gRPC target for the sidecar’s external authorization filter.
The Cloud Run service connects to the Apigee Remote Service via an Envoy proxy that acts as a sidecar to the main application. The configuration for the envoy proxy can either be embedded within a customized Envoy image or mounted via the secret manager integration of cloud run as shown in the diagram above. Externalizing the configuration simplifies the maintenance and upgrade of the sidecar container as it can just pull the latest patch version of Envoy regularly.
The newly added API management capability is transparent for the primary application container within the Cloud Run service and does not require any changes in the application source code. Once the Cloud Run service is re-deployed with the sidecar in place, consuming applications can start to use credentials that they obtained via the Apigee API Management platform or the API developer portal to consume the Cloud Run service. At an operations level the platform operators will start to see requests to the Cloud Run service popping up in Apigee’s analytics dashboards and be able to track consumption and exposure at an API product level.
Next Steps
If you are interested in trying the multi-container support for Cloud Run yourself, check out the release announcement with many more use case descriptions. For another example and a detailed walkthrough on how to use sidecars in Cloud Run to report custom metrics to Google Cloud managed service for Prometheus you can head over to this tutorial in the Cloud Run documentation. Lastly, if you’re interested in the broader picture of how the latest features in Cloud Run are moving serverless forward, then make sure you check out this video.
Ten Videos to Help You Get Started with Anthos

3455
Of your peers have already read this article.
2:00 Minutes
The most insightful time you'll spend today!
Do you need to develop, run and secure applications across your hybrid and multicloud environments? Look no further than Anthos, our managed application platform that extends Google Cloud services and engineering practices to your environments so you can modernize apps faster and establish operational consistency across them.
To help you get started, we created the Anthos 101 video learning series. It’s a great starting point for understanding the basics of Anthos—and you can watch the whole series in less than an hour.
Let’s dive in.
1. What is Anthos?
Discover what Anthos is and how it helps enterprises manage their applications. You’ll learn about the different tools Anthos offers—like the ability to create environs and platform administrators—to help you modernize and manage your application infrastructure.
https://youtube.com/watch?v=Qtwt7QcW4J8%3Fenablejsapi%3D1%26
2. How to get started with Anthos on Google Cloud
Ready to get started with Anthos? In this lesson, you’ll create your own Anthos deployment. You’ll learn about the different tools on the Anthos dashboard—like the Service Mesh card and Cluster Status cards—plus how to deploy and alter Google Kubernetes Engine (GKE) clusters and Anthos Service mesh via Google Compute Engine.
https://youtube.com/watch?v=ghFiaz7juoA%3Fenablejsapi%3D1%26
3. How to modernize and run Windows apps in Anthos
Running a Windows application that’s in need of modernization? In this lesson, you’ll discover how you can create and deploy a Windows-based application on Anthos, allowing you to modernize existing workloads and manage your application seamlessly. You’ll even learn to do this without requiring access to source code, re-writing, or re-architecting your existing application.
https://youtube.com/watch?v=w6tzIjZhTIk%3Fenablejsapi%3D1%26
4. How to build modern CI/CD with Anthos
Continuous integration? Continuous delivery? These are two things that developers need to think about with container adoption for hybrid or multicloud environments. Learn how Anthos helps you increase your development velocity without compromising the security of your application.
https://youtube.com/watch?v=ayRz5NmM6pI%3Fenablejsapi%3D1%26
5. How to adopt a multi-cluster strategy for your applications in Anthos
There are a number of use cases that might require a multi-cluster strategy, such as maintaining multiple clusters on the cloud and in your own data center. In this lesson, learn the different tools that Anthos offers—such as GKE, Anthos Config Management, and Anthos Service Mesh—to help deploy and manage multiple clusters.
https://youtube.com/watch?v=ZhF-rTXq-Us%3Fenablejsapi%3D1%26
6. How to improve observability using golden signals in Anthos
Observability is important in application development, but without the right tools monitoring your services can be time consuming. In this episode, learn more how Anthos Service Mesh can help you monitor and manage the four Golden Signals—latency, traffic, errors, and saturation—for your application.
https://youtube.com/watch?v=EDcy3KwV22o%3Fenablejsapi%3D1%26
7. How to modernize legacy Java apps with Anthos
Looking to modernize legacy Java applications? In this lesson, you’ll learn the three categories of Java applications and their unique paths for modernization via Anthos. This can help you reduce your dependency on high-cost proprietary software, decrease operational overhead, and increase software delivery speed.
https://youtube.com/watch?v=hQWcx9iyF7E%3Fenablejsapi%3D1%26
8. How to apply a zero trust model for your deployments using Anthos
It’s time to rethink traditional security models when it comes to network observability and consistency for IAM permissions. In this lesson, learn how you can adopt a zero trust posture with Anthos. This allows you to better secure your network, detect underlying network compromises, and ensure workloads are secure before deployment.
https://youtube.com/watch?v=_qG2vazlozY%3Fenablejsapi%3D1%26
9. How to go beyond business continuity with Anthos
Sometimes a business continuity plan that only covers traditional backup and disaster recovery methods simply isn’t enough. In this lesson, learn how Anthos helps resolve issues like data redundancy, scaling without code changes, implementing measurable SLOs, and much more. You’ll also discover how Anthos can help you manage your application beyond the confines of traditional backup and disaster recovery approaches.
https://youtube.com/watch?v=kUxqdjbgcXs%3Fenablejsapi%3D1%26
10. How to simplify identity with Anthos
Managing identities across hybrid and multicloud environments can be troublesome and hard to keep track of. Luckily, Anthos is capable of simplifying identity management for users and workloads. In this lesson, you’ll learn how Anthos can extend and enable existing capabilities, while allowing you to manage IAM permissions across multiple Anthos and GKE environments.
https://youtube.com/watch?v=6P-4ZEwZqZQ%3Fenablejsapi%3D1%26
11. How to optimize costs with Anthos
Learn how you can optimize costs with Anthos through greater observability, improving existing operations, and many other practices.
https://youtube.com/watch?v=8mGICSTRoYw%3Fenablejsapi%3D1%26
Keep learning
This is just a starting point for learning about Anthos. To deepen your knowledge, check out our free on-demand training: Getting started with Anthos. Or, you can download our Anthos Under the Hood ebook, or get hands-on right now with the Anthos sandbox.
ANZ Bank Trusts Apigee to Deliver Secure and Compliant API Strategy

3047
Of your peers have already read this article.
3:30 Minutes
The most insightful time you'll spend today!
ANZ Bank is one of Australia’s top four banks and the largest bank in New Zealand by market capitalization. Headquartered in Melbourne, Victoria, we operate in more than 32 markets across Australia, New Zealand, Asia, Pacific, Europe, America and the Middle East. Our Payment team deals with all payment transaction types by providing highly secure, mission critical payment services to retail, institutional and international customers. The core payment platform is based on microservices architecture to support discreet payment processing requirements such as continuous volume growth, industry service level agreement (SLA) and complex payment orchestration and more. The API platform leverages APIs to perform specific business functions under the payment orchestration layer, which need to be resilient, scalable and heavy on security controls.
Simplifying our technology landscape
At ANZ, our mission is to improve the financial wellbeing and sustainability of our customers through reliable payment services. Over the past 12 months, we looked to simplify our technology landscape, to free up time so we could focus on implementing more customer-focused banking services. We needed an API management solution that would align to our API-first strategy, while also maintaining our high performance, security, and regulatory standards.
Specifically, the solution needed to:
- Simplify channel interactions with our platform;
- Improve developer experience and enable self-service;
- Ensure resilient fault tolerance;
- Improve our payment API security posture;
- Enable API-first digital enablement for both our internal and external payments customers;
- Have a scalable and transparent pricing model that ensured sustainable API programme growth.

Core focus on security and compliance
To meet our security and regulatory compliance standards an API solution would need to offer functionality including:
- Providing coarse-grained and fine-grained authorization and domain specific entitlements for API requests;
- Bundling APIs based on the nature of the channel;
- Integrating easily with established identity providers;
- Establishing patterns for connecting trusted upstream and downstream systems;
- Providing support for the industry standard OAuth 2.0 authorization protocol as per enterprise security standards.
We reviewed Apigee against other API management solutions and gateways, and determined it was the best fit for our needs. Not only did Apigee deliver on all our mission-critical requirements, but it also provided strong ease of use, feature-completeness and support for multiple coding languages.
Enabling smooth developer onboarding, processes and troubleshooting
Using Apigee has greatly improved developer onboarding and reduced the tedious steps involved in knowledge transfer and upskilling. The platform is easy for developers to use, and is backed by great documentation and video resources. These resources provide clear guidance about how to execute certain processes and troubleshoot as needed.
Overall, Apigee has delivered the features we need to manage the publication and consumption of APIs efficiently. We are now running eighteen APIs in production, including two APIs that enable payments through connection to our transaction database, and others that enable supporting services in the payment services platform team.
Our engineers and testers have found it easy to use the interface and Apigee API Management to deploy and test proxies. In addition, out of the box policies allow for fine-grained access control to handle and build proxies of varying degrees of complexity. These policies allow us to control security, manage traffic, mediate transformations and implement custom functionality via scripts.
We can now implement our fine-grained entitlement-based access control requirements, onboard new customers to the cloud and streamline payment channel onboarding. With Apigee, we are also integrating with other API management tools at the bank, in part to enable self-service for API providers and consumers by building a developer portal.
Thanks to Apigee, we are well positioned to adopt a decentralized API team model that will see different teams within payments and beyond create APIs, and ramp up to full production of our API-centric model in the near future. This is a key component of the bank’s broader cloud and API-first strategy that is designed to help ANZ become a more agile and adaptive technology organization. With the right components in place, can we help ANZ create opportunities and propositions that colleagues and customers love, ultimately helping ANZ realize its vision across Australia, New Zealand and international markets.

3698
Of your peers have already downloaded this article
8:45 Minutes
The most insightful time you'll spend today!
For most established businesses today, the disruptive start-up has emerged as the biggest and most intimidating competition. A start-up’s digital prowess and astounding ability to innovate and scale massively in weeks, for what takes conventional businesses quarters, is daunting. How does one compete with that?
To play in today’s digitally-connected world, companies need to be equipped to deliver apps and digital experiences at lightning speed. How do you leverage insights from your environment of customers, partners, suppliers, and, in many cases, stores, warehouses, and inventory and use all that data to deliver relevant products and services? How do you unlock the data from your slow-moving systems of record to build those apps and experiences at the speed and agility of the App Store?
Gartner calls it bi-modal IT: an approach that enables an organization to protect the back-end systems and also drive rapid innovation. Think of it as an enterprise gearbox that enables you to scale your interactions a million times . In this eBook we explore how businesses can implement an API tier to keep backend transaction systems humming as front-end digital interactions scale to billions of requests and interactions , way beyond what your systems were designed to do.
Why You Should Consider API-first Integration

3166
Of your peers have already read this article.
1:30 Minutes
The most insightful time you'll spend today!
Enterprises need to move faster than ever to gain a competitive advantage in today’s customer-focused environment. Time-to-market for products and services has shortened dramatically, from years to days. IT teams must move fast, react fast, and enable business strategies via constant innovation.
All of this digital transformation is about more than adopting the latest technologies. It is also about maximizing the use of existing data and services to improve efficiency and productivity, drive engagement and growth, and ultimately make the lives of customers, partners, and staff better. Connecting existing data and services and making them easily accessible via APIs promises a path forward, empowering enterprises to extend the value they already possess with new technologies, managed services, ecosystems, and support.
In addition to the challenges of legacy data and systems, today’s organizations are overwhelmed by the variety of cloud applications to meet their business needs and deliver innovative services to their customers.
Managing all of this data, connecting sources, integrating applications, and surfacing them as easy-to-use APIs for development is a crucial competency for any IT organization.
Design APIs with an Outside-in Approach
Many IT organizations have focused on solving this challenge with an “inside-out” approach: starting with the integration layer, building the flow, and then developing the APIs. But this approach is inefficient and fundamentally flawed because it looks at the problem from an “exposure” model; rather than designing for the business use cases of developers and other API consumers. Leaders in the organization end up seeing all of this data, connectivity, and integration as the “table stakes plumbing”, and thus do not seek inputs regarding business value from key business stakeholders.
The key issue is not exposure but rather how you leverage your data, services, and systems to drive impact across your digital value chain. Goals such as meeting your adoption or sales targets, reducing costs across lines of business, speeding up time to market, and reducing time spent supporting your customers may all be within reach. Easy-to-use APIs, rather than crudely exposed systems, are foundational enablers of this impact, and they are almost always designed from the outside-in, from the perspective of teams that are consuming the APIs to achieve a business goal.
Embrace API-first Integration
To accelerate the speed of development, enterprise IT teams need to take an API-first approach to integration, starting with the consumers’ use cases rather than the structure of the data in their systems.
The notion of outside-in thinking should be familiar to product managers, who routinely have to demonstrate customer empathy and put themselves in their customers’ shoes. If your team has a product owner, be sure they are empowered to decide what functionality is needed from their data.
Maximize your APIs with the right technology enablers
An API-first strategy treats the API not as middleware but as a software product that empowers developers, enables partnerships, and accelerates innovation—a big shift from integration-first operations in which APIs are typically exposed and then forgotten.
Possessing APIs is only part of the equation. If a company is going to share valuable digital assets with outsiders, it needs API management tools to:
- apply security protections, such as authentication and authorization
- protect assets from malicious attacks
- monitor digital services to ensure availability and high performance
- measure and track usage of the assets
With the right tools in place, APIs can unlock incredible business opportunities—which is a reason for every enterprise to aspire to be API-first!
Visit our website to learn more about API management with Google Cloud.
More Relevant Stories for Your Company

Introducing a strong alternative to CentOS: Rocky Linux Optimized for Google Cloud
As CentOS 7 reaches end of life, many enterprises are considering their options for an enterprise-grade, downstream Linux distribution on which to run their production applications. Rocky Linux has emerged as a strong alternative that, like CentOS, is 100% compatible with Red Hat Enterprise Linux. In April 2022, we announced

An App Modernization Story with Cloud Run
Back in 2016, an ASP.NET monolith app was deployed to IIS on Windows. While it worked, it was clunky in every sense of the word. Over the years, the app was freed from Windows (thanks to .NET Core), containerized to run consistently in different environments (thanks to Docker) and decomposed

Latest News: Secure Digital Infrastructure Services with Apigee Advanced API Security for Google Cloud
Organizations in every region and industry are developing APIs to enable easier and more standardized delivery of services and data for digital experiences. This increasing shift to digital experiences has grown API usage and traffic volumes. However, as malicious API attacks also have grown, API security has become an important

Report on API-led Digital Transformations in 2020 and the Future
In 2020, many businesses across industries turned their focus and investments towards digital strategies. APIs being an integral part of every organization's digital disruption, will grow in relevance throughout 2021. Read the report to gain more insights on driving API-led digital transformations and in-depth analysis of Google Cloud's Apigee API






