Skip to main content
API Management
from Network
Engineer’s
Perspective
Priya Saxena
Cloud Engineer, Google
API
Management
S
e
c
u
r
i
t
y
Network
P
e
r
f
o
r
m
a
n
c
e
Multi-cloud
A
I
R
e
l
i
a
b
i
l
i
t
y
Beyond API Management
Multi-layer Security & Privacy
● Cloud Armor web application firewall
● Cloud Identity and Access Management (IAM) for
authenticating and authorizing access
● Control the network locations from which users can
access data by using VPC Service Controls.
● ReCaptcha risk-based bot algorithms with
continuous machine learning for fraud detection
● Cloud DLP (Data Loss Prevention) for inspecting
text, images, and other data to identify and mask
sensitive data
● CMEK for customer-managed encryption keys
● AI and machine learning capabilities to historical API metadata to
autonomously identify anomalies, predict traffic for peak seasons, and
ensure APIs adhere to compliance requirements.
AI Powered Automation
AI and machine learning capabilities to historical
API metadata to
● Autonomously identify anomalies,
● Predict traffic for peak seasons,
● Ensure APIs adhere to compliance
requirements.
Global Reach, High Performance & Reliability
● Power of Cloud CDN to maximize the
availability and performance of APIs
globally.
● Customers can now deploy their APIs
across 24 Google Cloud regions
● Enhance caching at more than 100
locations.
● Store data in the region of choice
● Hybrid architecture for low latency and
multi-cloud setup
Architecture Overview
● Apigee X runs in a separate fully managed Google VPC
● Network separation between Customer VPC and Apigee's
VPC without further configuration
● Apigee is not exposed to outside world on public facing IP
Architecture Overview
● VPC network peering enables communication
between VPCs
● Apigee communicates via private IPs
Architecture Overview
● Managed VMs allow requests and responses to flow between the
peered networks.
Architecture Overview
● Traffic routed privately to a workload in the internal VPC
API Call Lifecycle
Thank you