Skip to content
Aviato Consulting

Apigee API Management, Hybrid & Edge Migrations

Enterprise Apigee implementation, Apigee Edge and hybrid migrations, and governed API layers between your data warehouse and AI on Google Cloud.

Apigee API Platform • Edge & Hybrid Migrations

Modernise Your Apigee Estate Before Google Decoms Your Old Runtime

If you are still running Apigee Edge or an older Apigee hybrid cluster that Google is decommissioning, you are sitting on a ticking clock. We implement modern Apigee and Apigee hybrid on Google Cloud, run zero downtime migrations off legacy platforms, and put a governed API layer between your data warehouse and your AI workloads.

Why You Can’t Just Leave Legacy Edge or Hybrid Alone

Nobody wakes up wanting to migrate an API gateway. If it routes traffic and doesn’t page your on call team at 3am, the temptation is to leave it alone.

The problem is that Google is actively decommissioning older Apigee hybrid versions and retiring legacy Apigee Edge tooling. If you are on Apigee Edge (SaaS or Private Cloud OPDK) or an older Apigee hybrid runtime tied to deprecated Kubernetes and Istio releases, staying put stops being an option. Once your runtime version drops out of support, you lose security patches, bug fixes, and GKE version compatibility. If you are in a regulated industry in Australia, running an unpatched edge gateway in front of customer or clinical data is a massive compliance risk.

We have just gone through this exact migration for a large Australian healthcare company, helping them transition off legacy infrastructure onto the new Apigee platform as Google decommissioned their old hybrid setup. Moving live healthcare APIs handling patient and clinical data without dropping a single request takes proper engineering, not a lift and shift script.

Proven in Australian Healthcare

We recently migrated a major Australian healthcare provider onto the new Apigee platform as Google decommissioned their old hybrid environment. We moved their clinical and patient APIs across with zero cutover downtime and full Australian Privacy Act compliance.

The stuff that breaks when you migrate

Teams often assume migrating from Apigee Edge or an old hybrid install to the new Apigee platform is just exporting proxy bundles and importing them into the new org. If you have actually tried it in staging, you know that falls apart fast. Here is what actually trips teams up:

  • HTTP/1.1 headers get forced to lowercase. The new Apigee runtime converts all HTTP/1.1 header field names to lowercase when forwarding requests to your backend target servers. If you have a crusty legacy backend that expects X-Customer-ID in mixed case, it will silently break until you fix it.
  • No more Node.js proxies or SOAP wizards. Legacy Node.js API proxies are gone. Google expects you to run Node.js apps as separate containers on Kubernetes or Cloud Run. The old SOAP proxy wizard is gone too, so you have to use the open source wsdl2apigee utility instead.
  • Envoy replaces the old Istio adapter. The Apigee Adapter for Istio is deprecated. Everything now runs on the Apigee Adapter for Envoy.
  • One MP pod per environment. In the new architecture, a Message Processor (MP) pod can only serve a single environment. You organise routing through environment groups, and deployments are asynchronous based on when the runtime plane last checked in with the management plane.
  • Payload and API changes on apigee.googleapis.com. Query parameters prefixed with an underscore (like _optimal=true) are no longer supported, properties like created_by, modified_by, and self are stripped from payloads, timestamps in keys are strings ({"createdAt": "1234"}), and cache API operations only support list and delete (returning 204 No Content).

How We Implement Apigee, Edge, and Hybrid

We work across all three setups depending on where your workloads live and what your network team will allow:

☁️

Apigee (Google Cloud Hosted)

Apigee hosts and manages both the management plane and the runtime plane on Google Cloud. We wire it into your VPC using Private Service Connect so you get hyperscale API management without babysitting Kubernetes clusters.

🔄

Apigee Hybrid Upgrades & Builds

Apigee runs the management plane in Google Cloud while you run the runtime plane on Kubernetes in your own data centre or cloud. We upgrade old hybrid clusters before Google decoms them, and automate the whole runtime in Terraform.

🚀

Apigee Edge Migrations

Getting off Apigee Edge SaaS or Private Cloud (OPDK). We assess your existing proxies, rewrite deprecated policies, migrate encrypted KVMs and developer apps, and shift traffic over gradually with zero downtime.

Apigee Technical Feature Summary (Apigee vs Apigee Hybrid)

If you are comparing Apigee (fully managed on Google Cloud) and Apigee hybrid, both share the same modern API (apigee.googleapis.com) and feature set. The difference comes down to who runs the runtime plane.

ProductWhere HostedManaged By
ApigeeGoogle CloudApigee manages both the management plane and the runtime plane
Apigee hybridBoth Google Cloud and your private data centre or cloudApigee manages the management plane and you manage the runtime plane

Platform Feature Breakdown

Here is a practical look at how the core features work across Apigee and Apigee hybrid, and what you need to know when building on them:

FeatureHow It Works in Apigee & HybridWhat Our Engineers Do With It
API Proxy RevisionsRevisions are immutable once deployed. You cannot edit a live revision in place.We enforce strict GitOps CI/CD pipelines so every change deploys a new versioned revision.
DeploymentsAsynchronous deployments. Status is based on the last time the runtime plane checked in with the management plane.We script deployment polling checks into Cloud Build and GitHub Actions before shifting traffic.
Environments & TopologySupports environment groups via UI and APIs. Each Message Processor (MP) pod can only serve one environment.We size MP pod pools per environment so a noisy staging test never starves production pods.
gRPC Proxy SupportProcesses unary gRPC protocol API requests to a gRPC target server.Lets us front high speed internal Go and Python gRPC services alongside standard REST APIs.
Encrypted KVMs & Property SetsEnvironment scoped KVMs are always encrypted. You cannot view or edit KVM entries in the UI; you use the keyvaluemaps.entries API or KeyValueMapOperations policy with a dynamic <MapName> element, or use property sets.We prefix all sensitive KVM lookups with private. during GET operations so secrets never leak in decrypted form during a debug (Trace) session.
Keystores & TruststoresNorthbound TLS keys and certs are managed as Kubernetes secrets in hybrid (via Anthos Service Mesh), or via instance HTTPS endpoints in Apigee.We automate certificate rotation through Secret Manager and Kubernetes secrets so certs never expire silently.
Identity, Roles & OAuthRoles and permissions are managed through Google Cloud IAM (curated and custom roles). Includes the new RevokeOAuthv2 policy to revoke tokens by end user ID, app ID, or both.Ties Apigee access directly into your Google Cloud landing zone IAM and gives you an instant kill switch for compromised user or agent tokens.
App Ownership & MonetizationOrganise client apps using AppGroups or developer app associations. Full API Monetization is supported in both Apigee and hybrid.Cleanly separates B2B partner teams and internal business units for chargeback or commercial billing.
Trace & Debug SessionsAsynchronous debug sessions via the Debug Session API and UI. Supports AND / OR filter logic on flow variables, up to 15 requests per MP, 5 min (API) or 10 min (UI) default timeout, with hybrid deleting trace data after 24 hours.We make sure Synchronizer clocks are NTP synced so debug session creation requests don’t get dropped by the runtime plane.
Caching & Metrics APIsShort lived L1 cache is created automatically when you deploy a proxy. Metrics and custom reports run on apigee.googleapis.com (userId, createdBy, and lastModifiedBy are omitted from async query and report responses).We wire custom analytics exports into BigQuery and Looker rather than relying on deprecated daily analytics emails.

Under the Hood of the Apigee Hybrid Runtime Plane

When we deploy or upgrade Apigee hybrid in your Kubernetes cluster, here is the actual plumbing we stand up and manage:

  • API Proxy Gateway (RMP): An Istio Ingress controller (via Anthos Service Mesh) hands incoming traffic to containerised Router / Message Processor (RMP) pods in the runtime plane.
  • Synchronizer: Containerised pods that pull API proxy configurations, environment settings, and policy updates from the Google Cloud management plane to keep the local runtime in sync.
  • Persistence (Cassandra StatefulSet): Apache Cassandra runs in Kubernetes as a StatefulSet to persist KMS, KVM, quota, and cache state on disk.
  • MART (Management API Runtime Data): Apigee APIs talk to the Management Server and MART, which interacts with your local Cassandra datastore to manage runtime data entities.
  • Analytics & Metrics: A data collection pod in the runtime plane uses Fluentd and UDCA (Universal Data Collection Agent) to ship analytics to the UAP (Unified Analytics Platform) in the management plane, while a single Prometheus server per cluster handles runtime metrics.

Using Apigee Between Your Data Warehouse and AI

Right now, everyone is rushing to hook AI agents and LLMs up to their enterprise data. The most common mistake we see is teams taking a well governed BigQuery data warehouse and wiring a Vertex AI agent or third party LLM straight into it with a broad service account.

That works fine in a proof of concept. In production, it is a mess. You have no token rate limiting, no prompt injection screening, no caching when twenty users ask the same question, and no way to prove to a regulator what data left the warehouse and why.

Governed AI Plumbing
Data Warehouse ↔ Apigee ↔ AI Agents
01. Data Warehouse

BigQuery & Core DBs

Your BigQuery lakehouse, FHIR clinical stores, and transactional databases stay locked inside a VPC Service Controls perimeter. No direct agent access.

02. Governance & Control Layer

Apigee & Apigee AI Gateway

Sits right between your data warehouse and your AI. Enforces OAuth2 per agent, Model Armor prompt screening, token quotas, semantic caching, and MCP tool transcoding.

03. AI & Agents

Gemini, Claude & ADK Agents

Agents discover approved data products in Apigee API Hub and call them as governed MCP tools, with every token and payload logged.

Putting Apigee between your data warehouse and your AI gives you the governance and control your security team needs to actually sign off on production AI:

  1. Governance and Data Boundaries: Apigee sits in front of BigQuery and your core APIs. Every request from an AI agent has to authenticate with its own OAuth2 identity, and Model Armor screens prompts and responses so PII and sensitive records don’t leak into an LLM context window.
  2. Turning Warehouse Queries into MCP Tools: Instead of letting agents write raw SQL against production tables, we expose curated data warehouse views and enterprise APIs through Apigee as Model Context Protocol (MCP) tools. Agents only see the tools they are allowed to call.
  3. Token Quotas & Semantic Caching: If an agent gets stuck in a loop, Apigee’s token limit policies cut it off before it racks up a massive BigQuery and Vertex AI bill. Semantic caching serves cached answers for similar prompts in milliseconds.
  4. Audit Trails for the Regulators: Every tool call, data lookup, and model response is logged with a correlation ID and streamed to Cloud Logging and Google SecOps.

We have built a dedicated page on how we use Apigee as an AI gateway. Check out our Apigee AI Gateway page under AI & Machine Learning →

How We Run an Apigee Migration

1

Audit Your Current Edge or Hybrid Estate

We run automated assessment tools over your existing Apigee Edge or legacy hybrid setup. We map every proxy, shared flow, KVM, target server, and policy, and flag everything that will break on the new platform (like lowercase HTTP/1.1 headers, old Istio adapters, or Node.js proxies).

2

Build the New Platform in Terraform

We stand up your new Google Cloud Apigee org or upgraded Apigee hybrid Kubernetes runtime (Cassandra StatefulSets, Synchronizer, MART, UDCA, and Envoy / Anthos Service Mesh ingress) completely in Terraform, wired into Google Cloud IAM and Cloud Armor.

3

Refactor Proxies & Wire Up CI/CD

We refactor incompatible proxies, migrate your encrypted KVMs and AppGroups, load your specs into Apigee API Hub, and build automated regression tests into Cloud Build or GitHub Actions for immutable revision deployments.

4

Parallel Run & Zero Downtime Cutover

We run the new Apigee platform alongside your old Edge or hybrid cluster, shifting traffic over in stages with canary routing until 100% of production is on the new platform and you can switch the old servers off.

Who This Is For

  • Teams on Apigee Edge or older Apigee hybrid versions that need to migrate to the new platform before Google’s decommission and end of support dates hit.
  • Healthcare, finance, and regulated businesses that need strict Australian data residency, Privacy Act or APRA CPS 234 compliance, and an engineer team that has already done this at scale in Australian healthcare.
  • Data and AI teams that need a proper governance and control layer sitting between BigQuery and their AI agents.

Why Aviato

Aviato is a Google Cloud Premier Partner and the 2026 Google Cloud Australia & New Zealand Partner of the Year. Our practice is led by ex Google Cloud architects, including our founder Ben King, who spent 6.5 years at Google Cloud leading App Modernisation for APAC Professional Services. We write clean Terraform in your repos, we don’t do vendor lock in, and if you want us to run the platform afterwards, our Managed SRE team can carry the pager.



Ready to Sort Out Your Apigee Migration?

Book a 20 minute call with one of our senior Google Cloud architects. Tell us what version of Edge or hybrid you are running today, and you will walk away with a straight answer on how to migrate it, what will break, and what it will cost.

Book a Free 20 Min Architecture Call →

Fixed price, fixed date

Talk to an architect who has done this before.

Bring your current setup and the outcome you need. You will get a view on the approach, the risks and roughly what it costs.

Book a 20-min architecture call

Straight to a senior GCP architect. No SDR, no slide deck.

Not ready to talk? See how we migrated Hapana off AWS →

Or call +61 2 8359 9507 · Hello@aviato.consulting

Call us Book a call