This page documents production updates to all Apigee software in 2022 and later. We recommend that users periodically check this list for any new announcements, or subscribe to this page using a feed reader to get notifications of updates.
What is a feed reader?
Really simple syndication (RSS) feed readers aggregate content from websites that you specify.
Feed reader notifications can be email-, browser-, desktop-, or mobile-based. Some readers are free, or have free versions, and some require a subscription.
A few examples:
More information on RSS:
See also:
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
December 11, 2025
Apigee API hubModel Context Protocol (MCP) support in API hub
API hub now supports the Model Context Protocol (MCP) as a first-class API style. This enables you to ingest, register, and manage MCP APIs and their associated tools.
Key capabilities include:
- MCP API registration: Register MCP APIs manually or via API hub APIs to create a single registry for your agentic services.
- MCP tools: Attach MCP specification files to your APIs. API hub parses these files to automatically extract and display the MCP tools in the UI.
For more information, see API resources overview, Register MCP APIs, and Manage MCP tools.
December 10, 2025
Apigee XOn December 10th, 2025, we released an updated version of Apigee (1-16-0-apigee-6).
| Bug ID | Description |
|---|---|
| 458417250 | Multiple authorization headers Fixed issue where adding multiple authorization headers would cause Apigee to return a |
| N/A | Updates to security, infrastructure, and libraries. |
December 09, 2025
Apigee API hubActions tab changes
The Actions tab previously located in the API hub > Settings page is now removed, accounting for the following UI changes:
- You can now find and configure add-on services like Specification Linter and Semantic Search under the new unified Add-on Management page, alongside other API hub add-ons.
- The deprovisioning function is now moved to a dedicated top-level tab called Deprovision.
New add-on management page in API hub
A new Add-on Management page is now available in API hub. This page serves as a centralized location to enable, configure, and manage all your add-on services.
For more information, see Manage add-ons.
December 04, 2025
Apigee XMask KVM values
You can now turn on key value map (KVM) masking to mask values with asterisks (*****). For more information, see About KVM masking.
November 18, 2025
Apigee API hubNew API deployments view
API deployment information is now available as a separate tab in the API details page. You can view your API deployment details, create new deployments, and manage existing deployments using the API deployments tab.
For more information, see Manage deployments.
The issue relating to API hub provisioning failures in data residency enabled Apigee organizations is now resolved. You can now provision API hub within an Apigee organization that has data residency enabled.
For information about provisioning API hub, see Provision API hub in the Cloud console.
New tutorial: Ingest Microsoft Azure API data into API hub
A new tutorial is available for ingesting Microsoft Azure API data into API hub.
This tutorial shows you how to ingest API metadata from Azure API Management (APIM) into Apigee API hub. It uses a pre-built Application Integration template and a set of custom scripts on GitHub to perform a manual, on-demand ingestion of your API data.
For more information, see Ingest Microsoft Azure API data into API hub.
November 17, 2025
Apigee AnalyticsOn November 17, 2025 we released an updated version of Apigee Analytics.
Support for aggregate data in Error Code Analysis, Cache Performance, and Target Performance charts
Announcing support for viewing aggregate data in the Error Code Analysis, Cache Performance, and Target Performance Analytics dashboards.
For information on the Analytics dashboards, see Use the Analytics dashboards.
| Bug ID | Description |
|---|---|
| 446973091 |
Proxy editor endpoint view is now disabled if there are over 200 flows configured in proxy endpoints. When opening the proxy editor endpoint view with a proxy that has over 200 flows, the proxy graph is no longer rendered, and instead you are presented with a message informing you that there are too many flows to render. This action addresses a performance issue that made the proxy editor unusable when there were over 200 flows configured. |
On November 17, 2025, we released an updated version of the Apigee UI.
On November 17, 2025 we released an updated version of Apigee Analytics.
Support for aggregate data in Error Code Analysis, Cache Performance, and Target Performance charts
Announcing support for viewing aggregate data in the Error Code Analysis, Cache Performance, and Target Performance Analytics dashboards.
For information on the Analytics dashboards, see Use the Analytics dashboards.
On November 17, 2025, we released an updated version of Apigee (1-16-0-apigee-5).
Secure and validate documents using WS-Security with X.509 certificates
You can now secure and validate SOAP documents using WS-Security with X.509 certificates using crypto object methods. See Secure SOAP documents using WS-Security with X.509 certificates and Validate SOAP documents using WS-Security with X.509 certificates.
| Bug ID | Description |
|---|---|
| 454672970 | Added strict input validation to the SetIntegrationRequest policy |
New field available in the Apigee Organization API
With this release, a new field is added to the Apigee Organization API. The new caCertificates (plural) field returns the value of the original CA certificate field and can hold additional values. The original caCertificate (singular) field is deprecated.
| Bug ID | Description |
|---|---|
| N/A | Updates to security, infrastructure, and libraries. |
November 12, 2025
Apigee UIOn November 12, 2025, we released an updated version of the Apigee UI.
| Bug ID | Description |
|---|---|
| 455584175 |
Fixed a performance issue with Debug session UI Fixed an issue where performance of the Debug session was severely degraded when loading a Debug session with a moderate number of transactions. |
November 10, 2025
Apigee AnalyticsOn November 10, 2025 we released an updated version of Apigee.
Support for new Apigee Analytics regions
This release introduces Apigee Analytics support for these new regions:
Hong Kong (asia-east2) and São Paulo (southamerica-east1).
NOTE: Apigee Advanced API Security does not support these new regions at this time.
For a list of all of the supported Analytics regions, see Available Apigee API Analytics regions.
On November 10, 2025 we released an updated version of Apigee.
Support for new Apigee Analytics regions
This release introduces Apigee Analytics support for these new regions:
Hong Kong (asia-east2) and São Paulo (southamerica-east1).
NOTE: Apigee Advanced API Security does not support these new regions at this time.
For a list of all of the supported Analytics regions, see Available Apigee API Analytics regions.
November 04, 2025
Apigee API hubFilter APIs by user-defined attributes
You can now filter APIs using your custom, user-defined attributes from the APIs page in the Google Cloud console.
For more information, see Filter resources based on attributes.
November 03, 2025
Apigee API hubAPI hub provisioning fails in data residency enabled Apigee organizations
Currently, API hub can't be provisioned within an Apigee organization that has data residency enabled. Attempts to provision API hub in a data residency-enabled Apigee organization will result in a timeout error.
Workaround: There is no workaround available at this time. If your existing Apigee organization has data residency enabled, you will not be able to provision API hub until this limitation is resolved in a future release.
November 02, 2025
Apigee UIOn November 2, 2025, we released an updated version of the Apigee UI.
The Apigee Classic UI shutdown is complete. The shutdown was finalized on November 2, 2025, completing the migration of Apigee to the Google Cloud console. All Apigee functionality is now available in the Apigee UI in the Google Cloud console.
See the Apigee Classic UI shutdown page for more details.
October 31, 2025
Apigee XOn October 31, 2025, we released an updated version of Apigee (1-16-0-apigee-4).
| Bug ID | Description |
|---|---|
| 452621774, 452381632, 441266643, 448498138 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities:
|
| Bug ID | Description |
|---|---|
| 448647917 | Fixed a issue where non-SSL connections through a forward proxy could be improperly shared. |
| N/A | Updates to security, infrastructure, and libraries. |
October 30, 2025
Apigee UIOn October 30, 2025, we released an updated version of the Apigee UI.
| Bug ID | Description |
|---|---|
| 443120120 |
Fixed an issue where an incorrect target URL or cURL command was displayed in the proxy debug properties window. New generated debug sessions now contain information in a flow info event that describes the values used by the proxy to call the target endpoint. The debug UI displays these values and uses them to generate the target URL and curl command displayed in the debug properties window when the target request event is selected. If some of the header fields are masked in the debug session, a warning appears next to the Copy cURL button. If the headers are truncated due to system limitations, Copy cURL is disabled. Older debug sessions that do not have the new target endpoint information no longer attempt to display the target URL or generate a cURL command as they were unreliable. A dialog is displayed warning you of this when attempting to open older debug sessions. |
October 29, 2025
Apigee XEnhanced Validation for API products
Heightened validation logic for creating and updating API products is now available. Apigee now explicitly verifies proxy and environment resources against your organization when creating and updating API products.
Please ensure that all referenced resources exist and are correctly associated with your organization to avoid validation errors.
Support for API-product scoped quotas
You can now set quotas at the API product level to limit the number of requests all API proxies in the API product can process within a specified time frame. See Configuring the quota policy to use API product quota settings for information and instructions.
NOTE: API product-scoped quotas are not supported in Apigee hybrid at this time.
On October 29, 2025, we released an updated version of Apigee.
October 28, 2025
Apigee API hubAPI insights in API hub
API insights is now available in API hub, providing a unified view of your API traffic and performance across all connected gateways. With API insights, you can gain a holistic understanding of your API ecosystem's health and quickly identify areas for optimization.
Currently, API insights supports data sources from Apigee, Apigee hybrid, Apigee Edge Public Cloud, and Apigee Edge Private Cloud (OPDK).
For more information, see API insights overview.
Detailed API resource insights
A new Insights tab is now available on the API details page, providing API-centric analytics to help you understand usage patterns and performance for each of your APIs.
You can now analyze key metrics such as total traffic, average TPS, request/response latencies, and more, directly from the API details page.
For more information, see View API resource insights.
October 27, 2025
Apigee XIntroduction of the target.evaluated.url flow variable
This release includes a new flow variable, target.evaluated.url,
which should be used instead of the target.url flow variable in
cases when the URL is dynamically constructed based on user input.
For more information, see the target flow variables documentation.
On October 27, 2025, we released an updated version of Apigee.
October 16, 2025
Apigee API hubCreate and manage API operations in the UI
You can now create and manage API operations for your API versions from the API details page in the Google Cloud console.
For more information, see Manage operations.
On October 16, 2025, we released an updated version of Apigee (1-16-0-apigee-3).
| Bug ID | Description |
|---|---|
| 442501403 | Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a TargetEndpoint is configured with a <LoadBalancer>. |
| 437999897 | Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses. |
| 436323210 | Fixed ingress cert keys to allow both tls.key/key and tls.crt/cert. |
| 438192028 | Updated the geolocation database to mitigate stale IP-to-location mappings. |
| N/A | Updates to security infrastructure and libraries. |
| Bug ID | Description |
|---|---|
| 440419558, 433759657 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities: |
| 443902061 | Security fix for Apigee infrastructure This addresses the following vulnerability:
|
October 14, 2025
Apigee API hubNew MCP API style system attribute
The system-defined API style attribute now includes a new value: MCP. This lets you classify and govern APIs based on the latest Model Context Protocol (MCP) standards.
For more information, see System attributes.
Removal of deprecated Gemini Code Assist @Apigee tool.
The Gemini Code Assist @Apigee tool is shut down as of October 14, 2025.
See Gemini Code Assist @Apigee tool deprecation for information.
October 12, 2025
Apigee hybridRecurring, top-up, and setup fees for Apigee hybrid monetization
Apigee hybrid now supports recurring, top-up, and setup fees for monetization. For information see Enabling monetization for Apigee hybrid.
hybrid v1.15.1
On October 10, 2025 we released an updated version of the Apigee hybrid software, 1.15.1.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.15.
- For information on new installations, see The big picture.
Apigee policies for LLM/GenAI workloads
Apigee hybrid now supports the following Apigee policies with support for LLM/GenAI workloads.
The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs. With this release, the semantic caching policies support URL templating, enabling the use of variables for AI model endpoint values.
The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.
For more information on using these policies in your Apigee API proxies, see:
| Bug ID | Description |
|---|---|
| 451841788 | Apigee hybrid required the mintTaskScheduler.serviceAccountPath property even when Monetization was not enabled. |
| 451375397 | The apigee-pull-push.sh script could return a "No such image error" message. |
| 445912919 | Unused files and folders have been removed from the Apigee hybrid Helm charts to prevent potential security exposure and streamline the product installation and upgrade process. |
| 442501403 | Fixed an issue that caused incorrect target latency metrics in Apigee Analytics when a TargetEndpoint is configured with a <LoadBalancer>. |
| 437999897 | Reduced the log level for failed geo IP lookups to address excessive log messages for private IP addresses. |
| 431930277, 395272878 | When the configuration property envs.managementCallsSkipProxy is set to true via helm for environment-level forward proxy, trace and analytics (which use googleapis.com) will skip forward proxy. |
| 423597917 | Post of an AppGroupAppKey scopes should result in insert operation instead of update. |
| 420675540 | Fixed Cassandra based replication for runtime contracts in synchronizer. |
| 419578402 | Mint-Mart forward proxy compatible. |
| 416634326 | Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods. |
| 412740465 | Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway. |
| 409048431 | Fixes a vulnerability which could allow a SAML signature verification to be bypassed. |
| 378686709 | The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error. To apply this fix, follow the procedure in Known issue 378686709. |
| 367815792 | Two new Flow Variables: app_group_app and app_group_name have been added to VerifyApiKey and Access Token policy. |
| Bug ID | Description |
|---|---|
| 448498138 | Security fixes for apigee-runtime. This addresses the following vulnerability: |
| 447367372 | Security fixes for apigee-runtime. This addresses the following vulnerability: |
| 418557195 | Security fixes for apigee-fluent-bit. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-hybrid-cassandra. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mart-server. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-stackdriver-logging-agent. This addresses the following vulnerabilities:
|
Documentation change
The following documents have been changed or introduced to align the Apigee hybrid installation guides with the supported methods for service account authentication:
- Service account authentication methods in Apigee hybrid - A new overview topic for service account authentication.
- Storing service account keys in Kubernetes secrets - A new topic.
- Step 4: Create service accounts - Rewritten to accommodate all supported methods of service account authentication.
- Step 5: Set up service account authentication - A new topic on configuring authentication after creating service accounts.
- Step 7: Create the overrides and Step 11: Install Apigee hybrid Using Helm - Topics revised to provide templates, examples, and procedures for each supported type of service account authentication.
- Step 11(Optional): Configure Workload Identity - Topic removed. The procedures are included in Step 11: Install Apigee hybrid Using Helm: WIF for GKE
October 09, 2025
Apigee XDeprecation of the Gemini Code Assist @Apigee tool.
The Gemini Code Assist @Apigee tool is deprecated and will be shut down as of October 14, 2025.
See Gemini Code Assist @Apigee tool deprecation for information.
October 07, 2025
Apigee UIOn October 7, 2025, we released an updated version of the Apigee UI.
Output from print statements is now displayed in the Debug session viewer
A new option has been added to the transaction navigation table header in the Debug session viewer that opens the Transaction output window. The Transaction output window displays print() output from either all transactions in the debug session, or a specific transaction from the session. See Creating a debug session for details.
Previously unreported customer DNS misconfigurations now result in DNS errors
Apigee removed the automatic DNS fallback functionality that was in 1-16-0-apigee-2. This removal surfaces customer DNS misconfigurations that previously did not show as DNS errors.
hybrid v1.14.3
On October 7, 2025 we released an enhancement to Apigee hybrid version 1.14.3, recurring, top-up, and setup fees for Apigee hybrid monetization.
- For complete information on the contents of the v1.14.3 release, see Apigee hybrid v1.14.3 release notes.
Recurring, top-up, and setup fees for Apigee hybrid monetization
Apigee hybrid now supports recurring, top-up, and setup fees for monetization. For information see Enabling monetization for Apigee hybrid.
| Bug ID | Description |
|---|---|
| 419578402 | Mint-Mart forward proxy compatible. |
October 02, 2025
Apigee Advanced API SecurityOn October 2, 2025 we released an updated version of Advanced API Security Abuse Detection
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Introduction of exclusion lists for Abuse Detection and incidents
You can now specify CIDR ranges and IP addresses to exclude from future incident reports. Use this feature to exclude traffic known to be safe, such as requests related to automated testing.
The new functionality includes the ability to create and manage multiple "exclusion lists" which define traffic to exclude and the reasons it is excluded.
Note: Exclusion lists are not available for VPC-SC customers at this time.
For usage information, see Exclude traffic from abuse detection in the documentation.
September 29, 2025
Apigee hybridhybrid v1.14.3
On September 29, 2025 we released an updated version of the Apigee hybrid software, 1.14.3.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.14.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 451841788 | Apigee hybrid required the mintTaskScheduler.serviceAccountPath property even when Monetization was not enabled. |
| 451375397 | The apigee-pull-push.sh script could return a "No such image" error message. |
| 423597917 | Post of an AppGroupAppKey scopes should result in insert operation instead of update. |
| 420675540 | Fixed Cassandra based replication for runtime contracts in synchronizer. |
| 416634326 | Presence of istio.io Custom Resource Definitions (CRDs) in an Apigee hybrid cluster could cause failure in apigee-ingressgateway-manager pods. |
| 414499328 | ApigeeTelemetry could become stuck in creating state |
| 412740465 | Fixed issue where zipkin headers were not generated by Apigee Ingress Gateway. |
| 409048431 | Fixes a vulnerability which could allow a SAML signature verification to be bypassed. |
| 395272878 | Separate Forward proxy support for googleapis.com and non-googleapis.com runtime traffic. |
| 378686709 | The use of wildcards (*) in Apigee proxy basepaths would conflict with other explicit basepaths, resulting in a 404 error. To apply this fix, follow the procedure in Known issue 378686709. |
| 367815792 | Two new Flow Variables: app_group_app and app_group_name have been added to VerifyApiKey and Access Token policy. |
| Bug ID | Description |
|---|---|
| 433952146 | Security fix. This addresses the following vulnerability: |
| 433951774 | Security fix. This addresses the following vulnerability: |
| 433950558 | Security fix. This addresses the following vulnerability: |
| 433950370 | Security fix. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-asm-ingress. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-asm-istiod. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-envoy. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-hybrid-cassandra. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mart-server. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-operators. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-stackdriver-logging-agent. This addresses the following vulnerabilities:
|
| N/A | Security fixes for apigee-watcher. This addresses the following vulnerability: |
September 24, 2025
Apigee Operator for kubernetesOn September 24, 2025, we released an updated version of Apigee.
ApigeeBackendService for the Apigee Operator for Kubernetes (GA)
The ApigeeBackendService resource for the Apigee Operator for Kubernetes is Generally Available (GA).
This new resource enables the integration of the Apigee Operator for Kubernetes with the Google Kubernetes Engine (GKE) Inference Gateway. The GKE Inference Gateway is an extension to the GKE Gateway that provides optimized routing and load balancing for serving generative Artificial Intelligence (AI) workloads. It simplifies the deployment, management, and observability of AI inference workloads.
With this new integration, GKE Inference Gateway users can now leverage Apigee's full suite of features to manage, govern and monetize their AI workload through APIs.
To learn more, see Create an ApigeeBackendService.
Apigee Operator for Kubernetes for Apigee Hybrid (Preview)
On September 24, 2025 we released the Apigee Operator for Kubernetes for Apigee Hybrid 1.15.0 and newer.
The Apigee Operator for Kubernetes allows you to perform API management tasks, such as defining API products and operations, using Kubernetes tools. This preview release allows you to integrate this capability with your Apigee hybrid (v1.15.0 or newer) installation.
For more information, see:
September 19, 2025
Apigee Advanced API SecurityOn September 19, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New security actions status icons and "expired" note in the security actions UI
This release adds security status icons to the Apigee UI to make it easier to see, at a glance, whether a security action is enabled, disabled, or paused, and an "expired" note when an action is expired.
The status icons display next to the action's status in the security actions list and in the security action details page.
For information on security actions and security action statuses, see the Security Actions customer documentation.
On September 19, 2025, we released an updated version of the Apigee UI.
| Bug ID | Description |
|---|---|
| 444579842 | Fixed browser hang issue when uploading large bundles. Fixed an issue where the browser would hang when creating a new proxy or proxy revision from a large uploaded zip bundle. |
September 18, 2025
Apigee Advanced API SecurityOn September 18, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Improvements to the Abuse Detection incident model
This release includes improvements to the incident model, including lower noise and higher accuracy for abuse detection incidents.
Note: This feature is not currently available to customers with VPC-SC enabled.
For information on abuse detection incidents, see the Abuse Detection customer documentation.
September 14, 2025
Apigee UIOn September 14, 2025, we released an updated version of the Apigee UI.
Added icon to proxy and sharedflow editor to mark unused policies
If a policy has yet to be attached to any flow in the configuration, an icon now displays next to that policy in the Proxy Editor side navigation to signify that the policy is currently unused in the proxy or sharedflow.
September 12, 2025
Apigee XOn September 12, 2025, we released an updated version of Apigee (1-16-0-apigee-2).
| Bug ID | Description |
|---|---|
| N/A | Security fix for apigee-runtime. |
September 11, 2025
Apigee API hubUpdated Go client library. For more information, see apihub: v0.2.0.
API hub navigation update
The API hub section is now moved to the top level of the Apigee left navigation menu. This change improves discoverability and access to the API hub features.
API hub navigation update
The API hub section is now moved to the top level of the Apigee left navigation menu. This change improves discoverability and access to the API hub features.
September 09, 2025
Apigee X| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
On September 9, 2025, we released an updated version of Apigee (1-16-0-apigee-1).
September 08, 2025
Apigee API hubAutomatic discovery of OpenAPI Spec from Apigee proxy resources
API hub now automatically discovers and ingests valid OpenAPI specifications when they are included in an Apigee API proxy resource. This applies to all new and existing Apigee and Apigee hybrid runtime projects that are attached in API hub.
For more information, see Auto-discovery of OpenAPI specs from Apigee proxies.
Deprecation of Vertex AI Extensions in API hub
The Vertex AI Extensions feature is no longer supported in API hub as of September 8, 2025.
Enable and disable semantic search
You can now enable and disable semantic search from the API hub > Settings> Actions page in the Google Cloud console.
For more information, see Enable and disable semantic search.
On September 8, 2025 we released a new version of the Apigee integrated portal.
Workforce Identity Federation users can now manage Integrated Portals using the Apigee Cloud console. This previous limitation has been removed from Accessing features only available in the Classic Apigee UI.
On September 8, 2025 we released a new version of the Apigee integrated portal.
Workforce Identity Federation users can now manage Integrated Portals using the Apigee Cloud console. This previous limitation has been removed from Accessing features only available in the Classic Apigee UI.
September 04, 2025
Apigee XApigee policies for LLM/GenAI workloads are Generally Available (GA)
Four new Apigee policies supporting LLM/GenAI workloads are now GA:
The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs. With this release, the semantic caching policies support URL templating, enabling the use of variables for AI model endpoint values.
The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.
For more information on using these policies in your Apigee API proxies, see:
On September 4, 2025, we released an updated version of Apigee.
September 03, 2025
Apigee XOn September 3, 2025, we released an updated version of Apigee.
Apigee Server-Sent Events (SSE) and EventFlows are supported for use with the Apigee Extension Processor.
The Apigee SSE feature enables continuous response streaming from server-sent event (SSE) endpoints to clients in real time. To learn more about this feature, see Streaming server-sent events.
The Apigee Extension Processor is a traffic extension that lets you use Cloud Load Balancing to send callouts from the data processing path of the application load balancer to the Apigee Extension Processor. To learn more, see the Apigee Extension Processor overview.
September 01, 2025
Apigee API hubNew API versions view
API version information is now available as a separate tab in the API details page. You can view your API version details, copy API ID, create new API versions and more using the API versions tab.
For more information, see Manage versions.
August 27, 2025
Apigee XOn August 27, 2025, we released an updated version of Apigee (1-15-0-apigee-9).
| Bug ID | Description |
|---|---|
| 427752569 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities: |
| Bug ID | Description |
|---|---|
| 420901514 | Enhanced WebSocket authentication. |
| 429245088 | Implemented option to override endpoints in the PublishMessage policy. |
| 405039175 | Resolved issue causing duplicate x-b3-* headers when Distributed Trace is enabled. |
| 378686709 | Resolved issue causing unexpected 404 errors when using wildcards in proxy basepaths. |
| 429245268 | Implemented option to override endpoints in the MessageLogging policy. |
| N/A | Updates to security infrastructure and libraries. |
August 26, 2025
Apigee UIOn August 26, 2025, we released an updated version of the Apigee UI.
Debug view settings are now retained when switching between transactions
When switching between transactions in the debug view the following view settings are now retained:
- The state of the expand all toggle
- The zoom level of the graph
- The positioning of the viewport in the graph (best effort). This may be modified due to discrepancies in between the transactions
- The search filter. The active match will go into an indeterminate when switching transactions.
Added Display name column to Apps table
Added a column to the Apps table to show the App display name separate from the App name. The App name column will no longer show the display name if one is set. Instead the display name will appear in the new Display name column. You can also now filter by the App name and Display name independently.
August 25, 2025
Apigee Advanced API SecurityOn August 25, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Additional details and explanations for incidents and traffic identified as anomalous in Abuse Detection Advanced Anomaly Detection
Starting with this release, additional details are available for anomalies detected in incidents and detected traffic, including details on why traffic was flagged as anomalous, the days and times it triggered, time series charts showing anomalous traffic spikes, and direct links to the Google Cloud Logging for events.
See the Abuse detection "Details view" for more information.
On August 25, 2025 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
On August 25, 2025 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
August 22, 2025
Apigee API hubCreate and delete custom plugins in the UI
You can now create and delete custom plugins from the API hub > Settings > Plugins page in the Google Cloud console.
For more information, see Create custom plugins and Manage custom plugins.
Deprovision API hub in the UI
You can now deprovision an API hub instance from the API hub > Settings > Actions page in the Google Cloud console.
For more information, see Deprovision Apigee API hub.
August 20, 2025
Apigee UIOn August 20, 2025, we released an updated version of the Apigee UI.
Added Name column to API Products table
Added a column to the API Products table to display the product name. You can now filter and sort by the product name. The link to the API product detail page is now in the Name column instead of the Display Name column.
August 12, 2025
Apigee API hubAPI observations in API hub (Preview)
API observations in API hub helps you tackle the challenges of undocumented and unmanaged APIs in your API infrastructure. It leverages Apigee shadow API discovery and uses automated discovery processes to bring all your APIs, across Google Cloud projects, into a unified, managed view.
For more information, see API observations in API hub.
On August 12, 2025, we released an updated version of the Apigee UI.
Added path column to Debug transaction table
A new column has been added to the transactions table in the Debug view that specifies the path that was used by the transaction to call the proxy.
| Bug ID | Description |
|---|---|
| 421974963 | Adjusted tooltip positions in Debug sequence view The tooltips for response items in the Debug sequence view now appear at the bottom of the element, so as not to block the elements above. |
| 421975987 | You can no longer pan away from the graph in the Debug canvas The Debug canvas is now restricted and will no longer allow you to pan away from the graph. The scroll wheel on the mouse can now also be used to zoom in and out of the graph. |
| 421975987 | Debug canvas no longer automatically centers when event elements are clicked When clicking an element in the Debug canvas the canvas will no longer automatically center on the selected item. |
August 11, 2025
Apigee Advanced API SecurityOn August 11, 2025 we released an updated version of Advanced API Security Abuse Detection
Improved performance when viewing IP address-specific details for abuse detection incidents
With this release, the IP address detail information for abuse incidents displays more quickly for IP addresses with high traffic volumes, potentially reducing load times from minutes to seconds.
For usage information, see the Abuse Detection incident detail documentation.
August 06, 2025
Apigee Advanced API SecurityOn August 6, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Availability of Shadow API Discovery for APIs in any Google Cloud project
Using Shadow API Discovery, you can find undocumented/shadow APIs in your existing cloud infrastructure. Shadow APIs pose a security risk to your system, since they might be unsecured, unmonitored, and unmaintained.
With this release, you can configure and run API observation jobs in any Google Cloud project, without needing to provision Apigee in that project. You can also centrally view the results of API observation jobs and compare discovered API endpoints and operations to APIs cataloged in API hub to identify shadow APIs.
See the Shadow API Discovery overview for information on Shadow API Discovery and how to add it to projects.
August 04, 2025
Apigee Advanced API SecurityOn August 4, 2025 we announced new functionality in Advanced API Security Abuse Detection.
Terraform support for configuring Advanced API Security
We have expanded our Terraform support for Advanced API Security, enabling you to automate the management of your security posture. You can now use Terraform to manage add-on enablement for Subscription and PAYG environments, create Risk Assessment security profiles and monitoring conditions, configure IP address resolution, and create security actions.
For information, see Configure Advanced API Security using Terraform.
On August 4, 2025, we released an updated version of Apigee (1-15-0-apigee-8).
Server-sent events and EventFlows are Generally Available (GA)
Apigee supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.
Streaming from SSE endpoints is available in Apigee and in Apigee hybrid v1.15.0 and newer.
| Bug ID | Description |
|---|---|
| 435620966 | Fixed a regression that occurred when upgrading from ASM 1.22 to 1.23 that resulted in 503 errors. |
| 422195061 | Enhanced cache lookup performance. |
| 269573358 | Resolved issue with OASValidation policy schema references for parameters without body validation The OASValidation policy correctly resolves and validates schemas passed by reference ( |
| 421141062 | Increased OAS validation limit to 20MB in JSON payloads to prevent validation failures. |
| 417200603 | Improved API connection stability to prevent premature timeouts for long-running requests. |
| 423597917 | POST operations for AppGroupApp keys updated
|
| 390234048 | Resolved issue resulting in missing fields in API responses for Monetization rate plans The |
| 422757662 | Reverted problematic commit regarding X-b3 trace headers send when using distributed tracing. |
| 409048431 | Fixed a SAML signature verification bypass vulnerability. |
| N/A | Updates to security infrastructure and libraries. |
July 31, 2025
Apigee API hubNew data source support for plugins
API hub now supports importing API metadata through new dedicated plugins for the following data sources:
For more information, see Plugins overview.
Push-based plugin ingestion
API hub now supports push-based plugin ingestion. This method allows for more real-time synchronization of API metadata. All new Apigee, Apigee hybrid, Apigee Edge Public Cloud, and Apigee Edge Private Cloud (OPDK) plugins are created with push-based ingestion by default.
For more information, see Plugin data ingestion methods.
Create custom plugins [API only]
You can now use the Create Plugin API to create custom plugins in API hub. Custom plugins are created manually to connect API hub to a specific API data source.
For more information, see Create custom plugins.
Default Apigee plugin instance not auto-created during runtime attachment
Issue: When provisioning API hub as part of Apigee provisioning, the default Apigee X and hybrid plugin instance is not automatically created. This prevents API proxies from being auto-registered.
Workaround: You can manually attach an Apigee runtime instance and import the Apigee assets. See Attach a runtime project.
Delete plugin instance changes
API hub no longer retains any ingested metadata from a plugin after its deletion. Deleting a plugin instance also permanently deletes all the associated API data from API hub.
For more information, see Delete a plugin instance.
Provisioning changes and Apigee API proxy registration
API hub changed how it registers API proxies from Apigee and how it creates default plugin instances during provisioning.
API hub now automatically creates a default Apigee X and hybrid plugin instance and auto-registers API proxies only when you provision it as part of Apigee provisioning.
If you provision API hub directly from the API hub UI, API hub does not automatically create a default plugin instance, nor does it auto-register proxies.
For more information, see Project attachments and plugins.
New tutorial: Enrich API data in API hub
A new tutorial is available for enriching API data in Apigee API hub.
It shows you how to use API hub's custom curation features to automatically fetch OpenAPI specifications from a Cloud Storage bucket and associate them with their corresponding Apigee API proxies. The custom curation logic is defined using an integration in Application Integration.
For more information, see Enrich API data with custom curation in API hub.
Deprecation of Apigee proxy deployment attributes
As of July 31st, 2025, the Apigee X and Hybrid Environment and Apigee X and Hybrid Organization attributes will no longer be added to new Apigee proxy deployments. This change specifically applies when you import deployments into API hub by attaching a runtime project.
If your existing projects use these attributes in filtered search queries, we recommend updating them. To ensure your searches continue to work, use the Source project and Source environment fields as alternatives.
Deprecation of pull-based ingestion for Apigee plugins
Pull-based ingestion is no longer supported for Apigee and Apigee hybrid plugins as of July 31, 2025. For existing projects that have pull-based Apigee X and hybrid plugins configured, these plugins will continue to function and will be automatically migrated to the push-based type starting August 2025.
July 30, 2025
Apigee UIOn July 30, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Develop > API Proxies
- Develop > Shared Flows
- Develop > Offline Debug
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On July 30, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Develop > API Proxies
- Develop > Shared Flows
- Develop > Offline Debug
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
July 29, 2025
Apigee UIOn July 29, 2025 we removed the Switch to Classic option from the following Apigee UI in the Google Cloud console pages:
- API Proxy
- Shared Flow
- Offline Debug detail
This is part of the Apigee Classic UI shutdown plan.
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
July 28, 2025
Apigee XOn July 28, 2025, we released an updated version of Apigee (1-15-0-apigee-7).
Server-sent events and EventFlows are Generally Available (GA)
Apigee supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.
Streaming from SSE endpoints is available in Apigee and in Apigee hybrid v1.15.0 and newer.
| Bug ID | Description |
|---|---|
| 422195061 | Enhanced cache lookup performance. |
| 269573358 | Resolved issue with OASValidation policy schema references for parameters without body validation The OASValidation policy correctly resolves and validates schemas passed by reference ( |
| 421141062 | Increased OAS validation limit to 20MB in JSON payloads to prevent validation failures. |
| 417200603 | Improved API connection stability to prevent premature timeouts for long-running requests. |
| 423597917 | POST operations for AppGroupApp keys updated
|
| 390234048 | Resolved issue resulting in missing fields in API responses for Monetization rate plans The |
| 422757662 | Reverted problematic commit regarding X-b3 trace headers send when using distributed tracing. |
| 409048431 | Fixed a SAML signature verification bypass vulnerability. |
| N/A | Updates to security infrastructure and libraries. |
July 24, 2025
Apigee Integrated PortalOn July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Portals
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Portals
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Portals
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On July 24, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Portals
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
July 22, 2025
Apigee API hubAPI hub provisioning now enables Apigee API
When you provision API hub, it now enables the Apigee API (apigee.googleapis.com) in your Google Cloud project. If Apigee isn't already provisioned, an Apigee organization is also automatically created in your project as part of the provisioning process.
API hub remains a free service. Enabling the Apigee API has no additional pricing or billing implications for your project.
For more information, see Provision API hub in the Cloud console.
VPC Service Controls (VPC-SC) is GA
VPC Service Controls in API hub is now GA.
For more information, see VPC Service Controls for API hub.
API hub deprovisioning changes
Deprovisioning an API hub instance now also deletes any associated Apigee organizations from your Google Cloud project, provided those Apigee organizations have no Apigee instances.
If you deprovision an API hub instance, you can reprovision it later, but you'll need to wait 7 days before you can do so.
For more information, see Deprovision Apigee API hub.
July 18, 2025
Apigee API hubApigee and hybrid plugin instance management
You can now create and delete plugin instances for Apigee and Apigee Hybrid while associating the respective Apigee runtime projects to API hub.
For more information, see Auto-register Apigee proxies.
Apigee and Apigee hybrid plugin creation now requires source project ID
When creating new instances of the Apigee X and hybrid plugin, you must now provide a source project ID. This source project ID is the Google Cloud project from which the plugin will import data.
This is a breaking change and will affect any existing API calls that create these plugins without explicitly providing this ID.
Action Required: Update your API calls to include the appropriate source project ID when creating new Apigee X and hybrid plugins. Failing to do so will result in creation errors.
Resource URI format for Apigee deployments
To ensure optimal functionality and consistency while creating or updating Apigee deployments, we now recommend that the Resource URI conforms to the following format:
organizations/([^/]+)/environments/([^/]+)/apis/([^/]+)$
For more information, see Introduction to deployments.
Edit plugin instances changes
You can now change or modify the name and curation logic of your plugin instance.
For more information, see Edit a plugin instance.
July 14, 2025
Apigee Advanced API SecurityOn July 14, 2025 we released an updated version of Advanced API Security
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Support for editing and deleting security actions
With this release you can edit and delete existing security actions using either the UI or the Apigee Management APIs.
For usage information, see the security actions documentation.
July 09, 2025
Apigee hybridhybrid v1.13.4
On July 9, 2025 we released an updated version of the Apigee hybrid software, 1.13.4.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.13.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 420675540 | Fixed Cassandra based replication for runtime contracts in synchronizer. |
| 401746333 | Fixed a java.lang.ClassCircularityError that could occur in Java Callouts due to an issue with the class loading mechanism. |
| 382565315 | A memory leak within the Security Policy has been addressed, improving system stability. |
| 375360455 | Updated apigee-runtime drain timeout to 300s to fix connection termination issue during pod termination. |
| Bug ID | Description |
|---|---|
| 396944778 | Security fixes for apigee-synchronizer. This addresses the following vulnerabilities: |
| 392934392 | Security fixes for apigee-logger. |
| N/A | Security fixes for apigee-mart-server. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mint-task-scheduler. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-redis. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-runtime. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-synchronizer. This addresses the following vulnerability: |
| N/A | Security fixes for vault. This addresses the following vulnerability: |
July 01, 2025
Apigee Advanced API SecurityOn July 1, 2025 we released a new version of Advanced API Security Abuse Detection.
Support for AppGroups in Abuse Detection attributes
Abuse Detection incidents and detected traffic now show information on AppGroups and AppGroup apps when the AppGroup is part of the request or traffic.
Note: This functionality is not available in Apigee hybrid at this time.
For usage information, see the Abuse Detection documentation.
June 25, 2025
Apigee UIOn June 25, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > API products
- Publish > Developers
- Publish > Apps
- Admin > Instances
- Admin > Data collectors
- Admin > Environments
- Admin > Endpoint attachments
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On June 25, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > API products
- Publish > Developers
- Publish > Apps
- Admin > Instances
- Admin > Data collectors
- Admin > Environments
- Admin > Endpoint attachments
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
June 23, 2025
Apigee AnalyticsOn June 23, 2025 we released an updated version of Apigee.
On June 23, 2025 we released an updated version of Apigee.
Addition of AppGroup-specific Analytics dimensions for Custom Reports
This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.
Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.
For additional information see Analytics dimensions and Creating and managing custom reports.
Addition of AppGroup-specific Analytics dimensions for Custom Reports
This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.
Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.
For additional information see Analytics dimensions and Creating and managing custom reports.
On June 23, 2025 we released a new version of the Apigee integrated portal.
This release adds the Export feature to the Apigee UI in the Cloud console. You can now export publishing data for developers, apps, or API products as a comma-separated values (CSV) file or JSON file.
Documentation: Exporting publishing data
On June 23, 2025 we released an updated version of Apigee.
On June 23, 2025 we released an updated version of Apigee.
On June 23, 2025 we released a new version of the Apigee integrated portal.
Addition of AppGroup-specific Analytics dimensions for Custom Reports
This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.
Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.
For additional information see Analytics dimensions and Creating and managing custom reports.
Addition of AppGroup-specific Analytics dimensions for Custom Reports
This release introduces two new AppGroups Analytics dimensions: AppGroup Name and AppGroup App Name.
Use these dimensions with custom reports and report jobs to group metrics by a specific AppGroup or a specific app within an AppGroup.
For additional information see Analytics dimensions and Creating and managing custom reports.
This release adds the Export feature to the Apigee UI in the Cloud console. You can now export publishing data for developers, apps, or API products as a comma-separated values (CSV) file or JSON file.
Documentation: Exporting publishing data
June 17, 2025
Apigee UIOn June 17, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Monetization
- Analyze > API monitoring
- Analyze > API metrics
- Analyze > Developers > Developer Engagement
- Analyze > Developers > Traffic Composition
- Analyze > End Users > Devices
- Analyze > End Users > Geomap
- Analyze > Custom reports
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
On June 17, 2025 we began redirecting the following Apigee Classic UI navigation items to Apigee UI in the Google Cloud console:
- Publish > Monetization
- Analyze > API monitoring
- Analyze > API metrics
- Analyze > Developers > Developer Engagement
- Analyze > Developers > Traffic Composition
- Analyze > End Users > Devices
- Analyze > End Users > Geomap
- Analyze > Custom reports
See Apigee UI in Cloud console navigation for a mapping of each Classic Apigee UI feature page to its location in the Apigee UI in Cloud console.
See Apigee Classic UI shutdown for details on shutdown dates.
If you require more time to transition to the Google Cloud console, submit the exception request form by Aug 15, 2025.
June 16, 2025
Apigee Advanced API SecurityOn June 16, 2025 we released a new version of Advanced API Security Abuse Detection.
API address drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents in the detected traffic tab.
This new functionality shows details related to specific API addresses when viewing detected abuse in detected traffic.
For usage information, see the Abuse Detection customer documentation for incident details.
On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.
For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.
Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.
For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.
On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On June 16, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.
For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.
Starting with this release, the API proxy performance dashboard includes aggregate metrics such as the average TPS (transactions per second) with each chart.
For information and usage instructions for the API proxy performance dashboard, see the API proxy performance dashboard customer documentation.
June 04, 2025
Apigee Advanced API SecurityOn June 4, 2025 we released an update to the Anomaly Detection model in Advanced API Security Abuse Detection.
New model for Abuse Detection's Advanced Anomaly Detection rule
With this release, we introduced a new and improved machine learning model for anomaly detection in Advanced API Security. This new model includes the following improvements:
- Trained on customer-specific traffic patterns. The new model is trained exclusively on your organization's historical API traffic data. It continues to learn from your API traffic patterns over time to increase accuracy.
- Engineered by Google for anomaly detection. The new model is a custom Vertex AI-based machine learning model, engineered and also used internally by Google specifically to detect anomalies in traffic patterns.
Usage requirements:
- In order to use this new model, you must explicitly opt in to allow the model to use your traffic and other data to train for anomaly detection. Note that your data is never shared with other customers for training purposes.
- The new model is not available for VPC-SC customers at this time.
The new anomaly detection model replaces the old model, with no customer-facing changes to the API or UI. Upon opting in for model training, you can expect to start seeing detected anomalies within 6 hours. If you have already opted in to allow the older version of our anomaly detection model to use your traffic data for training, you will not need to opt in again.
For more information on this model and on Abuse Detection, see Abuse Detection customer documentation, including Detection rules.
hybrid v1.15.0
On June 4, 2025 we released an updated version of the Apigee hybrid software, 1.15.0.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.15.
- For information on new installations, see The big picture.
Large message payload support in Apigee hybrid
Apigee now supports message payloads up to 30MB. You configure support for large message payloads in Apigee hybrid for individual environments or for your whole installation. See Configure large message payload support in Apigee hybrid.
| Bug ID | Description |
|---|---|
| 414499328 | ApigeeTelemetry could become stuck in creating state (Fixed in v1.15.0) |
| 412324617 | Fixed issue where Runtime container could spin at 100% cpu limit. (Fixed in v1.14.2) |
| 399447688 | API proxy deployment could become stuck in PROGRESSING state. (Fixed in v1.14.2) |
| 396886110 | Fixed a bug where the HPA max replicas could be lower than min. (Fixed in v1.14.1) |
| 413708061, 396571537 | Rotating Cassandra credentials in Kubernetes secrets fixed for Multi-region deployments. (Fixed in v1.14.2) |
| 392547038 | Add Helm chart template checks for non-existent environments and virtualhosts. (Fixed in v1.14.1) |
| 391861216 | Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes Known Issue 391861216. (Fixed in v1.14.1) |
| 390258745, 388608440 | Any left over Cassandra snapshots are automatically removed. This fixes known issue 388608440. (Fixed in v1.14.1) |
| 384937220 | Fixed ApigeeRoute name collision on internal chaining gateway for Enhanced Proxy Limits. (Fixed in v1.14.2) |
| 383441226 | Added the following metrics configuration properties:
|
| 368155212 | Auto Cassandra secret rotation could fail when Enhanced per-environment proxy limits are enabled. (Fixed in v1.14.2) |
| 367681534 | Tagging apigee-stackdriver-prometheus-sidecar to prevent removal from customer repos after 2 years due to infrequent updates. (Fixed in 1.14.0-hotfix.1) |
Fixed in this release
Fixed since last minor release
| Bug ID | Description |
|---|---|
| 391923260 | Security fixes for apigee-watcher. (Fixed in v1.14.1) This addresses the following vulnerabilities: |
| 391923260 | Security fixes for apigee-udca. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| 385394193, 383850393, 383778273 | Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. (Fixed in v1.14.1) This addresses the following vulnerabilities: |
| 385394193, 383850393, 383778273 | Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. (Fixed in v1.13.3) This addresses the following vulnerabilities: |
| 383113773, 382967738 | Fixed a vulnerability in PythonScript policy. (Fixed in v1.14.1) |
| 365178914 | Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra. (Fixed in v1.14.1) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-watcher. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-udca. (Fixed in v1.13.3) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-stackdriver-logging-agent. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-redis. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-prometheus-adapter. (Fixed in v1.14.2) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-prometheus-adapter. (Fixed in v1.14.1) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-operators. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. (Fixed in v1.14.1) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mint-task-scheduler. (Fixed in v1.14.2) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mint-task-scheduler. (Fixed in v1.14.1) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-mint-task-scheduler. (Fixed in v1.13.3) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-kube-rbac-proxy. (Fixed in v1.13.3) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-hybrid-cassandra. (Fixed in v1.14.2) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-hybrid-cassandra. (Fixed in v1.14.1) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-hybrid-cassandra. (Fixed in v1.13.3) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-hybrid-cassandra-client. (Fixed in v1.14.2) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-fluent-bit. (Fixed in v1.14.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-fluent-bit. (Fixed in v1.13.3) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-asm-istiod. (Fixed in v1.14.1) This addresses the following vulnerability: |
June 03, 2025
Apigee API hubOn June 3, 2025, we released an updated version of Apigee.
Apigee API hub is enabled for new Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for new Apigee organizations in regions where API hub is supported. All new Apigee organizations, including hybrid organizations, that select an API hub-supported region for their Apigee Analytics region during provisioning will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
On June 3, 2025, we released an updated version of Apigee.
Apigee API hub is enabled for new Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for new Apigee organizations in regions where API hub is supported. All new Apigee organizations, including hybrid organizations, that select an API hub-supported region for their Apigee Analytics region during provisioning will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
June 02, 2025
Apigee Integrated PortalOn June 2, 2025 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 404509044 | When configuring an SMTP server, and the portal is first provisioned, email notifications are sent to portal users from a generic sender address. This release updates that generic address to [email protected]. |
This approach is suitable for evaluation, but you should configure your own SMTP server before launching your portal to users. When you configure the SMTP server, you can also configure the sender address, for example, [email protected].
On June 2, 2025 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 404509044 | When configuring an SMTP server, and the portal is first provisioned, email notifications are sent to portal users from a generic sender address. This release updates that generic address to [email protected]. |
This approach is suitable for evaluation, but you should configure your own SMTP server before launching your portal to users. When you configure the SMTP server, you can also configure the sender address, for example, [email protected].
New flow variables available for VerifyAPIKey policy
Two new flow variables have been added to the VerifyAPIKey policy.
app_group_appapp_group_name
To learn more, see Using flow variables.
On June 2, 2025, we released an updated version of Apigee (1-15-0-apigee-5).
| Bug ID | Description |
|---|---|
| 410670597 | Fixed the proxy response count metric (proxy/response_count) for EventFlow-enabled streaming proxies. |
| 375360455 | Resolved issues with connection termination when using HTTP streaming Added automatic retries for connection reset due to upstream services. |
| N/A | Updates to security infrastructure and libraries. |
| N/A | x-b3 trace headers will be sent only when distributed tracing is enabled. In previous releases Apigee was sending x-b3 trace headers even when distributed tracing was disabled. This was an unexpected behavior which is fixed in this release. |
May 30, 2025
Apigee XOn May 30, 2025 we released an updated version of Apigee.
Announcing the general availability of Gemini Code Assist API development features in Apigee
With this functionality, you can accelerate your API development lifecycle within VS Code using Gemini Code Assist in Apigee. This feature allows you to use natural language prompts to design, create, iterate, and manage OpenAPI specifications with the following capabilities:
- AI-Powered API Design: Generate high-quality OpenAPI specifications from natural language prompts to the Apigee tool in Gemini Code Assist Chat, leveraging the Gemini model and the enterprise context of your API hub.
- Effortless Iteration: Refine existing or newly generated specifications using the intuitive Gemini chat interface.
- Integrated Testing: Quickly validate your APIs by deploying them to a local or Google Cloud-hosted mock server.
- Streamlined Workflow: Publish your completed API specifications directly to Apigee API hub and kick-start proxy development by creating Apigee proxy bundles from your API specifications.
- Duplicate Endpoint Detection: Proactively identify and prevent the creation of duplicate API endpoints already registered in your API hub.
For more information and usage instructions, see Designing and editing APIs, Tutorial: Use Gemini Code Assist to design, develop, and test APIs in Apigee, and Setting up Apigee API Management in Cloud Code for VS Code.
May 29, 2025
Apigee Integrated PortalOn May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
On May 29, 2025 we released a new version of the Apigee integrated portal.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
GA: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.
This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.
Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.
No new APIs have been introduced in this release.
See Publishing overview to get started.
On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
On May 29, 2025 we released a new version of the Apigee integrated portal.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
GA: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.
This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.
Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.
No new APIs have been introduced in this release.
See Publishing overview to get started.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
On May 29, 2025, we released an updated version of Apigee.
Public Preview: Apigee Extension Processor support for request and response body processing
When creating a load balancer service extension, you can customize the behavior of the extension processor proxy to support request body processing, response body processing, or a combination of the two.
For more information, see Get started with the Apigee Extension Processor.
On May 29, 2025 we announced the shutdown schedule for the Apigee Classic UI.
The Apigee Classic UI will be shutdown as of August 29, 2025.
This is the final phase of moving Apigee to the Google Cloud console. Apigee in the Google Cloud console gives you the ability to manage all of your Apigee functionality in one place.
To prepare for the shutdown of the Apigee Classic UI, familiarize yourself with the new Apigee UI in Google Cloud console by reviewing UI overview.
See Apigee Classic UI shutdown for details on shutdown dates and exception request.
May 27, 2025
Apigee Advanced API SecurityOn May 27, 2025 we released an updated version of Apigee Advanced API Security.
With this release, Advanced API Security expands its runtime region support to include africa-south1 (Johannesburg).
For a list of supported regions, see Apigee locations.
May 22, 2025
Apigee XOn May 22, 2025, we released an updated version of Apigee.
Public preview of server-sent events
Apigee now supports continuous response streaming from server-sent event (SSE) endpoints to clients in real time. The Apigee SSE feature is useful for handling large language model (LLM) APIs that operate most effectively by streaming their responses back to the client. SSE streaming reduces latency, and clients can receive response data as soon as it is generated by an LLM. This feature supports the use of AI agents that operate in real time environments, such as customer service bots or workflow orchestrators. For more information, see Streaming server-sent events.
Public Preview of Apigee policies for LLM/GenAI workloads
Four new Apigee policies supporting LLM/GenAI workloads are now available in Public Preview:
The Apigee semantic caching policies enable intelligent response reuse based on semantic similarity. Using these policies in your Apigee API proxies can minimize redundant backend API calls, reduce latency, and lower operational costs.
The Model Armor policies protect your AI applications by sanitizing user prompts to and responses from large language models (LLMs). Using these policies in your Apigee API proxies can mitigate the risks associated with LLM usage by leveraging Model Armor to detect prompt injection, prevent jailbreak attacks, apply responsible AI filters, filter malicious URLs, and protect sensitive data.
For more information on using these policies in your Apigee API proxies, see:
May 21, 2025
Apigee API hubApigee API hub is now available in the following regions:
- europe-west10 (Berlin)
- us-east5 (Columbus)
- us-south1 (Dallas)
- me-central2 (Dammam)
- asia-south2 (Delhi)
- me-central1 (Doha)
- europe-north1 (Finland)
- europe-west3 (Frankfurt)
- asia-east2 (Hong Kong)
- asia-southeast2 (Jakarta)
- africa-south1 (Johannesburg)
- us-west4 (Las Vegas)
- us-west2 (Los Angeles)
- europe-southwest1 (Madrid)
- australia-southeast2 (Melbourne)
- europe-west8 (Milan)
- northamerica-northeast1 (Montréal)
- europe-west4 (Netherlands)
- asia-northeast2 (Osaka)
- us-west3 (Salt Lake City)
- southamerica-west1 (Santiago)
- asia-northeast3 (Seoul)
- us-east1 (South Carolina)
- asia-east1 (Taiwan)
- me-west1 (Tel Aviv)
- asia-northeast1 (Tokyo)
- northamerica-northeast2 (Toronto)
- europe-west12 (Turin)
- europe-central2 (Warsaw)
- europe-west6 (Zürich)
For more information, see API hub locations.
May 20, 2025
Apigee Advanced API SecurityOn May 20, 2025 we released a new version of Advanced API Security Abuse Detection.
Advanced API Security Abuse Detection incident reports now include the ability to view raw data
With this new functionality, you can view raw data underlying an incident report, including client IP address, API proxy, developer app, and other attributes.
For usage information, see the Abuse Detection customer documentation.
May 16, 2025
Apigee API hubUpdated UI for API hub
The API hub user interface is now updated to Google Material Design 2. This update provides a more consistent and modern look and feel, enhancing the overall user experience and aligning the UI with other Google Cloud products.
Attach and manage Tags
You can now add custom tags to your APIs and API deployments, making it easier to organize, categorize, and discover your API resources in API hub. Tags can also be used to conditionally allow or deny policies to a specific resource.
For more information see Attach and manage tags.
API overview and metrics
The Get Started with API hub page now includes new charts and scorecards to provide a quick overview of your API landscape.
For more information see Get started with API hub.
hybrid 1.14.2-hotfix.1
On May 16, 2025 we released an updated version of the Apigee hybrid software, 1.14.2-hotfix.1.
Apply this hotfix with the following steps:
Download the
apigee-organdapigee-envcharts with the1.14.2-hotfix.1version tag:export CHART_REPO=oci://us-docker.pkg.dev/apigee-release/apigee-hybrid-helm-charts
export CHART_VERSION=1.14.2-hotfix.1helm pull $CHART_REPO/apigee-env --version $CHART_VERSION --untarhelm pull $CHART_REPO/apigee-org --version $CHART_VERSION --untarOptional: Perform this step if you need to allow use of the
allOfcombinator along with settingadditionalProperties: truein your OAS spec. See fixed bug 393615439.Add the following stanza to your
overrides.yaml:runtime: cwcAppend: conf_message-processor-communication_oas.disable.resolve.combinator: trueInstall the hotfix release:
Update the
apigee-envchart with thehelm upgradecommand and your current overrides file for each environment in your Apigee org:Dry run:
helm upgrade ENV_RELEASE_NAME apigee-env/ \ --namespace APIGEE_NAMESPACE \ --set env=ENV_NAME \ --atomic \ -f OVERRIDES_FILE \ --dry-run=server
- ENV_RELEASE_NAME is a name used to keep track of installation and upgrades of the
apigee-env chart. This name must be unique from the other Helm release names in your installation. Usually this is the same as ENV_NAME. However, if your environment has the same name as your environment group, you must use different release names for the environment and environment group, for exampledev-env-releaseanddev-envgroup-release. For more information on releases in Helm, see Three big concepts in the Helm documentation. - APIGEE_NAMESPACE is your installation's namespace. The default is
apigee. - ENV_NAME is the name of the environment you are upgrading.
- OVERRIDES_FILE is your edited overrides file.
Install the changes:
helm upgrade ENV_RELEASE_NAME apigee-env/ \ --namespace APIGEE_NAMESPACE \ --set env=ENV_NAME \ --atomic \ -f OVERRIDES_FILE
- ENV_RELEASE_NAME is a name used to keep track of installation and upgrades of the
Update the
apigee-orgchart:Dry run:
helm upgrade ORG_NAME apigee-org/ \ --namespace APIGEE_NAMESPACE \ -f OVERRIDES_FILE \ --dry-run=server
Install the changes:
helm upgrade ORG_NAME apigee-org/ \ --namespace APIGEE_NAMESPACE \ -f OVERRIDES_FILE
Verify the installation:
Ensure runtime and udca pods are up and running by checking their state:
kubectl -n APIGEE_NAMESPACE get pods -l app=apigee-runtime
kubectl -n APIGEE_NAMESPACE get pods -l app=apigee-udca
- For information on upgrading, see Upgrading Apigee hybrid to version 1.14.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 393615439 | OASValidation behavior for allOf with additionalProperties: true.
Issue
The OASValidation policy in Apigee Hybrid versions 1.12 and later may incorrectly reject requests when validating against an OpenAPI Specification (OAS) that uses combinator keywords ( ResolutionA configuration flag has been introduced to control this behavior. By setting this flag, you can disable the pre-validation combinator resolution step, reverting to the behavior consistent with Apigee Edge and older Hybrid versions. Validation errors in Apigee hybridIf you encounter the validation errors described above, particularly for specs that worked correctly in Apigee Edge or Hybrid versions prior to 1.12, you can revert to the previous validation behavior by setting the following flag for the apigee-runtime container: conf_message-processor-communication_oas.disable.resolve.combinator = true |
| Bug ID | Description |
|---|---|
| N/A | Incorporated an updated base image for stackdriver-logging-agent, improving the overall security of the service. This addresses the following vulnerabilities (among others and not limited to): |
May 14, 2025
Apigee XOn May 14, 2025, we released an updated version of Apigee (1-15-0-apigee-4).
Improvements to the AppGroups functionality
Scopes and attributes can now be added to the AppGroup App Key via a POST operation on the key using the appGroupAppKey. See the updateAppGroupAppKey API for details.
Large message payload support in Apigee
Apigee now supports message payloads up to 30MB. For more information, see:
- Message payload size.
Propertiesin the ProxyEndpoint configuration elements reference.Propertiesin the TargetEndpoint configuration elements reference.
Improvements to the PublishMessage policy
The PublishMessage policy now supports two new elements:
The <UseMessageAsSource> element uses request or response message content as the source of data to be written to Pub/Sub. For more information, see <UseMessageAsSource>.
The <Attributes> element lets you specify string attributes (key/value pairs) to include with the request or response message that is written to Pub/Sub. For more information, see <Attributes>.
| Bug ID | Description |
|---|---|
| 391140293 | Resolved scaling issue resulting in 503 errors Added |
| 391862684 | Resolved issue with requests stuck at Message Processor causing timeouts. |
| N/A | Updates to security infrastructure and libraries. |
May 06, 2025
Apigee UIOn May 6, 2025, we released a new Apigee REST resource for debug sessions.
Apigee now offers a Management API that allows users to list all recent debug sessions for a given proxy, regardless of revision or environment and current deployment status. This API is available for use, and is now used to populate all recent debug sessions in the Apigee Debug UI.
For more information on this method, see: organizations.apis.debugsessions.list
On May 6, 2025, we released a new Apigee REST resource for debug sessions.
Apigee now offers a Management API that allows users to list all recent debug sessions for a given proxy, regardless of revision or environment and current deployment status. This API is available for use, and is now used to populate all recent debug sessions in the Apigee Debug UI.
For more information on this method, see: organizations.apis.debugsessions.list
May 05, 2025
Apigee UI| Bug ID | Description |
|---|---|
| 402183688 | Resolved navigation issue when creating a new flow in the Apigee Proxy Editor In some instances, adding a flow to an Apigee endpoint using the Apigee Proxy Editor resulted in redirection to a |
On May 5, 2025, we released an updated version of the Apigee UI.
May 02, 2025
Apigee XOn May 2, 2025, we released an updated version of Apigee (1-15-0-apigee-3).
Large message payload support in Apigee
Apigee now supports message payloads up to 30MB. For more information, see:
- Message payload size.
Propertiesin the ProxyEndpoint configuration elements reference.Propertiesin the TargetEndpoint configuration elements reference.
Improvements to the PublishMessage policy
The PublishMessage policy now supports two new elements:
The <UseMessageAsSource> element uses request or response message content as the source of data to be written to Pub/Sub. For more information, see <UseMessageAsSource>.
The <Attributes> element lets you specify string attributes (key/value pairs) to include with the request or response message that is written to Pub/Sub. For more information, see <Attributes>.
| Bug ID | Description |
|---|---|
| 391140293 | Resolved scaling issue resulting in 503 errors Added |
| 391862684 | Resolved issue with requests stuck at Message Processor causing timeouts. |
| N/A | Updates to security infrastructure and libraries. |
hybrid v1.14.2
On May 2, 2025 we released an updated version of the Apigee hybrid software, 1.14.2.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.14.
- For information on new installations, see The big picture.
Large message payload support in Apigee hybrid
Apigee now supports message payloads up to 30MB. For information see:
- Message payload size
runtime.resources.limits.memoryin the Configuration property reference.runtime.resources.requests.memoryin the Configuration property reference.
Starting with v1.14.2, third-party container images will be labeled with a version tag that matches the Apigee hybrid image tag. This affects the image tags returned by the apigee-pull-push command line tool. For more information, see:
| Bug ID | Description |
|---|---|
| 412324617 | Fixed issue where Runtime container could spin at 100% cpu limit. |
| 401746333 | Fixed a java.lang.ClassCircularityError that could occur in Java Callouts due to an issue with the class loading mechanism. |
| 399447688 | API proxy deployment could become stuck in PROGRESSING state. |
| 397693324 | ESS and non-ESS Multi-region Cassandra credential rotation could fail in every region except the first. |
| 396571537 | Rotating Cassandra credentials in Kubernetes secrets fixed for Multi-region deployments. |
| 384937220 | Fixed ApigeeRoute name collision on internal chaining gateway for Enhanced Proxy Limits. |
| 368155212 | Auto Cassandra secret rotation could fail when Enhanced per-environment proxy limits are enabled. |
| Bug ID | Description |
|---|---|
| 391923260 | Security fixes for apigee-udca. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-hybrid-cassandra. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-hybrid-cassandra-client. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mint-task-scheduler. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-operators. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-prometheus-adapter. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-redis. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-stackdriver-logging-agent. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-watcher. This addresses the following vulnerabilities: |
April 29, 2025
Apigee API hubApigee API hub is enabled for existing Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for existing Apigee organizations in regions where API hub is supported. All existing Apigee organizations, including hybrid organizations, that selected an API hub-supported region for their Apigee Analytics region will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
The process of enabling API hub for these organizations will continue over the next several weeks until all eligible organizations are updated. No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
On April 29, 2025, we released an updated version of Apigee.
Apigee API hub is enabled for existing Apigee organizations in supported regions.
With this release, we are enabling Apigee API hub for existing Apigee organizations in regions where API hub is supported. All existing Apigee organizations, including hybrid organizations, that selected an API hub-supported region for their Apigee Analytics region will have access to API hub features at no additional cost.
API hub allows you to view, organize, and manage all of the APIs in your Apigee organization in one central location. To learn more, see What is Apigee API hub?
The process of enabling API hub for these organizations will continue over the next several weeks until all eligible organizations are updated. No action on your part is required to provision API hub for your organization, with the following exceptions:
- If your Apigee organization has Data Residency or VPC Service Controls enabled, you must configure your API hub instance manually to support these services. See VPC Service Controls for API hub and API hub and data residency for more information.
- If your Apigee organization uses Customer-Managed Encryption Keys (CMEK), you must deprovision the Apigee API hub instance provided by default and recreate it to support CMEK. See Deprovision Apigee API hub and Provision API hub in the Cloud console for step-by-step instructions.
Contact Google Cloud Support for questions or assistance.
On April 29, 2025, we released an updated version of Apigee.
April 22, 2025
Apigee Integrated PortalOn April 22, 2025 we released a new version of the Apigee integrated portal.
Public Preview: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.
This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.
Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.
No new APIs have been introduced in this release.
See Publishing overview to get started.
On April 22, 2025 we released a new version of the Apigee integrated portal.
Public Preview: Apigee Integrated Developer Portal Admin UI in the Google Cloud console.
This release adds the Apigee Integrated Developer Portal Admin UI from the Classic Apigee UI into the Google Cloud console.
Leveraging Google Cloud console components provides API providers and Portal Admins with a centralized platform to efficiently configure, publish, and manage your API consumer portals, eliminating the need to switch between different UIs.
No new APIs have been introduced in this release.
See Publishing overview to get started.
April 15, 2025
Apigee AnalyticsOn April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
On April 15, 2025 we released an updated version of Apigee Analytics and the Apigee UI.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
Starting with this release, the Analytics dashboards available in the Apigee Classic UI redirect to the comparable dashboards in Apigee UI in Cloud console. These dashboards are available exclusively in the Apigee UI in Cloud console going forward.
For information and usage instructions for the Analytics dashboards, see Apigee API Analytics overview.
April 14, 2025
Apigee XOn April 14, 2025 we released an updated version of Apigee.
Announcing data collectors data residency (DRZ) compliance for Apigee and Apigee hybrid.
Data collectors can be used with data residency for Subscription and Pay-as-you-go organizations and hybrid versions 1.14.0 and later.
See Data residency compatibility for information.
On April 14, 2025 we released an updated version of Apigee.
Announcing data collectors data residency (DRZ) compliance for Apigee and Apigee hybrid.
Data collectors can be used with data residency for Subscription and Pay-as-you-go organizations and hybrid versions 1.14.0 and later.
See Data residency compatibility for information.
hybrid 1.11.2-hotfix.3
On April 14, 2025 we released an updated version of the Apigee hybrid software, 1.11.2-hotfix.3.
Apply this hotfix with the following steps:
In your overrides file, update the
image.urlandimage.tagproperties ofaoandruntime:runtime: image: url: "gcr.io/apigee-release/hybrid/apigee-runtime" tag: "1.11.2-hotfix.3"Install the hotfix release:
For Helm-managed releases, update the
apigee-envchart with thehelm upgradecommand and your current overrides files:For each environment in your Apigee org:
helm upgrade ENV_RELEASE_NAME apigee-env/ \ --namespace APIGEE_NAMESPACE \ --set env=ENV_NAME \ --atomic \ -f OVERRIDES_FILE- ENV_RELEASE_NAME is a name used to keep track of installation and upgrades of the
apigee-env chart. This name must be unique from the other Helm release names in your installation. Usually this is the same as ENV_NAME. However, if your environment has the same name as your environment group, you must use different release names for the environment and environment group, for exampledev-env-releaseanddev-envgroup-release. For more information on releases in Helm, see Three big concepts in the Helm documentation. - APIGEE_NAMESPACE is your installation's namespace. The default is
apigee. - ENV_NAME is the name of the environment you are upgrading.
- OVERRIDES_FILE is your edited overrides file.
- ENV_RELEASE_NAME is a name used to keep track of installation and upgrades of the
For
apigeectl-managed releases:Install the hotfix release with
apigeectl initusing your updated overrides file:${APIGEECTL_HOME}/apigeectl init -f OVERRIDES_FILE --dry-run=clientFollowed by:
${APIGEECTL_HOME}/apigeectl init -f OVERRIDES_FILEApply the hotfix release with
apigeectl apply:${APIGEECTL_HOME}/apigeectl apply -f OVERRIDES_FILE --all-envs --dry-run=clientFollowed by:
${APIGEECTL_HOME}/apigeectl apply -f OVERRIDES_FILE --all-envs
- For information on upgrading, see Upgrading Apigee hybrid to version 1.11.
- For information on new installations, see The big picture.
- For recommended actions after upgrading, see Validate policies after upgrade to 1.12-hotfix.3.
Stricter class instantiation checks included in this release.
JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.
In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.
To test your installation, follow the procedure in Validate policies after upgrade to 1.11.2-hotfix.3 to validate policy behavior.
| Bug ID | Description |
|---|---|
| 382967738 | Fixed a vulnerability in PythonScript policy. |
April 10, 2025
Apigee XThe Apigee Extension Processor is now generally available (GA).
The Apigee Extension Processor lets Apigee customers add API management capabilities to Google Cloud and third-party products and services exposed using Cloud Load Balancing. Select from a range of Apigee policies that enable you to:
- Secure access to your workloads.
- Apply quota enforcement to network traffic.
- Manage Google access token and Google ID token injection to authenticate requests.
- Support native protocols like gRPC, SSE, and HTTP/3.
For more information, see the Apigee Extension Processor overview.
On April 10, 2025, we released an updated version of Apigee.
April 02, 2025
Apigee API hubVPC Service Controls (VPC-SC) integration (Preview)
API hub now integrates with VPC Service Controls, providing enhanced network security for your API hub instance provisioned in Google Cloud. Establish service perimeters to control ingress and egress traffic. For more information, see VPC Service Controls for API hub.
Data residency zone compliance
API hub is now compliant with data residency Zone C3 requirements.
For more information, see API hub and data residency.
Terraform support for provisioning
You can now provision API hub instances programmatically using Terraform for Google Cloud within Cloud Shell, enabling infrastructure-as-code practices. For more information, see Provision API hub using Terraform.
Attach API documents
You can now enhance your API documentation by attaching additional relevant files, such as requirements, design documents, and functionality details, directly to your APIs in API hub.
Deprovision an API hub instance [API only]
You can now delete an API hub instance from your Google Cloud project using the ApiHubInstance API. For more information, see Deprovision Apigee API hub.
API Supply chain graph view
Visualize and understand the dependencies within your API ecosystem with the new interactive API supply chain graph view. This directed graph allows you to explore the relationships between your APIs and API operations. For more information, see API Supply chain views.
API Metadata Curations
API hub introduces a curation process to transform and enrich API metadata ingested by plugins. This ensures consistency across different sources, enabling effective governance, discovery, and management of your APIs. For more information, see Curations overview.
Enhancements to the Operations entity [API only]
You can now add, edit, or delete operations for an API version even if it lacks a specification file or has an unparsable one. For more information, see Manage operations.
Plugin Framework
API hub now uses a plugin framework to connect and ingest API metadata from various Google Cloud services and external sources where your APIs are managed or defined. This provides a flexible and extensible way to integrate with your existing API landscape. For more information, see Plugins overview.
March 31, 2025
Apigee XNew flow variable suffixes available for accessing base64-encoded message content.
There are two new read-only flow variable suffixes available for accessing message content in base64-encoded form:
content.as.base64content.as.url.safe.base64
These variable suffixes can be used with the request, response, and message objects, as well as with any Message object created implicitly during API proxy execution when using the AssignMessage or ServiceCallout policies.
For more information, see Flow variables reference.
On March 31, 2025, we released an updated version of Apigee (1-15-0-apigee-2).
| Bug ID | Description |
|---|
| N/A | Updates to security infrastructure and libraries.
March 27, 2025
Apigee XOn March 27, 2025, we released an updated version of Apigee.
Availability of client IP resolution functionality with Apigee hybrid.
Client IP resolution functonality is now available with Apigee hybrid versions 1.14.0 and later.
See Client IP resolution for information.
On March 26, 2025, we released an updated version of Apigee (1-14-0-apigee-5). This Apigee version applies only to organizations using the JavaCallout policy in production environments.
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
On March 27, 2025, we released an updated version of Apigee.
Availability of client IP resolution functionality with Apigee hybrid.
Client IP resolution functonality is now available with Apigee hybrid versions 1.14.0 and later.
See Client IP resolution for information.
March 25, 2025
Apigee Advanced API SecurityOn March 25, 2025 we released an updated version of Advanced API Security.
Risk Assessment v2 is now the default Risk Assessment version
Starting with this release, Risk Assessment v2 is the default Risk Assessment version in the UI. You will see the see v2 functionality and interfaces unless you choose to switch back to v1 by clicking Switch to v1 in the upper right of the UI.
Note: Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New features added to public preview of Risk Assessment v2
This release introduces new features to the Risk Assessment v2 preview:
- Security monitoring conditions. Security monitoring conditions allow you to map resources (proxies or environments) to security profiles. Cloud Monitoring can then use this mapping to alert or create dedicated dashboards so that you can track security scores over time.
- Alerts on security monitoring conditions. Once you've created a monitoring condition, you can set up alerts using Alerting in Cloud Monitoring so that you're notified when the security scores change.
For information on monitoring conditions features and usage see monitoring conditions and alerts. For usage information and a list of all features in Risk Assessment v2, see the Risk Assessment v2 customer documentation.
Note: Rollouts of this functionality to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New Advanced API Security support when using data residency (DRZ) with Apigee hybrid
Advanced API Security is now available for Apigee hybrid orgs using DRZ, for hybrid versions 1.14.0 and later. See Using data residency with Apigee hybrid.
See Introduction to data residency for information on DRZ and Advanced API Security support across organization types.
On March 25, 2025 we released an updated version of Advanced API Security.
New Advanced API Security support when using data residency (DRZ) with Apigee hybrid
Advanced API Security is now available for Apigee hybrid orgs using DRZ, for hybrid versions 1.14.0 and later. See Using data residency with Apigee hybrid.
See Introduction to data residency for information on DRZ and Advanced API Security support across organization types.
March 24, 2025
Apigee XOn March 24, 2025, we released an updated version of Apigee.
Apigee Spaces is now generally available (GA) for use in Apigee organizations.
Apigee Spaces enables identity-based isolation and grouping of API resources within an Apigee organization. With Apigee Spaces, you can have granular IAM control over access to your API proxies, shared flows, and API products.
Spaces also provide the option of resource isolation at a team level, providing a clear separation of resources associated with different teams operating within the same Apigee organization. IAM policies can be applied at the Space level, eliminating the need to manage permissions individually for every API proxy, shared flow, and API product.
Spaces are a brand new resource type with resource-level permissions. This means that Space permissions are not subject to the 64k limitation for project-level IAM conditions. Each space has its own 64k limit.
To learn more, see Apigee Spaces overview.
March 17, 2025
Apigee XOn March 17, 2025, Apigee announced the GA support for DNS peering for Apigee organizations that have VPC peering disabled.
For Apigee organizations set up without VPC peering, you can now configure Apigee to resolve your private domains by peering your DNS zones with Apigee. See Connecting with private DNS peering zones.
March 14, 2025
Apigee UIOn March 14, 2025, we released an updated version of the Apigee UI.
| Bug ID | Description |
|---|---|
| 401574741 | Fixed issue with loading API resource and path configurations when opening the Product detail pages of legacy API products. API resources and paths are now properly populated and applied when viewing the Product detail pages for legacy API products in the Apigee UI. |
March 12, 2025
Apigee UIWith this release, the Filter display name for the proxy field in the Custom reports page of the Apigee UI in Cloud console is changed to Proxy Endpoint.
This change should help users differentiate between Proxy and Proxy Endpoint values when configuring filters for custom reports using Apigee API Analytics.
For more information, see [Creating and managing custom reports](/apigee/docs/api-platform/analytics/create-custom-reports#setting-filters).
On March 12, 2025, we released an updated version of the Apigee UI.
On March 12, 2025, we released an updated version of Apigee (1-15-0-apigee-1).
| Bug ID | Description |
|---|---|
| 396944778 | Security fix for Apigee infrastructure. This addresses the following vulnerabilities: |
The Nimbus JOSE + JWT library may cause a java.lang.ClassCircularityError when using a JavaCallout policy.
For more information, see Apigee known issues.
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
v1.13.3 , v1.14.1, v1.12.4
The Nimbus JOSE + JWT library may cause a java.lang.ClassCircularityError when using a JavaCallout policy.
For more information, see Apigee known issues.
March 11, 2025
Apigee Integrated PortalOn March 11, 2025 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 380076166 | For an app in a portal, the status for each key will now show approved, revoked, partially approved or inactive based on the approval status of all the API products on that key (or if the key has been revoked). Additionally, the status of an API Product for an app will show approved, partially approved, or pending approval based on the approval status for all keys associated to that API product. If a key is revoked, it will not effect the approval status of the API product. |
On March 11, 2025 we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 380076166 | For an app in a portal, the status for each key will now show approved, revoked, partially approved or inactive based on the approval status of all the API products on that key (or if the key has been revoked). Additionally, the status of an API Product for an app will show approved, partially approved, or pending approval based on the approval status for all keys associated to that API product. If a key is revoked, it will not effect the approval status of the API product. |
March 07, 2025
Apigee Advanced API SecurityOn March 7, 2025 we released an updated version of Apigee Advanced API Security.
Availability of data obfuscation support with Advanced API Security
With this release, data obfuscation can be used with Advanced API Security.
For usage information, see Obfuscate user data for Apigee API Analytics and Data obfuscation with Advanced API Security.
March 05, 2025
Apigee UI| Bug ID | Description |
|---|---|
| 368686537 | Resolved issue causing delay when loading API product pages in the Apigee UI in Cloud console. Members of Apigee organizations with large number of API proxies experienced long load times when accessing the API product create or API product edit pages in the Apigee UI in Cloud console. |
On March 5, 2025, we released an updated version of the Apigee UI.
March 01, 2025
Apigee hybrid| Bug ID | Description |
|---|---|
| 396886110 | Fixed a bug where the HPA max replicas could be lower than min. |
| 392547038 | Add Helm chart template checks for non-existent environments and virtualhosts. |
| 391861216 | Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes Known Issue 391861216. |
| 390019667 | Fixed bug where the daemonsets had an invalid pod disruption budget which prevented downscaling. |
| 383441226 | Added the following metrics configuration properties:
|
| 382565315 | LogTimer usage in SecurityPolicy could cause a memory leak. |
Manage process ID limits
The procedure to manage the process ID limits in your clusters has been added to the documentation.
A Process ID limit is a Kubernetes resource constraint on nodes and pods to prevent excessive process creation, which can impact node stability. Setting process ID limits in Kubernetes can improve system stability, security, and resource management. This is also consistent with Kubernetes best practices. Apigee Hybrid supports the Kubernetes feature to set process ID limits.
See: Manage process ID limits.
hybrid v1.14.1
On March 1, 2025 we released an updated version of the Apigee hybrid software, 1.14.1.
This release enhances the security posture within the JavaCallout and PythonScript policies. This release does not include any new features or general bug fixes.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.14.
- For information on new installations, see The big picture.
- For recommended actions after upgrading, see Validate policies after upgrade to 1.14.1.
Stricter class instantiation checks included in this release.
JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.
In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.
To test your installation, follow the procedure in Validate policies after upgrade to 1.14.1 to validate policy behavior.
| Bug ID | Description |
|---|---|
| 385394193, 383850393, 383778273 | Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. This addresses the following vulnerabilities: |
| 383113773, 382967738 | Fixed a vulnerability in PythonScript policy. |
| 365178914 | Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-asm-istiod. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-hybrid-cassandra. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mint-task-scheduler. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerability: |
| 392174215 | Security fixes for apigee-operator. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-prometheus-adapter. This addresses the following vulnerabilities: |
| 391786033 | Security fixes for apigee-watcher. This addresses the following vulnerability: |
| 388271708 | Security fix for Apigee infrastructure This addresses the following vulnerability:
|
Stricter class instantiation checks included in this release.
JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.
In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.
To test your installation, follow the procedure in Validate policies after upgrade to 1.13.3 to validate policy behavior.
| Bug ID | Description |
|---|---|
| Bug ID | Description |
| 385394193, 383850393, 383778273 | Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. This addresses the following vulnerabilities: |
| 382967738 | Fixed a vulnerability in PythonScript policy. |
| N/A | Security fixes for apigee-envoy. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-mint-task-scheduler. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerability: |
| 392174215 | Security fixes for apigee-operator. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-redis. This addresses the following vulnerabilities: |
| 391786033 | Security fixes for apigee-watcher. This addresses the following vulnerability: |
| N/A | Security fixes for livenessprobe. This addresses the following vulnerability: |
| 388271708 | Security fix for Apigee infrastructure This addresses the following vulnerability:
|
hybrid v1.13.3
On March 1, 2025 we released an updated version of the Apigee hybrid software, 1.13.3.
This release enhances the security posture within the JavaCallout and PythonScript policies. This release does not include any new features or general bug fixes.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.13.
- For information on new installations, see The big picture.
- For recommended actions after upgrading, see Validate policies after upgrade to 1.13.3.
Manage process ID limits
The procedure to manage the process ID limits in your clusters has been added to the documentation.
A Process ID limit is a Kubernetes resource constraint on nodes and pods to prevent excessive process creation, which can impact node stability. Setting process ID limits in Kubernetes can improve system stability, security, and resource management. This is also consistent with Kubernetes best practices. Apigee Hybrid supports the Kubernetes feature to set process ID limits.
See: Manage process ID limits.
| Bug ID | Description |
|---|---|
| 396886110 | Fixed a bug where the HPA max replicas could be lower than min. |
| 391861216 | Restore for Google Cloud Platform and HYBRID Cloud Providers no longer affects system keyspaces. This fixes Known Issue 391861216. |
| 390258745, 388608440 | Any left over Cassandra snapshots are automatically removed. This fixes known issue 388608440. |
| 390019667 | Fixed bug where the daemonsets had an invalid pod disruption budget which prevented downscaling. |
| 383441226 | Added the following metrics configuration properties:
|
| 382565315 | LogTimer usage in SecurityPolicy could cause a memory leak. |
hybrid v1.12.4
On March 1, 2025 we released an updated version of the Apigee hybrid software, 1.12.4.
This release enhances the security posture within the JavaCallout and PythonScript policies. This release does not include any new features or general bug fixes.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.12.
- For information on new installations, see The big picture.
- For recommended actions after upgrading, see Validate policies after upgrade to 1.12.4.
Stricter class instantiation checks included in this release.
JavaCallout policy now includes additional security during Java class instantiation. The enhanced security measure prevents the deployment of policies that directly or indirectly attempt actions that require permissions that are not allowed.
In most cases, existing policies will continue to function as expected without any issues. However, there is a possibility that policies relying on third-party libraries, or those with custom code that indirectly triggers operations requiring elevated permissions, could be affected.
To test your installation, follow the procedure in Validate policies after upgrade to 1.12.4 to validate policy behavior.
| Bug ID | Description |
|---|---|
| 391923260 | Security fixes for apigee-watcher. This addresses the following vulnerabilities: |
| 385394193, 383850393, 383778273 | Security fixes for apigee-cassandra-backup-utility, apigee-cassandra-client, and apigee-hybrid-cassandra. This addresses the following vulnerabilities: |
| 382967738 | Fixed a vulnerability in PythonScript policy. |
| 365178914 | Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-fluent-bit. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-mint-task-scheduler. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerability: |
| N/A | Security fixes for apigee-udca. This addresses the following vulnerability: |
| 388271708 | Security fix for Apigee infrastructure This addresses the following vulnerability:
|
| Bug ID | Description |
|---|---|
| 390258745, 388608440 | Any left over Cassandra snapshots are automatically removed. This fixes known issue 388608440. |
February 28, 2025
Apigee X| Bug ID | Description |
|---|---|
| 382883585 | Fixed a vulnerability in the JavaCallout policy. |
| N/A | Updates to security infrastructure and libraries. |
On February 28, 2025, we released an updated version of Apigee (1-14-0-apigee-8).
February 27, 2025
Apigee UIOn February 27, 2025, we released an updated version of the Apigee Proxy Debug tool.
Overview
This release introduces a redesigned debugging experience for API proxies in the Apigee UI, which is available in Google Cloud console.
This new feature, Debug Sequence View (v2), addresses user feedback and aims to streamline the process of identifying and resolving issues in your API proxies.
We believe that Debug Sequence View will significantly improve the API proxy debugging experience. We encourage you to try it out and provide your valuable feedback as we continue to refine and enhance this feature!
Key highlights
- Intuitive horizontal layout:
The new Debug Sequence View (v2) features a horizontal sequence diagram, mirroring the familiar layout of the classic Apigee Console UI, making it easier to understand the flow of your API proxy transactions at a glance. - Enhanced clarity:
The horizontal visualization, coupled with improved grouping of events, provides a clearer picture of policy execution, highlighting errors and their context within the transaction flow. - Streamlined workflow:
Debug Sequence View (v2) is designed to reduce the need for disruptive pop-ups and sifting through events, offering a smoother and more focused debugging experience. Reimagined icons help quickly understand a transaction at a glance. - Feature parity:
Debug Sequence View (v2) is designed for users already familiar with debugging in Apigee Classic UI to quickly be proficient. - Search:
You can now search for a specific string in the sequence diagram and details pane. - Improved API status display:
The API status display in the transaction list has been improved for increased readability. - Consolidated FlowInfo events:
FlowInfo events are now grouped together in the sequence diagram. - Target URL displayed:
Displayed target URL on "Request Sent" node when relevant
February 19, 2025
Apigee X| Bug ID | Description |
|---|---|
| 391714121 | Security fix for Apigee infrastructure. This addresses the following vulnerability: |
On February 19, 2025, we released an updated version of Apigee (1-14-0-apigee-7).
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
February 11, 2025
Apigee API hubIAM conditions for fine-grained access
API hub now integrates with IAM Conditions, enabling you to define and enforce granular, conditional attribute-based access control for your API hub resources. For more information, see Add IAM conditions.
Auth support for Vertex AI extensions
API hub now supports the following authentication configurations for creating Vertex AI extensions:
API Key: Authenticate using API keys stored in Secret Manager.HTTP Basic: Authenticate using credentials stored in Secret Manager.
For more information, see Create a Vertex AI extension.
Enhanced onboarding experience
After provisioning your API hub instance in your Google Cloud project, you'll now see an updated Overview page. You can also automatically attach your Apigee runtime projects right from this page. For more information, see Provision API hub in the Cloud console.
Resource ID length limits increased
The maximum allowed length for API hub resource IDs has been increased. The new limits are as follows:
- APIs: API unique IDs can now be up to 500 characters long.
- Versions: Version unique IDs can now be up to 700 characters long.
- Specs: Specification unique IDs can now be up to 1000 characters long.
| Bug ID | Description |
|---|---|
| 356780408 | Fixed issue preventing users from saving a proxy revision Resolved issue in the proxy editor where navigating away from a proxy file containing an error would not properly clear the error state, requiring users to reload the page to save the edited proxy. |
On February 11, 2025, we released an updated version of the Apigee UI.
February 06, 2025
Apigee X| Bug ID | Description |
|---|---|
| 381553288 | Fixed class initialization issue in JavaCallout policy. |
| 390559772 | Fixed issue with ResponseCache policy not appearing in debug sessions when added using Apigee APIM Operator for Kubernetes. |
| N/A | Updates to security infrastructure and libraries. |
On February 6, 2025, we released an updated version of Apigee (1-14-0-apigee-6).
February 04, 2025
Apigee Integrated PortalOn February 4, 2025 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
On February 4, 2025 we released a new version of the Apigee integrated portal.
This release includes general improvements to performance and availability.
February 03, 2025
Apigee UIOn February 3, we released an updated version of the Apigee UI.
GA of Apigee analytics dashboards in Google Cloud console
You can now access these dashboards in the Apigee UI in Google Cloud console:
- Analytics > Developer analysis > Developer engagement
- Analytics > Developer analysis > Traffic composition
- Analytics > End user analysis > Devices
- Analytics > End user analysis > Geomap
Public Preview of the Apigee APIM Operator for Kubernetes
The Apigee APIM Operator for Kubernetes (Preview) allows you to perform API management tasks using Kubernetes tools. It is designed to support cloud-native developers by providing a command-line interface that integrates with familiar Kubernetes tools like kubectl. The operator works by using various APIM resources to keep your Google Kubernetes Engine (GKE) cluster synchronized with the Apigee runtime.
For more information, see Apigee APIM Operator for Kubernetes overview.
January 24, 2025
Apigee XOn January 24, 2025, we released an updated version of Apigee (1-14-0-apigee-4).
| Bug ID | Description |
|---|---|
| 372248577 | Fixed issue causing system.pod.name flow variable to return null. |
| N/A | Updates to security infrastructure and libraries. |
January 15, 2025
Apigee API hubValidation for user-defined attributes
API hub now supports JSON schema validation for user-defined attributes. This enhancement ensures data integrity and consistency for JSON data type inputs, improving the quality and reliability of API specifications.
Resource filtering with user-Defined attributes
You can now filter API hub resources based on user-defined attributes using a REST API call. For more information, see Filter resources based on user attributes.
January 13, 2025
Apigee Advanced API SecurityOn January 13, 2025 we released an updated version of Apigee's Shadow API Discovery.
Shadow API Discovery latency improvements
This release improves Shadow API Discovery and removes the latency impact on load balancers previously documented as part of Shadow API Discovery enablement.
For more information on Shadow API Discovery, see the Shadow API Discovery customer documentation.
January 09, 2025
Apigee XOn January 9, 2025, we released an updated version of Apigee (1-14-0-apigee-3).
| Bug ID | Description |
|---|---|
| 365406457 | Implemented fix to optimize CPU usage and close sockets when needed. |
| 382967738, 383113773 | Fixed security vulnerability in PythonScript policy. |
| 382883585 | Fixed security vulnerability in JavaCallout policy. |
| N/A | Updates to security infrastructure and libraries. |
hybrid 1.14.0-hotfix.1
On January 9, 2025 we released an updated version of the Apigee hybrid software, 1.14.0-hotfix.1.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.14.
- For information on new installations, see The big picture.
Instructions:
To install 1.14.0-hotfix.1:
In your
overrides.yamlfile update the value ofmetrics.sdSidecar.image.tagto0.10.0. Add the following stanza:metrics: sdSidecar: image: url: "gcr.io/apigee-release/hybrid/apigee-stackdriver-prometheus-sidecar" tag: "0.10.0"Apply the changes to the
apigee-telemetrychart:Dry run:
helm upgrade telemetry apigee-telemetry/ \ --install \ --namespace APIGEE_NAMESPACE \ --atomic \ -f overrides.yaml \ --dry-run=serverInstall the chart:
helm upgrade telemetry apigee-telemetry/ \ --install \ --namespace APIGEE_NAMESPACE \ --atomic \ -f overrides.yamlVerify the change by checking its state:
kubectl -n APIGEE_NAMESPACE get apigeetelemetry apigee-telemetry
| Bug ID | Description |
|---|---|
| 367681534 | Tagging apigee-stackdriver-prometheus-sidecar to prevent removal from customer repos after 2 years due to infrequent updates. |
January 07, 2025
Apigee Advanced API SecurityOn January 7, 2024 we released a new version of Advanced API Security Abuse Detection.
API key drill down details are now available in the preview release of Advanced API Security Abuse Detection incidents.
This new functionality allows viewing details of detected abuse by the API key used to access the API.
For usage information, see the Abuse Detection customer documentation for incident details.
January 06, 2025
Apigee Advanced API SecurityOn January 6, 2025 we released an updated version of Advanced API Security.
UI support for environment-level client IP address resolution
This release introduces the ability to view the client IP address resolution setting for an environment in the Apigee Console.
For more information and usage instructions, see the Client IP resolution customer documentation.
December 20, 2024
Apigee Advanced API SecurityOn December 20, 2024 we released an updated version of Apigee.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Support for environment-level client IP address resolution
This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the ax_resolved_client_ip Analytics variable and the new client.resolved.ip flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.
This functionality is not available in Apigee hybrid at this time.
For more information and usage instructions, see the Client IP resolution customer documentation, Analytics dimensions, and client flow variable.
On December 20, 2024 we released an updated version of Apigee.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
Support for environment-level client IP address resolution
This release introduces the ability to specify, per environment, how to capture the client IP address on API requests from the X-Forwarded-For header. When configured for the environment, the specified client IP address is used to apply security actions, populate the ax_resolved_client_ip Analytics variable and the new client.resolved.ip flow variable. The new configuration option can be used to specify the request IP address used in Advanced API Security.
This functionality is not available in Apigee hybrid at this time.
For more information and usage instructions, see the Client IP resolution customer documentation, Analytics dimensions, and client flow variable.
December 19, 2024
Apigee XOn December 19, 2024, we released an updated version of Apigee (1-14-0-apigee-3) for trial organizations only.
| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
December 17, 2024
Apigee XOn December 17, 2024, we released a new version of Apigee.
With this release, the maximum number of apps per AppGroup is increased from 500 to 30,000.
For more information, see the Apigee Limits page.
December 16, 2024
Apigee hybridhybrid v1.14.0
On December 16, 2024 we released an updated version of the Apigee hybrid software, v1.14.0.
- For information on upgrading, see Upgrading Apigee hybrid to version v1.14.
- For information on new installations, see The big picture.
Enhanced Per-environment Proxy Limits in Apigee Hybrid
Starting in version v1.14, new Apigee hybrid organizations can be provisioned with the ability to deploy more than 50 proxies per environment enabled. This feature is already available for Apigee X.
Starting with Apigee hybrid version 1.14, the limits for Apigee hybrid organizations have increased:
- The maximum number of deployed API proxies and shared flows per organization is 6000.
- The maximum number of proxy deployment units per Apigee instance is 6000.
- The maximum number of API base paths per Apigee organization is 3000.
When more than 50 proxies are deployed in an environment, Apigee will automatically partition the environment into several distinct replica sets, each containing a subset of proxies deployed in the environment. These replica subsets are equivalent in behavior and infrastructure resource usage to a single environment in the way it loads and runs a set of proxies and other environment resources. This will be transparent to the user, and you can continue to use the environment as you would a single environment.
See:
Forward Proxy allowlist access
Starting in version v1.14, forward proxies pass through access to allowlisted URLs. Therefore you only need to configure allowlists to googleapis.com URLs on the server on which the forward proxy is configured. See:
Guardrails checks to ensure backups before upgrade
Starting in version 1.14 new guardrails checks have been added to ensure a backup is enabled and has been made before proceeding with an upgrade. See:
Enable and disable metrics-based scaling with customAutoscaling.enabled
Starting in version v1.14, you can enable and disable metrics-based auto-scaling with the customAutoscaling.enabled configuration property. See:
Cassandra credential rotation
Starting in version v1.14, you can rotate Cassandra credentials in Kubernetes secrets. In addition, you can now roll back credential rotation before the cleanup job is initiated in both Vault and Kubernetes secrets. See:
New analytics and debug data pipeline for hybrid orgs
Starting with version 1.14, Apigee hybrid orgs can use a new data pipeline to collect analytics and debug data and allow various runtime components to write data directly to our control plane. Control plane access is required to enable the new data pipeline.
See:
| Bug ID | Description |
|---|---|
| 382323427 | Added a guardrails check that requires backup to be enabled for Apigee Hybrid upgrades. Backups are required prior to upgrading to support restoring to the previous version, if necessary. |
| 380346557 | Added a guardrails check that requires the backup within the last 24 hours to be present if the CSI backup is enabled. This will minimize potential data loss if a restore to the previous version is needed. |
| 377573589 | Fix a bug where manually created rollbacks would interfere with existing rotations instead of cancelling them. |
| 362305438 | Users can now add additional env variables to the runtime component. See runtime.envVars |
| 319152386 | Fix AccessTokenGenerationFailure in runtime when using a forward proxy. |
| 335357961 | Fixed an issue where Apigee hybrid could claim uploads of backups with the Cloud provider when no bucket had been configured |
| 290183372 | The need to allowlist oauth2 and iamcredentials.googleapis.com directly from MP in fwd proxy setup is removed. |
| 237656263 | Resolved issue with ServiceCallout policy not working in async mode as expected. |
| 373722434 | Fixed support for backups to Google Cloud Storage buckets with retention policies. (Fixed in v1.13.2) |
| 368646378 | Fixed an issue affecting control Plane connectivity testing in Guardrails. (Fixed in v1.12.3) |
| 364282883 | Remove check for dc-expansion flag and add timeout to multi-region seed host connection test. (Fixed in v1.13.1) |
| 362979563 | Fix for Ingress Health Check failure /healthz/ingress - route_not_found. (Fixed in 1.13.0-hotfix.1) |
| 362690729 | Fix for aggressive scaling of runtime pods & cpu spike. (Fixed in 1.13.0-hotfix.1) |
| 362305438 | You can now add additional env variables to the runtime component. (Fixed in v1.13.1) |
| 361044374 | Fixes assign message not correctly highlighting the set payload action in the debug trace. (Fixed in v1.13.2) |
| 355122464 | This release contains a few error-handling fixes for CSI backup and restore. (Fixed in v1.13.2) |
| 353527851 | WebSocket connection drops when using VerifyJwt or OAuthV2 VerifyJWTAccessToken operations. (Fixed in v1.13.1) |
| 351440306 | An issue was fixed where trace could not be viewed in the UI for orgs with DRZ enabled. (Fixed in v1.13.1) |
| 347798999 | You can now configure forward proxy for opentelemetry pods in Apigee hybrid. (Fixed in v1.12.2) |
| 338638343 | An ID is now added at the end of apigee-env and virtualhost guardrails pods to make the pod names unique. (Fixed in v1.13.1) |
| 237656263 | Fix added to make use of asynchronous ServiceCallout execution when the ServiceCallout policy <Response> element is not present (Fixed in v1.13.2) |
| 181569113 | Fixed an issue in new debug session creation. (Fixed in v1.12.3) |
| Bug ID | Description |
|---|---|
| N/A | Security fixes for apigee-redis. This addresses the following vulnerabilities: |
| N/A | Security fixes for livenessprobe. This addresses the following vulnerability: |
| 376104926 | Security fixes for apigee-kube-rbac-proxy. (Fixed in v1.12.3) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-redis. (Fixed in v1.13.2) This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. (Fixed in v1.13.1) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-open-telemetry-collector. (Fixed in v1.12.3) This addresses the following vulnerability: |
| N/A | Security fixes for apigee-cassandra-backup-utility and apigee-hybrid-cassandra. (Fixed in v1.12.2) This addresses the following vulnerability: |
December 10, 2024
Apigee Integrated PortalOn December 10, 2024, we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 381086551 | Fixed an issue that caused the page list view to fail for some portals with large numbers of pages. |
On December 10, 2024, we released a new version of the Apigee integrated portal.
| Bug ID | Description |
|---|---|
| 381086551 | Fixed an issue that caused the page list view to fail for some portals with large numbers of pages. |
| Bug ID | Description |
|---|---|
| 357880539 | Resolved issue with missing span in the Apigee UI for distributed trace. |
| 237656263 | Resolved issue with ServiceCallout policy not working in async mode as expected. |
| N/A | Updates to security infrastructure and libraries. |
On December 10, 2024, we released an updated version of Apigee (1-14-0-apigee-2).
November 22, 2024
Apigee UIOn November 22, 2024, we released an updated version of the Apigee UI.
This release includes an improved Apps page for Apigee API Management in the Google Cloud console, making it easier to manage API products that are assigned to app credentials.
With this release:
- Products can be added to an app from a single multi-select list box.
- Products can be approved, revoked, and removed from a credential by selecting products in the credential product table and using one of the available action buttons.
- Clicking the Add Credential button adds an empty credential to the list.
- Credential approval and expiry configuration fields are located in the credential card.
- A warning appears to users if they attempt to leave the Apps page when un-saved changes are present.
| Bug ID | Description |
|---|---|
| 357165778 | Refactored app credential management experience Resolved issue causing the Apps page in the Apigee UI in Cloud console to crash when working with apps that have a large amount of products assigned to app credentials. |
November 15, 2024
Apigee UIOn November 15, 2024, we released an updated version of the Apigee UI.
| Bug ID | Description |
|---|---|
| 376257906 | Fixed issue with custom report editing Resolved issue where customer reports without properties that were created using the API could not be rendered with the Edit option. |
November 14, 2024
Apigee Advanced API SecurityOn November 14, 2024 we released a new version of Advanced API Security
IP address drill down details are now available in the preview release of Advanced API Security Abuse Detection Incidents.
This new functionality allows viewing details of detected abuse by source IP.
For usage information, see the Abuse Detection customer documentation.
November 12, 2024
Apigee hybridhybrid v1.13.2
On November 12, 2024 we released an updated version of the Apigee hybrid software, 1.13.2.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.13.2.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| N/A | Security fixes for apigee-redis. This addresses the following vulnerabilities: |
| Bug ID | Description |
|---|---|
| 373722434 | Fixed support for backups to GCS buckets with retention policies. |
| 361044374 | Fixes assign message not correctly highlighting the set payload action in the debug trace. |
| 355122464 | This release contains a few error-handling fixes for CSI backup and restore. |
| 237656263 | Fix added to make use of asynchronous ServiceCallout execution when the ServiceCallout policy <Response> element is not present.
Procedure:
|
November 01, 2024
Apigee hybridhybrid v1.12.3
On November 1, 2024 we released an updated version of the Apigee hybrid software, 1.12.3.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.12.3.
- For information on new installations, see The big picture.
| Bug ID | Description |
|---|---|
| 368646378 | Fixed an issue affecting control Plane connectivity testing in Guardrails. |
| 361044374 | Fixes assign message not correctly highlighting the set payload action in the debug trace. |
| 335357961 | Fixed an issue where Apigee hybrid could claim uploads of backups with the Cloud provider when no bucket had been configured |
| 181569113 | Fixed an issue in new debug session creation. |
| Bug ID | Description |
|---|---|
| 376104926 | Security fixes for apigee-kube-rbac-proxy. This addresses the following vulnerabilities: |
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerability: |
October 23, 2024
Apigee X| Bug ID | Description |
|---|---|
| N/A | Updates to security infrastructure and libraries. |
On October 23, 2024, we released an updated version of Apigee (1-14-0-apigee-1).
October 22, 2024
Apigee XOn October 22, 2024, we released a new version of Apigee.
With this release, the following limits for Apigee organizations have changed:
- The maximum number of deployed API proxies and shared flows per (non-hybrid) organizations is 6000.
- The maximum number of proxy deployment units per Apigee instance is 6000.
- The maximum number of API base paths per Apigee organization is 6000.
For more information, see the Apigee Limits page.
October 18, 2024
Apigee API hubOn October 18, 2024, Apigee announced the an update to Apigee API hub.
In addition to us-central1 and europe-west1, Apigee API hub now supports the following new hosting regions:
| Region Description | Region name |
|---|---|
| Northern Virginia | us-east4 |
| Oregon | us-west1 |
| London | europe-west2 |
| Singapore | asia-southeast1 |
| Mumbai | asia-south |
| Sao Paulo | southamerica-east1 |
| Sydney | australia-southeast1 |
See Provision API hub.
October 11, 2024
Apigee UI| Bug ID | Description |
|---|---|
| 357165778 | VerifyIAM policy selection removed for hybrid organizations. The VerifyIAM policy is not supported for hybrid-enabled Apigee organizations. It has been removed as an option in the Proxy Editor. |
| 372224845 | Offline debug page not loading Fixed issue where the offline debug page would not load if a debug session was loaded elsewhere in the UI previously. |
On October 11, 2024, we released an updated version of the Apigee UI.
October 10, 2024
Apigee XOn October 10, 2024, we released an updated version of Apigee.
Apigee no longer limits the number of Cloud projects that can connect to an Apigee instance. Previously, the limit was 50 projects. For each project, you can now create up to 100 Private Service Connect Network Endpoint Groups. The previous limit was 20. For any Apigee instances created before October 10, 2024, you must perform an update to the consumer accept list for an Apigee instance if you want to take advantage of these new limits. See Updating the consumer accept list for an Apigee instance. See also Limits.
October 08, 2024
Apigee Advanced API SecurityOn October 8, 2024 we released an updated version of Advanced API Security.
Note: Rollouts of this release to production instances will begin within two business days and may take four or more business days to complete across all Google Cloud zones. Your instances may not have the feature available until the rollout is complete.
New features added to the Risk Assessment v2 preview
This release introduces new features to the Risk Assessment v2 preview:
- Support for custom security profiles. You can create your own security profiles, with unique combinations of risk assessment checks and weights, to use for proxy risk assessment.
- New assessment checks. We've added additional checks you can use when assessing proxy risk.
- Assess proxies across multiple profiles. You can now switch between security profiles to see differences in scoring across profiles.
For usage information and a list of all features in Risk Assessment v2, see the Risk Assessment v2 customer documentation.
| Bug ID | Description |
|---|---|
| 361714906 | Fixed synchronization issue with Cloud KMS keys Implemented recovery mechanism for the Apigee dataplane in the event of an extended disruption in the CloudKMS key service. |
| 361044374 | Resolved issue with incorrect payloads shown in debug trace When using debug trace with the AssignMessage policy, the UI now displays the correct request and response payloads. |
| N/A | Updates to security infrastructure and libraries. |
On October 8, 2024, we released an updated version of Apigee (1-13-0-apigee-6).
This release addresses the security concerns in GCP-2024-052 from Google Anthos Service Mesh.
October 04, 2024
Apigee Advanced API SecurityOn October 4, 2024 we released an updated version of Advanced API Security.
Fixed: Delay in score generation for Risk Assessment v2 with VPC-SC-enabled organizations only
In Risk Assessment v2, which is in preview, this issue has been resolved:
With VPC-SC-enabled organizations only, when generating scores for new organizations or scoring changes to included proxies, shared flows, and target server configurations, score generation could have take as much as three hours.
See the Risk Assessment v2 customer documentation for information on the functionality.
Risk Assessment v2 is now available in the me-central2 region. See Available Apigee API Analytics Regions for region information.
hybrid v1.13.1
On October 4, 2024 we released an updated version of the Apigee hybrid software, 1.13.1.
- For information on upgrading, see Upgrading Apigee hybrid to version 1.13.1.
- For information on new installations, see The big picture.
New analytics and debug data pipeline for data residency-enabled orgs
Starting in v1.13.1 hybrid organizations created with data residency enabled must use the new data pipeline to collect analytics and debug data and allow various runtime components to write data directly to our control plane. Changes to overrides file and control plane access are required to enable the new data pipeline.
For details, see:
Cassandra credential rotation in Vault
Starting in version v1.3.1, You can set up automatic Cassandra credential rotation when your credentials are stored in Hashicorp Vault. See Rotating Cassandra credentials in Hashicorp Vault.
| Bug ID | Description |
|---|---|
| 364282883 | Remove check for dc-expansion flag and add timeout to multi-region seed host connection test. |
| 362305438 | You can now add additional env variables to the runtime component. |
| 353527851 | WebSocket connection drops when using VerifyJwt or OAuthV2 VerifyJWTAccessToken operations. |
| 351440306 | An issue was fixed where trace could not be viewed in the UI for orgs with DRZ enabled. |
| 338638343 | An ID is now added at the end of apigee-env and virtualhost guardrails pods to make the pod names unique. |
| Bug ID | Description |
|---|---|
| N/A | Security fixes for apigee-open-telemetry-collector. This addresses the following vulnerability: |
October 03, 2024
Apigee UI| Bug ID | Description |
|---|---|
| 369647749 | Proxy deployment units counts include shared flows Fixed issue where proxy deployment unit counts in the UI did not take into account shared flow deployments. |
| 369385955 | Fixed the display of the Apigee apps list Resolved an issue causing Apigee apps to display incorrectly in the Apps list when the search bar is used for filtering. |
| 361497390 | Updated the description and calculation of Apigee deployment quotas The deployment quota displayed on the Apigee overview page now correctly describes and calculates the value of all proxy deployment units, including both API proxy and shared flow deployments across all environments./p> |
On October 3, 2024, we released an updated version of the Apigee UI.
October 02, 2024
Apigee XOn October 2, 2024, we released an updated version of Apigee.
Subscription Apigee organizations (without hybrid entitlements) upgraded in this release will see changes to the user experience in the Classic Apigee UI. To support management of the upgraded functionality now available to these organizations, a number of feature administration pages are now only available in the Apigee UI in Cloud console.
For more information, see Apigee UI in Cloud console navigation.
With this release, all remaining Apigee API Management organizations with Subscription 2021 contracts have been upgraded to introduce standard and extensible API proxy features.
To learn more about:
- Standard and Extensible API Proxy types, see API Proxy types.
- Viewing proxy deployment count, see View proxy deployment usage.
September 26, 2024
Apigee API hubOn September 26, 2024, Apigee announced the GA launch of Apigee API hub.
We added a new Supply chain page where you can create, view and manage your dependencies across API operations. The same dependencies can also be created from the API operations page. See Manage dependencies.
A new "Get started with API hub" page was added to the user interface. This new page includes valuable getting started information, including a new FAQ, to help you get the most out of API hub.
The Semantic Search (formerly Smart Search) user interface has been improved, and search results are shown across all API hub entities, such as APIs, deployments, specifications, and versions. See Search and filter APIs.
We added support for GMEK and CMEK in the provisioning steps. While provisioning, you can also choose to host your Vertex search data in a different location or disable Vertex search altogether. See Provision API hub.
While you can use API hub by making direct REST over HTTP requests, we now provide client libraries for several popular languages. See API hub client libraries.
We added support for Cloud audit logging.
The List APIs for specifications, dependencies, and external APIs have been enhanced to return a complete response, including user-defined attributes.
Significant user interface improvements were made, such as standardization of cards on the API details page, unlinking of deployments, various performance fixes, and more.
On September 26, 2024 we released an updated version of Apigee.
If you have CMEK org policy constraints on your Google Cloud project, Apigee will enforce compliance with those constraints and guide you in choosing valid configuration, and prevent you from using Apigee features that are not CMEK-compliant.
The following documents are new and explain how to use CMEK with Apigee:
The following documents have been updated with the relevant CMEK information:
A