Apigee Edge: Apigee Cloud v. Private Cloud Evaluating deployment model for API management
Table of Content Introduction 1 Time to ucce 2 Total cot of ownerhip 2 Performance 3 Security 4 Data privacy 4 Scalability and reliability 5 Summary 6
Introduction API are the underpinning of digital buine platform. To adopt an API-centric approach, it critical for an enterprie to chooe an API management platform that enable it to ecure, cale, and manage API, and make them attractive to internal and external developer. Apigee Edge, the intelligent API management platform, i the choice of hundred of companie that are building or expanding their digital buinee. Thee companie can chooe to deploy Apigee Edge in their private data center or in the Apigee cloud. Which model hould you chooe? It depend on your buine need do you need to manage your API or control your cutomer data in-houe? In thi brief, we examine the pro and con of the two deployment model, and key factor to conider a you determine the deployment option for your enterprie. When evaluating deployment alternative, our cutomer conider the following dimenion: Time to ucce Total cot of ownerhip Security Performance Scalability and reliability 1 1
Time to ucce Cutomer that deploy API management in the Apigee cloud typically go live with their digital initiative much fater than thoe that deploy in the private cloud. The procee of acquiring, proviioning, and deploying hardware, a well a oftware deployment configuration, and the training required to deploy and manage API management oftware can all delay deployment to private cloud. Cutomer that need to deliver high performance API to global audience can take advantage of Apigee global network of 24 data center. Further, a buine requirement change, a deployment in the Apigee cloud can be reconfigured to expand and adjut to a cutomer need. Leading e-commerce and payment olution provider Firt Data wanted to rapidly deliver a payment olution to enable merchant and bank to upport Apple Pay in time for Apple big launch. To enure the delivery in le than five month, Firt Data choe to deploy API management in the Apigee cloud. Total cot of ownerhip Apigee Edge API management in the Apigee cloud ha a lower total cot of ownerhip (TCO) for our cutomer compared to a private cloud implementation. Private cloud cot include API management oftware cot, hardware infratructure cot, hardware and oftware deployment and upport cot, and operation and training cot. The licene cot of a private cloud deployment i le than a three-year annual ubcription to the Apigee cloud. However, it i important to conider the additional cot an enterprie incur with a private cloud implementation. With the Apigee cloud (a with other SaaS offering) infratructure, operation, and upport cot are ditributed acro Apigee entire cutomer upport bae. Data from our cutomer ugget that for a ingle-region, medium-ized API management implementation, a private cloud deployment can cot three time a much a the Apigee cloud deployment. A key factor for the higher TCO aociated with private cloud deployment are the cot related to the people required to deploy, manage, monitor, and upport the API management infratructure 24x7. A comparion of the TCO of private cloud API management and an Apigee cloud implementation 2 2
A private cloud deployment can be the right choice for cutomer who want to recognize their invetment (via a one-time perpetual licene purchae) a a capital expenditure intead of a an operational cot (a ubcription licene). For cutomer with ignificant private cloud invetment and pare bandwidth in their cloud operation team, the incremental operational cot are minimal, and the economic of a private cloud implementation are imilar to that of the Apigee cloud. Performance The choice of API management deployment model can impact API performance in a couple of cenario: for internal ue cae, and when reaching geographically ditributed audience. In internal ue cae, where both the target backend and the API conumer are in a private cloud, API management in the Apigee cloud can introduce additional round-trip latency to API call. However, Apigee Edge Microgateway a hybrid cloud olution olve thi problem. Edge Microgateway enable cutomer to maintain their API run-time infratructure in their private cloud, while keeping the ret of API management in the Apigee cloud. Becaue Apigee run the API management platform in 24 globally dipered data center, the Apigee cloud can deliver uperior performance to global audience. Many of our global cutomer deploy in the Apigee cloud acro multiple regional data center (Virginia, Oregon, Ireland, Singapore, Tokyo, and Sydney, for example). Cutomer not only benefit from the reduced latency of API requet, but alo enjoy improved overall reliability and diater recovery in the event of a catatrophic data center failure. 3 3
Security Apigee adopt indutry tandard, deploy numerou ecurity offering and procee, and employ third partie to enhance the ecurity of the Apigee cloud. Indutry tandard Security framework Information ecurity SLA and redundancy Application teting SDLC Rik Analyi Incident management Background check The Apigee Platform i third-party audited, compliant, and certified for PCI DSS, HIPAA, SOC1, and SOC2. Thee and other certification are available to cutomer and each of thee tandard i audited annually. Apigee ue multiple framework to define and manage ecurity control, including Cloud Security Alliance (CSA) and ISO. Apigee ha a formal information ecurity policy and team. The team addree the following domain: Cloud ecurity Application ecurity Corporate ecurity (IT, HR, network, privacy, and phyical ecurity) Incident management Buine continuity and diater recovery Service level agreement are met through the ue of redundant ervice in each region and redundant region. Apigee cloud i a multi-tenant, elf-ervice, SaaS platform that i penetration teted annually by multiple third partie. Thi annual report i available to cutomer. Apigee Edge oftware i alo teted annually by a third party with expertie in application teting. Apigee alo conduct it own internal application teting. Apigee follow a ecure, formally documented oftware development lifecycle. Thi lifecycle include tatic code analyi and dynamic code analyi tool, a well a peer code review and code releae teting and approval procee. An independent third party conduct an annual formal rik analyi for Apigee Corp, including all oftware and ervice. Thi analyi identifie area of rik to be addreed and an annual update allow for changing threat, rik, and environment. Apigee ha a formal incident repone proce that i carefully documented, teted at leat once a year. It i updated and reviewed by third partie annually. Apigee conduct background check on all employee prior to their employment. Financial check are alo performed on key finance employee. Repeat check for key poition are performed after five year of employment. Apigee work with our cutomer information ecurity team to further enure that Apigee cloud meet the pecific ecurity requirement of the buine. Data privacy The cutomer manage all data proceed through or tored in Apigee cloud. Apigee doe not need acce to any end-uer data for operation of the platform. The cutomer ha the ability to decide what data to end through Apigee and what data, if 4 4
any, to tore in the Apigee cloud (either in the API BaaS or in a cache). When a cutomer end enitive data through the Apigee cloud, Apigee operation doe not ee the payload in normal operation. A cutomer can give Apigee upport acce to run a trace/debug eion and, in that cae, Apigee upport may get acce to cutomer data. If the Apigee cutomer doe not want Apigee to have acce to end-uer data, thi authorization can be withheld from all uer of the Apigee platform, or from pecific uer. Apigee doe manage the platform and hold the mater key. But our acce to cutomer environment i done the ame way cutomer ue the management UI. If an Apigee employee were to be given advanced acce the kind required to run a trace/debug the enablement of thi account, along with their action, would be tracked in both the cutomer pace and in the Apigee infratructure log. Apigee prohibit thi acce by policy unle a cutomer requet it during a troublehooting eion. The cutomer can ue analytic to identify any uer with thi type of acce and remove thoe uer at any time. A private cloud deployment i a good choice in cae where indutry or company regulation require that all your data, including API definition and key, need to reide on-premie. Scalability and reliability The Apigee cloud i managed by a talented operation team with hundred of year of aggregate experience managing API management oftware in the cloud. Beyond the people expertie benefit, there are additional benefit of Apigee cloud compared to private cloud deployment. Scale The Apigee cloud procee over 300 billion API call per year for cutomer acro a variety of indutrie that have rigorou compliance requirement (including financial ervice, healthcare, and telecommunication). During Black Friday lat year, peak API traffic in the Apigee cloud exceeded 50,000 requet per econd. The Apigee cloud provide the additional benefit of dynamically caling baed on changing buine need. Reliability Eae of operation We delivered 99.999% availability to our cutomer in the Apigee cloud in 2015 and we continue to improve availability. The Apigee cloud ditributed global network of 24 data center and trong traffic management capabilitie enure that the ytem i wellprotected from ytem outage and traffic burt. Apigee ha built a variety of tool to treamline the operation of the Apigee cloud, making upgrading oftware, debugging failure, and enuring high uptime moother. Apigee doe, however, provide all the neceary training to enable cutomer to manage Apigee in their private cloud, a it take additional operation reource and knowledge to become completely operational. A private cloud implementation i a good choice if you require complete control over the deployment of API management, including verion upgrade and caling. 5 5
Summary API management i a key enabler of your digital buine trategy. Making the right deployment deciion will help you accelerate your digital initiative. In mot cae, deploying in the Apigee cloud i the better option compared to private cloud. However, for pure internal ue cae and for company-pecific ecurity policy reaon, a private cloud deployment can be the right choice. Even for pure internal ue cae, we recommend the Apigee cloud option with the hybrid Edge Microgateway to minimize run-time latencie. We encourage your ecurity team to conduct an audit of our ecurity policie to determine if the Apigee cloud meet your company pecific requirement. Whether in the Apigee cloud or a private cloud, the Apigee Edge API management platform i built from the ame Apigee codebae, o you alway have the unique flexibility to tart with the Apigee cloud option and then, if needed, move to a private cloud deployment. About Apigee Apigee (NASDAQ: APIC) provide an intelligent API platform for digital buine. Many of the world' larget organization elect Apigee to enable their digital buine, including 30 percent of the Fortune 100, five of the top ix Global 2000 retail companie, and five of the top 10 global telecommunication companie. Apigee cutomer include global enterprie uch a Walgreen, Burberry, Morningtar, and Firt Data. Apigee i headquartered in San Joe, California and ha over 400 employee worldwide. To learn more, ee apigee.com. 6 6