How to run Apigee Hybrid PoC with terraform

How to run Apigee Hybrid PoC with terraform

Overview

As customers get interested in Apigee hybrid most of them would typically start their journey with an evaluation or proof of concept in a sandbox or test environment to get familiar with the entire setup process to see how it works/fits in their organisation architecture, how much effort is involved, how it will co-exist in their ecosystem. This article describes how customers can automate setting up Apigee hybrid in a POC - proof of concept environment to evaluate Apigee hybrid.

What is Apigee hybrid

Apigee hybrid is a platform for developing and managing API proxies that features a hybrid deployment model. The hybrid model includes a management plane hosted by Apigee in the Cloud and a runtime plane that you install and manage on one of the supported Kubernetes platforms.

Apigee Hybrid decouples the runtime plane from the management plane, allowing you to deploy Apigee runtime services (message processors, data stores) within your own data centers or private clouds, while the management plane remains Google-managed. This addresses data residency, compliance, and latency concerns.

Customer Question

Some of the questions we typically get from customers include

  • Can I deploy Apigee hybrid on a container ?
  • Can I deploy Apigee hybrid on a single node ?
  • Why are there several steps to do the PoC?

For a product as robust as Apigee this is not unusual due to the many touchpoints and components of Apigee. Without a clear understanding of the requirements, the process of installing Apigee Hybrid, which involves setting up a Kubernetes cluster, installing the Apigee components, and configuring networking, can be daunting. These complexities often delay or even derail a customer’s ability to evaluate the full potential of the platform. The repository here was created to address this very issue, providing a streamlined, automated approach to deploying Apigee Hybrid on multiple cloud platforms using Terraform. This automation significantly reduces the manual effort and potential for human error, enabling a much smoother and faster setup for PoCs and production environments.

The first step in using this solution is to meet the prerequisites. This involves having an Apigee organization provisioned, which is the cloud-based control plane for Apigee Hybrid. You also need a Google Cloud Platform (GCP) project for the Apigee organization. Additionally, you must have the necessary software installed on your local machine, including Terraform, the gcloud CLI, the kubectl CLI, and the Apigee command-line tools. The solution is designed to work across three major cloud providers shown below:

  • Amazon Web Services (AWS) EKS
  • Google Kubernetes Engine (GKE)
  • Azure Kubernetes Service (Microsoft) AKS.

Each platform has its own set of provider configurations, which are handled by the Terraform modules.

The repository provides a structured approach to the installation. The Terraform code is organized into modules that handle different stages of the deployment. It starts with the cluster setup, where Terraform provisions a Kubernetes cluster on your chosen cloud provider (EKS, GKE, or Azure). This includes configuring the virtual private cloud (VPC), subnets, and node pools to ensure the cluster is ready to host the Apigee components. The code also handles the necessary networking configurations, such as firewall rules and load balancers, to ensure proper communication within the cluster and with external services. This modular design allows for a clear separation of concerns, making the code easier to manage and modify.

AWS EKS Setup

Pre-requisites for setting up in AWS include

  • Setup an AWS Account (similar to GCP Account) if you don’t have one as described here
  • Create an IAM user and a cli user described here (Similar to IAM user in GCP as well, Use cli user credentials when configuring our aws cli)
  • Clone the apigee hybrid terraform repo
  • Download and install terraform to your local terminal described here
  • Download and install the aws cli to your local terminal from where terraform would be run described here
  • Download and install helm ( version 3.16.2+) for installing hybrid helm charts
  • Run terraform init to initialise terraform

The diagram below shows the high level steps involved for setting up APigee hybrid on AWS EKS when selecting the AWS cloud option

Azure AKS Setup

Pre-requisites for setting up in AKS include

  • Setup an Azure Account/Subscription if you don’t have one. You can start with a free account here.
  • Create an Azure Service Principal or use your User Account:
  • For automation and CI/CD, it’s recommended to create a Service Principal with the necessary permissions (e.g., “Contributor” on the subscription or a specific resource group). .
  • Alternatively, you can authenticate as a user via Azure CLI. (az login)
  • Download and install Terraform to your local terminal as described here.
  • Download and install the Azure CLI (az) to your local terminal from where Terraform would be run, as described here.
  • Download and install Helm (version 3.15+ recommended, check Apigee docs for specific version compatibility).
  • Run terraform init to initialize Terraform and download necessary providers.
  • kubectl v1.29+

The diagram below shows the high level steps involved for setting up Apigee hybrid on microsoft AKS when selecting the AKS Azure option

Once the cluster is set up, the next stage is to install the Apigee Hybrid components. This is where the Terraform code really simplifies the process. It automates the installation of the Apigee Hybrid operator, which is a Kubernetes controller that manages the Apigee components. It also deploys the various Apigee services, such as Mart, Watcher, and Synchronizer, and configures them to connect to your Apigee control plane in Google cloud.

The Terraform modules handle the creation of the necessary Kubernetes secrets and custom resources (CRs) that define the Apigee configuration, which is a major pain point when doing this manually. The code also automates the setup of TLS certificates and service accounts, ensuring a secure and functional deployment.

A few points worth noting

  1. Apigee hybrid multi-region and upgrade of Apigee hybrid are not supported with this tool.
  2. While the tool is primarily for installing both the kubernetes cluster and the hybrid components, the tool can also be used to deploy Apigee hybrid where a cluster is already available in which case the Apigee hybrid components will be installed on the designated kubernetes cluster.

Conclusion

In conclusion, the Terraform repository provides a robust and repeatable solution for deploying Apigee Hybrid on AWS, GCP, and Azure. By automating the entire process from cluster creation to the installation of all Apigee components, it drastically reduces the complexity and time required for setup. This allows customers to move beyond the technical hurdles and focus on what truly matters: evaluating Apigee’s API management capabilities for their business needs. The modular and well-documented nature of the code makes it a valuable resource for both PoCs and production deployments, ensuring a consistent and reliable installation every time.

Authors

Rajesh Mishra – Customer Engineer Apigee
Ayo Salawu - Technical Solutions Consultant , Apigee

Let’s talk — Google Cloud Sales Specialist awaits.

3 Likes