[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[[["\u003cp\u003eThis Apigee hybrid documentation version 1.3 is end-of-life and should be upgraded to a newer version.\u003c/p\u003e\n"],["\u003cp\u003eAn Apigee hybrid installation consists of multiple pods, each with specific port access requirements and internal connections.\u003c/p\u003e\n"],["\u003cp\u003ePods such as \u003ccode\u003eapigee-logger\u003c/code\u003e and \u003ccode\u003eapigee-metrics\u003c/code\u003e send application logs to Cloud Operations, while \u003ccode\u003eapigee-cassandra\u003c/code\u003e is the runtime persistence layer.\u003c/p\u003e\n"],["\u003cp\u003eTo secure runtime pods, Google recommends reviewing the Kubernetes security overview and implementing network policies to restrict pod communication.\u003c/p\u003e\n"],["\u003cp\u003eNetwork policies, which can be implemented using a CNI plugin like Calico, allow for the isolation of pods and the control of access to specific pods.\u003c/p\u003e\n"]]],[],null,["# Securing the runtime installation\n\n| You are currently viewing version 1.3 of the Apigee hybrid documentation. **This version is end of life.** You should upgrade to a newer version. For more information, see [Supported versions](/apigee/docs/hybrid/supported-platforms#supported-versions).\nA typical Apigee hybrid installation is made of multiple pods, as listed in the following table. Each of these pods require specific access to ports, and not every pod needs to communicate with every other pod. For a detailed map of these internal connections and the security protocols they employ, see [Internal connections](/apigee/docs/hybrid/v1.3/ports#internal).\n\n\u003cbr /\u003e\n\n\nGoogle recommends that you follow these methods and best practices to harden,\nsecure, and isolate the runtime\npods:"]]