[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[[["\u003cp\u003eApigee operates as a multitenant, cloud-based platform with live/live redundancy across multiple data centers and regions, ensuring continuous service availability.\u003c/p\u003e\n"],["\u003cp\u003eApigee's Business Continuity Planning and Disaster Recovery (BCP/DR) is a platform-wide plan designed to handle disruptions and outages without individual customer intervention.\u003c/p\u003e\n"],["\u003cp\u003eGoogle conducts frequent operational processes that include taking down an entire data center for updates, while the load is serviced by other live centers to ensure the services have no issues, and also conducts annual BCP/DR testing involving simulated disaster scenarios.\u003c/p\u003e\n"],["\u003cp\u003eCustomers are encouraged to incorporate Apigee into their own disaster recovery plans, considering traffic redirection during outages, although this testing is beyond Apigee's core BCP/DR scope.\u003c/p\u003e\n"],["\u003cp\u003eApigee does not offer specific recovery point and recovery time objectives (RPO/RTO), but provides real-time service due to its redundant architecture, and the service offers single and multi region capabilities for customers.\u003c/p\u003e\n"]]],[],null,["# Business continuity planning and disaster recovery\n\n*This page\napplies to **Apigee** and **Apigee hybrid**.*\n\n\n*View [Apigee Edge](https://docs.apigee.com/api-platform/get-started/what-apigee-edge) documentation.*\n\n\nApigee is a multitenant, self-service, cloud-based platform that runs in a fully redundant\n(live/live) configuration across multiple datacenters in multiple regions of the globe.\nApigee uses Google Cloud for its cloud-based platform. As part of the services we build on\nGoogle Cloud, we use multiple data centers within each region and service live traffic for\nour customers across these multiple data centers. We do not have a \"live\" data center and a\n\"standby\" (or \"secondary\" or \"failover\") data center. We have two (or more) data centers\nconstantly and simultaneously servicing customer traffic in each region globally.\n\n**BCP/DR plan**\n---------------\n\n\nApigee Business Continuity Planning and Disaster Recovery (BCP/DR) is a platform-wide plan\nand does not contain detailed tasks for individual customers. Rather, the platform is\nconfigured to process customer data requests regardless of disruptions and outages. The\ndata will continue to flow even if an entire data center is offline. If an entire region\nwere to go offline, a single-region customer could experience an outage of API processing\nservices. For customers looking for more than \"in-region\" redundant services, Apigee is\navailable at a globally redundant level of redundant data centers where traffic can be\nserviced in multiple regions or countries so that if an entire region were to go offline,\nthe data would still flow.\n\n\nSingle-region customer services are not automatically transferred to another region because of\npossible geographic restrictions on data processing and access. Apigee services are hosted\nfor customers in the region identified by the customer. Because there may be specific\nregulations or customer commitments to their users on geographic locations of data, services\nwill not automatically move to an alternate region, as this could potentially compromise\nGoogle's commitments to its customers or Google customers' commitments to their customers.\n\n\nGoogle does not share the full BCP/DR plan with any individual customer, as it contains internal\nsensitive information and references to our customers. Our privacy policy prevents sharing the\nplatform BCP/DR plan with individual customers that could potentially expose other customer\nnames. We offer this same level of privacy to each customer.\n\n**BCP/DR Management**\n---------------------\n\n\nA Google Information Security team is responsible for the oversight of the Business\nResiliency program while a rotating Incident Commander is responsible for management\nand resolution of all incidents. The Incident Commander has operational and engineering\npersonnel on call at all times along with playbooks for all actions that may need to be taken.\n\n**BCP/DR Testing**\n------------------\n\n\nGoogle performs operational processes that support BCP/DR testing of the platform on a more\nfrequent cadence than our full annual BCP/DR testing. Each month we perform load swings\nfrom our live/live environment while we perform updates to the systems running the service.\nThis process involves taking down one entire data center's worth of systems while the load\nis handled by the peer datacenter. During this process, after any updates are performed,\nthe first data center is brought back up and services are run live/live again to verify\nthat no issues were introduced. Then the peer datacenter is brought down for the same\nupdates and then brought back online again. Google uses tools and techniques to drain traffic\nand send a small percentage of traffic to recently updated services to check for any issues\nor errors before going back to full load processing.\n\n\nThis consistent operational process exceeds industry-standard bi-annual resiliency \"testing\" of\nour service by making it an operational task that occurs more frequently.\n\n\nIn addition to the operational processes described above, Google also conducts BCP/DR exercises\nat least once annually where engineering and operations team members test a real disaster\nscenario. This provides additional training and experience for our personnel on our larger\nBCP/DR plans for the enterprise as a whole in addition to the service itself.\n\n\nThe BCP/DR testing done by Google does not use \"failover exercises\" or \"secondary locations\"\nbecause all of that is built into the running system.\n\n\nGoogle does maintain Playbooks for use by all operational and engineering teams. These\nplaybooks are reviewed and updated at least annually and used in all of our BCP/DR testing\nand training exercises.\n\n\nAnnual BCP/DR test reports are available for customers. We also share the results of our\noperational tasks and annual DR exercise test reports with our third-party auditors,\nand these form the basis for the auditor's review of our compliance with PCI, HIPAA,\nISO, contractual, and other requirements.\n\n### **Customer BCP/DR tests**\n\n\nCustomers are encouraged to have their own DR plans incorporate Apigee services. Customers\ncan and should consider how Apigee can redirect traffic as needed for customers to maintain\nend-user services even during a customer data center outage or other disaster event.\nHowever, this level of testing is outside the scope of the Apigee DR plan. We encourage\ncustomers to perform BCP/DR testing on their own applications and include Apigee in the test.\n\n### **RTO/RPO**\n\n\nApigee does not offer recovery point and recovery time objectives (RPO/RTO) for customers or in\ncontracts related to BCP/DR activities. SLAs are the cloud equivalent of the RTO/RPO data\npoints. Because Apigee is a redundant cloud based service with both management and runtime\nservices being architected with redundant live services, RTO and RPO can both be seen as\n'real-time'. Single region customers receive a minimum of redundant services in different\ndatacenters within the same region. Customers desiring higher levels of redundancy can opt\nfor multi-region services.\n\n### **Pandemic plan**\n\n\nGoogle includes a pandemic plan as part of the overall BCP/DR plan and processes. For\nbusiness operations such as support, Google operates a 24x7 global support team across\nmultiple offices and remote locations. If a pandemic in one area of the globe impacts one\nof our support locations, personnel in other offices will be alerted and cover the shifts\nnormally handled by the impacted office. For other business services such as sales, the\nworkforce is globally distributed. All teams at Google are equipped to work remotely if\nneeded. Tools used are cloud-based and lend themselves naturally to a pandemic response plan.\n\n### **Updates**\n\n\nGoogle reviews and updates our BCP/DR plan at least annually. Information gathered from\nincidents, product changes, industry standards, risk analysis activities, and BCP/DB\ntesting are used to update the plan.\n\n### **Business Impact Analysis and Risk Assessments**\n\n\nGoogle conducts a business impact analysis and a Risk assessment annually. Results of the\nBIA and the RA are prioritized and documented in the issue tracking system."]]