Apigee 是一个多租户、自助式、基于云的平台,在全球多个区域的多个数据中心以完全冗余(实时/实时)配置运行。Apigee 使用 Google Cloud 作为其基于云的平台。作为我们在 Google Cloud 上构建的服务的一部分,我们在每个区域内使用多个数据中心,并为跨这些多个数据中心的客户提供实时流量服务。我们没有“实时”数据中心和“备用”(或“辅助”或“故障切换”)数据中心。我们拥有两个(或更多)数据中心,持续同时为全球每个地区的客户流量提供服务。
BCP/DR 方案
Apigee 业务连续性规划和灾难恢复 (BCP/DR) 是一个平台范围的计划,不包含针对单个客户的详细任务。相反,该平台被配置为无论中断和中断如何处理客户数据请求。即使整个数据中心离线,数据也会继续流动。如果整个区域都离线,则单个区域的客户可能会遇到 API 处理服务中断。对于需要更多“区域内”冗余服务的客户,Apigee 可在全球冗余级别的冗余数据中心使用,其中可以为多个区域或国家/地区的流量提供服务,这样如果整个区域都离线,数据仍会流动。
由于数据处理和访问可能存在地理限制,单一区域的客户服务不会自动转移到另一个区域。Apigee 服务由客户所在区域中的客户托管。由于可能有关于数据地理位置的特定法规或客户对其用户的承诺,因此服务不会自动转移到备用区域,否则可能会损害 Google 对其客户的承诺或 Google 客户对其客户的承诺。
Google 不会与任何个人客户共享完整的 BCP/DR 方案,因为它包含内部敏感信息和对我们客户的引用。我们的隐私政策防止与可能暴露其他客户名称的个人客户共享平台 BCP/DR 方案。我们为每位客户提供相同级别的隐私。
BCP/DR 管理
Google 信息安全团队负责监督业务弹性计划,而轮值的事件指挥官负责管理和解决所有事件。事件指挥官有随时待命的操作和工程人员以及可能需要采取的所有行动的策略方案。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[[["\u003cp\u003eApigee operates as a multitenant, cloud-based platform with live/live redundancy across multiple data centers and regions, ensuring continuous service availability.\u003c/p\u003e\n"],["\u003cp\u003eApigee's Business Continuity Planning and Disaster Recovery (BCP/DR) is a platform-wide plan designed to handle disruptions and outages without individual customer intervention.\u003c/p\u003e\n"],["\u003cp\u003eGoogle conducts frequent operational processes that include taking down an entire data center for updates, while the load is serviced by other live centers to ensure the services have no issues, and also conducts annual BCP/DR testing involving simulated disaster scenarios.\u003c/p\u003e\n"],["\u003cp\u003eCustomers are encouraged to incorporate Apigee into their own disaster recovery plans, considering traffic redirection during outages, although this testing is beyond Apigee's core BCP/DR scope.\u003c/p\u003e\n"],["\u003cp\u003eApigee does not offer specific recovery point and recovery time objectives (RPO/RTO), but provides real-time service due to its redundant architecture, and the service offers single and multi region capabilities for customers.\u003c/p\u003e\n"]]],[],null,["# Business continuity planning and disaster recovery\n\n*This page\napplies to **Apigee** and **Apigee hybrid**.*\n\n\n*View [Apigee Edge](https://docs.apigee.com/api-platform/get-started/what-apigee-edge) documentation.*\n\n\nApigee is a multitenant, self-service, cloud-based platform that runs in a fully redundant\n(live/live) configuration across multiple datacenters in multiple regions of the globe.\nApigee uses Google Cloud for its cloud-based platform. As part of the services we build on\nGoogle Cloud, we use multiple data centers within each region and service live traffic for\nour customers across these multiple data centers. We do not have a \"live\" data center and a\n\"standby\" (or \"secondary\" or \"failover\") data center. We have two (or more) data centers\nconstantly and simultaneously servicing customer traffic in each region globally.\n\n**BCP/DR plan**\n---------------\n\n\nApigee Business Continuity Planning and Disaster Recovery (BCP/DR) is a platform-wide plan\nand does not contain detailed tasks for individual customers. Rather, the platform is\nconfigured to process customer data requests regardless of disruptions and outages. The\ndata will continue to flow even if an entire data center is offline. If an entire region\nwere to go offline, a single-region customer could experience an outage of API processing\nservices. For customers looking for more than \"in-region\" redundant services, Apigee is\navailable at a globally redundant level of redundant data centers where traffic can be\nserviced in multiple regions or countries so that if an entire region were to go offline,\nthe data would still flow.\n\n\nSingle-region customer services are not automatically transferred to another region because of\npossible geographic restrictions on data processing and access. Apigee services are hosted\nfor customers in the region identified by the customer. Because there may be specific\nregulations or customer commitments to their users on geographic locations of data, services\nwill not automatically move to an alternate region, as this could potentially compromise\nGoogle's commitments to its customers or Google customers' commitments to their customers.\n\n\nGoogle does not share the full BCP/DR plan with any individual customer, as it contains internal\nsensitive information and references to our customers. Our privacy policy prevents sharing the\nplatform BCP/DR plan with individual customers that could potentially expose other customer\nnames. We offer this same level of privacy to each customer.\n\n**BCP/DR Management**\n---------------------\n\n\nA Google Information Security team is responsible for the oversight of the Business\nResiliency program while a rotating Incident Commander is responsible for management\nand resolution of all incidents. The Incident Commander has operational and engineering\npersonnel on call at all times along with playbooks for all actions that may need to be taken.\n\n**BCP/DR Testing**\n------------------\n\n\nGoogle performs operational processes that support BCP/DR testing of the platform on a more\nfrequent cadence than our full annual BCP/DR testing. Each month we perform load swings\nfrom our live/live environment while we perform updates to the systems running the service.\nThis process involves taking down one entire data center's worth of systems while the load\nis handled by the peer datacenter. During this process, after any updates are performed,\nthe first data center is brought back up and services are run live/live again to verify\nthat no issues were introduced. Then the peer datacenter is brought down for the same\nupdates and then brought back online again. Google uses tools and techniques to drain traffic\nand send a small percentage of traffic to recently updated services to check for any issues\nor errors before going back to full load processing.\n\n\nThis consistent operational process exceeds industry-standard bi-annual resiliency \"testing\" of\nour service by making it an operational task that occurs more frequently.\n\n\nIn addition to the operational processes described above, Google also conducts BCP/DR exercises\nat least once annually where engineering and operations team members test a real disaster\nscenario. This provides additional training and experience for our personnel on our larger\nBCP/DR plans for the enterprise as a whole in addition to the service itself.\n\n\nThe BCP/DR testing done by Google does not use \"failover exercises\" or \"secondary locations\"\nbecause all of that is built into the running system.\n\n\nGoogle does maintain Playbooks for use by all operational and engineering teams. These\nplaybooks are reviewed and updated at least annually and used in all of our BCP/DR testing\nand training exercises.\n\n\nAnnual BCP/DR test reports are available for customers. We also share the results of our\noperational tasks and annual DR exercise test reports with our third-party auditors,\nand these form the basis for the auditor's review of our compliance with PCI, HIPAA,\nISO, contractual, and other requirements.\n\n### **Customer BCP/DR tests**\n\n\nCustomers are encouraged to have their own DR plans incorporate Apigee services. Customers\ncan and should consider how Apigee can redirect traffic as needed for customers to maintain\nend-user services even during a customer data center outage or other disaster event.\nHowever, this level of testing is outside the scope of the Apigee DR plan. We encourage\ncustomers to perform BCP/DR testing on their own applications and include Apigee in the test.\n\n### **RTO/RPO**\n\n\nApigee does not offer recovery point and recovery time objectives (RPO/RTO) for customers or in\ncontracts related to BCP/DR activities. SLAs are the cloud equivalent of the RTO/RPO data\npoints. Because Apigee is a redundant cloud based service with both management and runtime\nservices being architected with redundant live services, RTO and RPO can both be seen as\n'real-time'. Single region customers receive a minimum of redundant services in different\ndatacenters within the same region. Customers desiring higher levels of redundancy can opt\nfor multi-region services.\n\n### **Pandemic plan**\n\n\nGoogle includes a pandemic plan as part of the overall BCP/DR plan and processes. For\nbusiness operations such as support, Google operates a 24x7 global support team across\nmultiple offices and remote locations. If a pandemic in one area of the globe impacts one\nof our support locations, personnel in other offices will be alerted and cover the shifts\nnormally handled by the impacted office. For other business services such as sales, the\nworkforce is globally distributed. All teams at Google are equipped to work remotely if\nneeded. Tools used are cloud-based and lend themselves naturally to a pandemic response plan.\n\n### **Updates**\n\n\nGoogle reviews and updates our BCP/DR plan at least annually. Information gathered from\nincidents, product changes, industry standards, risk analysis activities, and BCP/DB\ntesting are used to update the plan.\n\n### **Business Impact Analysis and Risk Assessments**\n\n\nGoogle conducts a business impact analysis and a Risk assessment annually. Results of the\nBIA and the RA are prioritized and documented in the issue tracking system."]]