diff --git a/en/docs/api-gateway/federated-gateways/apigee/discover-apis-on-apigee-gateway.md b/en/docs/api-gateway/federated-gateways/apigee/discover-apis-on-apigee-gateway.md new file mode 100644 index 0000000000..8f357bbe36 --- /dev/null +++ b/en/docs/api-gateway/federated-gateways/apigee/discover-apis-on-apigee-gateway.md @@ -0,0 +1,85 @@ +# Discover APIs on Google Apigee Gateway + +WSO2 API Manager supports federated API discovery for APIs deployed on Google Apigee. This enables API proxies created and managed in Apigee to be discovered and brought under the centralized control plane of WSO2 API Manager. + +Once discovered, these APIs can fully leverage the control plane capabilities of WSO2 API Manager, including: + +- **Governance enforcement** – Apply security, compliance, and lifecycle policies consistently. +- **Unified management** – Maintain a centralized view of all APIs, eliminating manual imports and fragmented operations. +- **Developer Portal features** – Provide a unified catalog where developers can discover Apigee-hosted APIs, explore documentation, test endpoints, subscribe to APIs, and access keys and tokens seamlessly. + +By integrating Apigee APIs into the control plane, organizations can ensure consistent standards, stronger governance, and improved visibility across their API ecosystem. + +Follow the steps below to configure Google Apigee as a Federated API Gateway for API discovery. + +## Step 1: Create a GCP Service Account and Generate a JSON Key + +1. Log in to the [Google Cloud Console](https://console.cloud.google.com/) and navigate to **IAM & Admin** > **Service Accounts**. +2. Click **Create Service Account** and provide a name (e.g., `wso2-apim-discovery`). +3. Grant the service account the `Apigee API Admin` role (or `Apigee API Reader` for read-only access). + + If you maintain OpenAPI specifications for your API proxies in Apigee API Hub, also grant the `API Hub Viewer` role. Without it, the specifications cannot be read from API Hub, and the APIs are imported with a generated placeholder definition instead of their actual resources. +4. Navigate to the newly created service account, click **Keys** > **Add Key** > **Create new key**. +5. Select **JSON** as the key type and click **Create**. A JSON key file will be downloaded. + + !!!warning + Keep this JSON key file safe. It contains credentials that grant access to your Apigee organization. You will need to paste the full JSON content when configuring the gateway in WSO2 API Manager. + +## Step 2: Register Apigee Gateway as a Federated Gateway in WSO2 API Manager + +1. Start WSO2 API Manager. + +2. Sign in to the Admin Portal. + + `https://:9443/admin` + + `https://localhost:9443/admin` + +3. Add a new Gateway Environment. + 1. Select the **Gateway Type** as **Apigee** from the dropdown and provide the relevant details in the fields accordingly. + 2. Select the **Gateway Mode** as **Read Only**. + 3. Under **Gateway Connector Configurations**, provide the following: + - **Apigee Organization** – The GCP project ID (e.g., `my-gcp-project`). + - **Apigee Environment** – The target environment name (e.g., `eval`, `test`, `prod`). + - **Service Account JSON Credentials** – The full contents of the GCP service account JSON key file obtained in Step 1. The content should start with `{` and end with `}`. + - **API Hostname** – The hostname where APIs are accessible (e.g., `34.49.61.76.nip.io` or `api.example.com`). Leave empty to use the default `{org}-{env}.apigee.net`. + - **API Hub Location** – The GCP region in which your API Hub instance is provisioned (e.g., `global`, `us-west1`). You can find this in the Google Cloud Console under **Apigee** > **API hub**, where the region is shown with the API hub instance. + + !!! warning + The **API Hub Location** must match the region of your API hub instance exactly. If it does not, the specifications cannot be retrieved and the APIs are imported with a generated placeholder definition instead of their actual resources. See [OpenAPI Specifications for Discovered APIs](#openapi-specifications-for-discovered-apis). + + 4. Provide the scheduling interval for API discovery in minutes (e.g., set to `0` to disable background scheduling). + 5. Save the configurations. + + [![add apigee gateway discovery environment]({{base_path}}/assets/img/deploy/add-apigee-gw-discovery.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-apigee-gw-discovery.png) + +## Step 3: Discover and Publish to Developer Portal + +1. Sign in to the Publisher Portal. + + `https://:9443/publisher` + + `https://localhost:9443/publisher` + +2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/). +3. Once imported, click on the API from the listing to view its details. +4. From the left menu, click **Lifecycle** and select **Publish** so that the API will deploy to the Developer Portal. + +## Step 4: Invoke the API + +1. Sign in to the Developer Portal. + + `https://:9443/devportal` + + `https://localhost:9443/devportal` + +2. Navigate to tryout and invoke the API. + +!!!note + The Apigee connector operates in **Read-Only** mode. It only discovers APIs from Apigee, it does not deploy APIs to Apigee. + +## OpenAPI Specifications for Discovered APIs + +If you maintain OpenAPI specifications for your API proxies in Apigee API Hub, the connector attaches them to the discovered APIs. For a specification to be retrieved, its API Hub entry must reside in the region configured as the **API Hub Location**, and its display name must exactly match the name of the API proxy. + +If a specification cannot be retrieved, the API is still imported, but with a generated placeholder definition that exposes a single wildcard resource instead of its actual resources. If you see this, verify the **API Hub Location**, confirm that the API Hub display name matches the proxy name, and ensure that the service account has the `API Hub Viewer` role. diff --git a/en/docs/api-gateway/federated-gateways/aws/deploy-on-aws-api-gateway.md b/en/docs/api-gateway/federated-gateways/aws/deploy-on-aws-api-gateway.md index e9d8c56232..5c50d2257a 100644 --- a/en/docs/api-gateway/federated-gateways/aws/deploy-on-aws-api-gateway.md +++ b/en/docs/api-gateway/federated-gateways/aws/deploy-on-aws-api-gateway.md @@ -7,6 +7,9 @@ Follow the instructions given below to configure AWS API Gateway as a Federated ## Step 1: Configure User Credentials in AWS API Gateway +!!!note + This step creates the static Access Key and Secret Key used by the first authentication method described in Step 2. If WSO2 API Manager runs on AWS infrastructure and you intend to use the IAM role of the host instead, you can skip this step. + 1. Login to your [AWS](https://console.aws.amazon.com/) account and navigate to Console Home. Search for “IAM” in the search bar. 2. Click on the IAM service. Navigate to **Users** under **Access Management**. 3. Create an IAM user in AWS with `AmazonAPIGatewayAdministrator` permission. @@ -27,7 +30,17 @@ Follow the instructions given below to configure AWS API Gateway as a Federated 3. Add a new Gateway Environment. 1. Select the Gateway type as AWS and provide the relevant details in the fields accordingly. - 2. Enter the Access Key and Secret Key obtained in Step 1 under Gateway configurations. + 2. Under **Gateway Connector Configurations**, provide the following: + - **AWS Region** – The region that hosts your AWS API Gateway (e.g., `us-east-1`). + - **Access Key** and **Secret Key** – The static keys obtained in Step 1. Leave both blank to use the IAM role of the host on which WSO2 API Manager runs, such as an EC2 instance profile or an EKS pod identity. + - **IAM Role ARN** – Optional. The ARN of an IAM role to assume (e.g., `arn:aws:iam::123456789012:role/MyRole`), which enables cross-account deployments. + - **Stage Name** – The default stage to which the APIs are deployed in AWS API Gateway (e.g., `prod`). + + The **IAM Role ARN** is not an alternative to the credentials above it. When provided, the role is assumed using whichever credentials were resolved, so it can be combined with either the static keys or the IAM role of the host. + + !!!note + To assume a role, the identity resolved from the credentials above must be allowed to perform the `sts:AssumeRole` action, and the trust policy of the role being assumed must permit that identity to assume it. The assumed role must also carry the API Gateway permissions described in Step 1. + 3. Save the configurations. [![add aws gateway environment]({{base_path}}/assets/img/deploy/add-aws-gw-environment.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-aws-gw-environment.png) diff --git a/en/docs/api-gateway/federated-gateways/aws/discover-apis-on-aws-api-gateway.md b/en/docs/api-gateway/federated-gateways/aws/discover-apis-on-aws-api-gateway.md index b517f83adb..ae60eb04c3 100644 --- a/en/docs/api-gateway/federated-gateways/aws/discover-apis-on-aws-api-gateway.md +++ b/en/docs/api-gateway/federated-gateways/aws/discover-apis-on-aws-api-gateway.md @@ -4,11 +4,9 @@ From 4.6.0 release, WSO2 API Manager supports federated API discovery for APIs d Once discovered, these APIs can fully leverage the control plane capabilities of WSO2 API Manager, including: -Governance enforcement – apply security, compliance, and lifecycle policies consistently. - -Unified management – maintain a centralized view of all APIs, eliminating manual imports and fragmented operations. - -Developer Portal Features – provide a unified catalog where developers can discover AWS-hosted APIs, explore documentation, test endpoints, subscribe to APIs, and access keys and tokens seamlessly. +- **Governance enforcement** – Apply security, compliance, and lifecycle policies consistently. +- **Unified management** – Maintain a centralized view of all APIs, eliminating manual imports and fragmented operations. +- **Developer Portal features** – Provide a unified catalog where developers can discover AWS-hosted APIs, explore documentation, test endpoints, subscribe to APIs, and access keys and tokens seamlessly. By integrating AWS APIs into the control plane, organizations can ensure consistent standards, stronger governance, and improved visibility across their API ecosystem. @@ -16,9 +14,16 @@ Follow the instructions given below to configure AWS API Gateway as a Federated ## Step 1: Configure User Credentials in AWS API Gateway +!!!note + This step creates the static Access Key and Secret Key used by the first authentication method described in Step 2. If WSO2 API Manager runs on AWS infrastructure and you intend to use the IAM role of the host instead, you can skip this step. + 1. Login to your [AWS](https://console.aws.amazon.com/) account and navigate to Console Home. Search for “IAM” in the search bar. 2. Click on the IAM service. Navigate to **Users** under **Access Management**. 3. Create an IAM user in AWS with `AmazonAPIGatewayAdministrator` permission. + + !!!tip + When the gateway is registered in **Read Only** mode, the identity only reads APIs from AWS API Gateway, so read-level permissions such as `apigateway:GET` are sufficient. + 4. Obtain an Access Key and Secret Access Key for the IAM user created in the previous step. Select **Third-party service** as the use case. !!!note @@ -37,7 +42,17 @@ Follow the instructions given below to configure AWS API Gateway as a Federated 3. Add a new Gateway Environment. 1. Select the Gateway Type as AWS Gateway from the dropdown and provide the relevant details in the fields accordingly. 2. Select the Gateway Mode as Read Only, or Read Write based on the requirement. - 3. Enter the Access Key and Secret Key obtained in Step 1 under Gateway Connector Configurations. + 3. Under **Gateway Connector Configurations**, provide the following: + - **AWS Region** – The region that hosts your AWS API Gateway (e.g., `us-east-1`). + - **Access Key** and **Secret Key** – The static keys obtained in Step 1. Leave both blank to use the IAM role of the host on which WSO2 API Manager runs, such as an EC2 instance profile or an EKS pod identity. + - **IAM Role ARN** – Optional. The ARN of an IAM role to assume (e.g., `arn:aws:iam::123456789012:role/MyRole`), which enables cross-account API discovery. + - **Stage Name** – The default stage of the APIs in AWS API Gateway (e.g., `prod`). + + The **IAM Role ARN** is not an alternative to the credentials above it. When provided, the role is assumed using whichever credentials were resolved, so it can be combined with either the static keys or the IAM role of the host. + + !!!note + To assume a role, the identity resolved from the credentials above must be allowed to perform the `sts:AssumeRole` action, and the trust policy of the role being assumed must permit that identity to assume it. The assumed role must also carry the API Gateway permissions described in Step 1. + 4. Provide the scheduling interval for API discovery in minutes. 5. Save the configurations. @@ -47,16 +62,16 @@ Follow the instructions given below to configure AWS API Gateway as a Federated [![add aws gateway discovery environment]({{base_path}}/assets/img/deploy/add-aws-gw-environment.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-aws-gw-discovery.png) -## Step 3 : Deploy to Developer Portal +## Step 3: Discover and Publish to Developer Portal -1. Sign in to Publisher Portal. +1. Sign in to the Publisher Portal. `https://:9443/publisher` `https://localhost:9443/publisher` -2. Go to APIs view and the APIs discovered from AWS API Gateway will be listed. -3. Click on the API to view the API details. -4. From the left menu, click **Lifecycle** and select **Publish** so that API will deploy to the Developer Portal. +2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/). +3. Once imported, click on the API from the listing to view its details. +4. From the left menu, click **Lifecycle** and select **Publish** so that the API will deploy to the Developer Portal. ## Step 4 : Invoke the API 1. Sign in to the Developer Portal. diff --git a/en/docs/api-gateway/federated-gateways/azure/discover-apis-on-azure-api-gateway.md b/en/docs/api-gateway/federated-gateways/azure/discover-apis-on-azure-api-gateway.md index bdfaa2694c..bc7653c1d9 100644 --- a/en/docs/api-gateway/federated-gateways/azure/discover-apis-on-azure-api-gateway.md +++ b/en/docs/api-gateway/federated-gateways/azure/discover-apis-on-azure-api-gateway.md @@ -65,9 +65,9 @@ Follow the instructions given below to configure Azure API Gateway as a Federate `https://localhost:9443/publisher` -2. Go to APIs view and the APIs discovered from Azure API Gateway will be listed. -3. Click on the API to view the API details. -4. From the left menu, click **Lifecycle** and select **Publish** so that API will deploy to the Developer Portal. +2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/). +3. Once imported, click on the API from the listing to view its details. +4. From the left menu, click **Lifecycle** and select **Publish** so that the API will deploy to the Developer Portal. ## Step 4 : Invoke the API 1. Sign in to the Developer Portal. diff --git a/en/docs/api-gateway/federated-gateways/federated-api-discovery.md b/en/docs/api-gateway/federated-gateways/federated-api-discovery.md new file mode 100644 index 0000000000..743c6c2385 --- /dev/null +++ b/en/docs/api-gateway/federated-gateways/federated-api-discovery.md @@ -0,0 +1,129 @@ +# Federated API Discovery + +WSO2 API Manager supports discovering APIs deployed on external third-party API gateways (such as AWS, Azure, Google Apigee, Kong, etc.) and bringing them under a centralized control plane. + +Publishers can trigger discovery on-demand, inspect the discovered APIs, and selectively import or update them in WSO2 API Manager. + +--- + +## Prerequisites + +Before discovering APIs, ensure that the external gateway has been registered as a Gateway Environment in the Admin Portal, with a **Gateway Mode** of **Read Only** or **Read Write**. Discovery is not available for gateways registered in **Write Only** mode. + +For gateway-specific registration steps, see the documentation for your gateway type, such as [Apigee]({{base_path}}/api-gateway/federated-gateways/apigee/discover-apis-on-apigee-gateway/), [AWS]({{base_path}}/api-gateway/federated-gateways/aws/discover-apis-on-aws-api-gateway/), [Azure]({{base_path}}/api-gateway/federated-gateways/azure/discover-apis-on-azure-api-gateway/), or [Kong]({{base_path}}/api-gateway/federated-gateways/kong/kong-standalone/discover-apis-on-kong-gateway/). + +--- + +## On-Demand and Scheduled Discovery + +Discovery can run in either of the following ways, controlled by the `enable_scheduler` setting in the `/repository/conf/deployment.toml` file: + +``` toml +[apim.federated_api_discovery] +enable_scheduler = false +``` + +- **On-demand discovery (default, `enable_scheduler = false`)**: Discovery runs only when a publisher explicitly triggers it from the Publisher Portal or through the REST API. This is the recommended mode. +- **Scheduled discovery (`enable_scheduler = true`)**: A background task periodically discovers and imports APIs automatically, using the **API Discovery Scheduling Interval** configured on each gateway environment. + +!!! note + The **API Discovery Scheduling Interval** field is required when registering a Read Only or Read Write gateway environment, but it only takes effect when `enable_scheduler` is set to `true`. When scheduled discovery is disabled, the value is retained but not used, so it can be left at `0`. + +--- + +## Discovering and Importing APIs via the Publisher Portal + +To discover and import APIs from a registered external gateway: + +1. Log in to the Publisher Portal. + + `https://:9443/publisher` + +1. Click on **Discover APIs** to view the list of configured Gateway Environments. + + [![API Gateways list view]({{base_path}}/assets/img/deploy/federated-gateways-list.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/federated-gateways-list.png) + +1. On the gateway environment listing page, click on the specific gateway and proceed. + + [![Discover APIs Dialog]({{base_path}}/assets/img/deploy/discover-apis-dialog.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/discover-apis-dialog.png) + +1. Once the discovery process is complete, the portal displays a list of discovered APIs in a table with their details and discovery status: + * **New**: The API exists on the external gateway but has not been imported to WSO2 API Manager. + * **Update**: The API has already been imported, and changes have been detected on the external gateway. + + !!! note + The exact changes that mark an API as **Update** depend on the gateway connector. Connectors typically detect changes such as a new deployment or revision of the API on the external gateway. Changes made only to an API's specification, without any corresponding change to the API on the gateway itself, may not be detected by every connector. + + [![Discovered APIs List]({{base_path}}/assets/img/deploy/discovered-apis-list.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/discovered-apis-list.png) + + To import or update APIs, select the checkbox next to the APIs you want to import or update. To select all discovered APIs at once, check the selection box in the table header. Click **Import** to bring the new APIs into WSO2 API Manager, or click **Update** to sync changes for existing ones. + + Once successfully imported, these APIs will appear in the main Publisher Portal API catalog. From here, you can configure their lifecycle, apply policies, and publish them to the Developer Portal. + +--- + +## Automated Workflow via REST APIs + +For automation or CI/CD pipelines, you can programmatically trigger and manage API discovery using the following asynchronous REST APIs. + +All the resources given below are relative to the Publisher REST API context, which is `https://:9443/api/am/publisher/v4`. These operations require an OAuth 2.0 access token with the `apim:api_create` or `apim:api_manage` scope. + +1. **Trigger Discovery**: + Send a `POST` request to start the discovery task for a registered gateway environment. + ```http + POST /federated-apis/discover?environment={gatewayName} + ``` + * **Response**: Returns a `202 Accepted` status with a `taskId` (e.g., `{"taskId": "df2b5346-c2ba-4b68-8be4-f77df2307ef5"}`). + +1. **Poll Status**: + Poll the task status periodically using the `taskId` returned in the previous step. + ```http + GET /federated-apis/status/{taskId} + ``` + * **Response**: Returns the task status (`PENDING`, `COMPLETED`, or `FAILED`). + +1. **Retrieve Cached Results**: + Once the task status is `COMPLETED`, retrieve the list of discovered APIs cached in the database. + ```http + GET /federated-apis/cached?environment={gatewayName} + ``` + +1. **Import or Update APIs**: + Submit the list of APIs you want to import or update. Use the `import` resource for APIs discovered with the **New** status, and the `update` resource for APIs discovered with the **Update** status. + ```http + POST /federated-apis/import?environment={gatewayName} + POST /federated-apis/update?environment={gatewayName} + ``` + * **Request body**: An array of the APIs to import or update. The `id` of each entry is the identifier returned for that API by the discovery result, and is the only required field. Optionally, provide `displayName` and `description` to override the values discovered from the gateway. + + ``` json + [ + { + "id": "abcd1234", + "displayName": "Customer API", + "description": "Provides customer details." + } + ] + ``` + + * **Response**: Returns a summary of the outcome, where `failedIds` lists the APIs that could not be imported or updated. + + ``` json + { + "status": "1 API(s) imported successfully", + "failedIds": [] + } + ``` + +--- + +## Troubleshooting + +| Symptom | Possible cause | +|---|---| +| No APIs are discovered from the gateway. | The APIs are not deployed to the environment configured for the gateway, or the configured credentials do not have permission to list them. Verify the environment name and credentials in the Admin Portal. | +| An imported API contains a single wildcard resource instead of its actual resources. | The API's specification could not be retrieved from the gateway, so a placeholder definition was generated instead. Verify the specification-related configurations and permissions for your gateway type. | +| An API that was changed on the gateway is not listed with the **Update** status. | The change may not be one that the connector detects. See the note under [Discovering and Importing APIs via the Publisher Portal](#discovering-and-importing-apis-via-the-publisher-portal). | +| Discovery fails with an authentication or authorization error. | The credentials configured for the gateway environment are invalid or have expired, or they lack the permissions required to read APIs from the gateway. | + +If discovery fails, inspect the API Manager logs for the underlying error reported by the gateway connector. diff --git a/en/docs/api-gateway/federated-gateways/kong/kong-standalone/discover-apis-on-kong-gateway.md b/en/docs/api-gateway/federated-gateways/kong/kong-standalone/discover-apis-on-kong-gateway.md index 06439414c5..8aeb5f291a 100644 --- a/en/docs/api-gateway/federated-gateways/kong/kong-standalone/discover-apis-on-kong-gateway.md +++ b/en/docs/api-gateway/federated-gateways/kong/kong-standalone/discover-apis-on-kong-gateway.md @@ -42,17 +42,17 @@ Follow the steps below to configure Kong Gateway as a Federated API Gateway for 1. Enter the **Name** obtained in Step 2 under Gateway configurations and select the **Gateway type** as **Kong Gateway** and provide the relevant details in the fields accordingly. 2. Select the Gateway mode as ReadOnly, or ReadWrite based on the requirement. - 3. Provide the Schedule time for the API discovery. + 3. Provide the scheduling interval for API discovery in minutes (e.g., set to `0` to disable background scheduling). 4. Select the **Deployment Type** as **Standalone** under **Gateway Connector configurations**. - 5. Enter the **Admin URL** with derived from the **Admin API** obtained in Step 2. Here the URL should be in the format `https://.api.konghq.com` under **Gateway Connector configurations**. Please note that the Admin URL should not contain the `/v2/control-planes` basepath. + 5. Enter the **Admin URL** derived from the **Admin API** obtained in Step 2. Here the URL should be in the format `https://.api.konghq.com` under **Gateway Connector configurations**. Please note that the Admin URL should not contain the `/v2/control-planes` basepath. 6. Enter the **Control Plane ID** derived from the **ID** obtained in Step 2 under **Gateway Connector configurations**. 7. Enter the **Access Token** obtained in Step 1 under **Gateway configurations**. - 8. Enter the **Vhost** derived from the **Proxy URL** obtained in Step 2. Here the for the Vhost provide only the hostname part of the Proxy URL. + 8. Enter the **Vhost** derived from the **Proxy URL** obtained in Step 2. Here, for the Vhost, provide only the hostname part of the Proxy URL. 9. Click **Add** button to add the Gateway. [![add kong gateway environment]({{base_path}}/assets/img/deploy/add-kong-gw-discovery.png){: style="width:90%"}]({{base_path}}/assets/img/deploy/add-kong-gw-discovery.png) -## Step 4 : Discover the API and Publish the API to Developer Portal +## Step 4: Discover the API and Publish the API to Developer Portal 1. Sign in to the Publisher Portal. @@ -65,7 +65,8 @@ Follow the steps below to configure Kong Gateway as a Federated API Gateway for https://:9443/publisher ``` -2. Select the Discovered API and click on the **Publish** button to publish the API to DevPortal. +2. Discover and import your APIs. For step-by-step instructions, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/). +3. Once imported, select the Discovered API and click on the **Publish** button to publish the API to DevPortal. ## Step 5 : Invoke the API diff --git a/en/docs/api-gateway/federated-gateways/overview.md b/en/docs/api-gateway/federated-gateways/overview.md index afdece9df4..3a9cac840d 100644 --- a/en/docs/api-gateway/federated-gateways/overview.md +++ b/en/docs/api-gateway/federated-gateways/overview.md @@ -7,14 +7,14 @@ WSO2 API Manager supports deploying APIs to external third-party API Gateways, e A federated gateway is an external API gateway that operates independently but is managed centrally through WSO2 API Manager. In this architecture: - **Central API Management**: WSO2 API Manager serves as the control plane where you define, version, secure, and monitor your APIs. -- **Distributed API Gateways**: APIs are deployed to multiple runtime gateways across different environments such as cloud platforms (AWS, Azure), on-premises systems, or Kubernetes clusters. +- **Distributed API Gateways**: APIs are deployed to multiple runtime gateways across different environments such as cloud platforms (AWS, Azure, Google Cloud/Apigee), on-premises systems, or Kubernetes clusters. This architectural pattern enables organizations to: - **Improve Performance**: Route API traffic to the nearest or most optimal gateway, reducing latency. - **Enhance Resilience**: Isolate failures so that issues in one gateway don't affect others. - **Maintain Governance**: Enforce policies and lifecycle management centrally across all federated gateways. -- **Enable Cloud Flexibility**: Deploy APIs across AWS, Azure, on-premises, or in hybrid/multi-cloud environments. +- **Enable Cloud Flexibility**: Deploy APIs across AWS, Azure, Google Cloud (Apigee), on-premises, or in hybrid/multi-cloud environments. ## Supported Gateway Types @@ -53,6 +53,17 @@ Discover and manage APIs deployed on Kong Gateway. WSO2 API Manager supports bot [Learn more about Kong Gateway integration]({{base_path}}/api-gateway/federated-gateways/kong/kong-standalone/discover-apis-on-kong-gateway/) +### Google Apigee Gateway +Discover and manage API proxies deployed on Google Apigee. The built-in Apigee gateway connector enables discovery of API proxies from your Apigee organization and brings them under centralized WSO2 API Manager governance. + +**Key Features:** +- Discover existing API proxies from Apigee organizations +- OpenAPI specification retrieval from Apigee API Hub +- GCP Service Account authentication +- Centralized governance from WSO2 API Manager + +[Learn more about Apigee Gateway discovery]({{base_path}}/api-gateway/federated-gateways/apigee/discover-apis-on-apigee-gateway/) + ### Envoy Gateway Discover and manage APIs deployed on Envoy Gateway in Kubernetes environments. @@ -71,6 +82,12 @@ Federated gateways can operate in different modes depending on your requirements - **Read-Only Mode**: Discover and import existing APIs from the federated gateway into WSO2 API Manager. - **Read-Write Mode**: Both deploy new APIs and discover existing APIs, providing full bidirectional synchronization. +## Federated API Discovery + +WSO2 API Manager allows discovering existing APIs from registered external gateways and importing them into your central repository. Publishers can trigger discovery on-demand through the Publisher Portal or REST APIs, and then selectively import or update APIs. + +For more information, see [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/). + ## Custom Gateway Agents If you need to integrate with a third-party gateway that is not supported out-of-the-box, WSO2 API Manager provides the flexibility to create custom gateway agents. This allows you to extend the federated gateway capabilities to any external gateway. @@ -92,10 +109,12 @@ Implementing a federated gateway architecture with WSO2 API Manager provides sev To get started with federated gateways: -1. **Choose Your Gateway**: Select the appropriate federated gateway based on your infrastructure (AWS, Azure, Kong, Envoy, or custom). +1. **Choose Your Gateway**: Select the appropriate federated gateway based on your infrastructure (Apigee, AWS, Azure, Kong, Envoy, or custom). 2. **Configure Credentials**: Set up the necessary credentials and permissions in your chosen gateway platform. 3. **Register Gateway**: Add the federated gateway as a new gateway environment in the WSO2 API Manager Admin Portal. -4. **Deploy APIs**: Create APIs in the Publisher Portal and deploy them to your federated gateway. +4. **Deploy or Discover APIs**: Depending on the mode the gateway is registered in: + - **Write-Only or Read-Write**: Create APIs in the Publisher Portal and deploy them to your federated gateway. + - **Read-Only or Read-Write**: Discover the APIs that already exist on the gateway and import them into WSO2 API Manager. See [Federated API Discovery]({{base_path}}/api-gateway/federated-gateways/federated-api-discovery/). 5. **Monitor and Manage**: Use WSO2 API Manager to monitor and manage your APIs across all federated gateways. ## Additional Resources diff --git a/en/docs/assets/img/deploy/add-apigee-gw-discovery.png b/en/docs/assets/img/deploy/add-apigee-gw-discovery.png new file mode 100644 index 0000000000..7549a35672 Binary files /dev/null and b/en/docs/assets/img/deploy/add-apigee-gw-discovery.png differ diff --git a/en/docs/assets/img/deploy/discover-apis-dialog.png b/en/docs/assets/img/deploy/discover-apis-dialog.png new file mode 100644 index 0000000000..f50b637012 Binary files /dev/null and b/en/docs/assets/img/deploy/discover-apis-dialog.png differ diff --git a/en/docs/assets/img/deploy/discovered-apis-list.png b/en/docs/assets/img/deploy/discovered-apis-list.png new file mode 100644 index 0000000000..e93b0f11c4 Binary files /dev/null and b/en/docs/assets/img/deploy/discovered-apis-list.png differ diff --git a/en/docs/assets/img/deploy/federated-gateways-list.png b/en/docs/assets/img/deploy/federated-gateways-list.png new file mode 100644 index 0000000000..522eced345 Binary files /dev/null and b/en/docs/assets/img/deploy/federated-gateways-list.png differ diff --git a/en/mkdocs.yml b/en/mkdocs.yml index 39250f5475..f475c03ffc 100644 --- a/en/mkdocs.yml +++ b/en/mkdocs.yml @@ -490,6 +490,9 @@ nav: - Configure Distributed Throttling: api-gateway/rate-limiting/distributed-throttling.md - Federated Gateways: - Overview: api-gateway/federated-gateways/overview.md + - Federated API Discovery: api-gateway/federated-gateways/federated-api-discovery.md + - Apigee: + - Discover APIs on Apigee Gateway: api-gateway/federated-gateways/apigee/discover-apis-on-apigee-gateway.md - AWS: - Deploy on AWS API Gateway: api-gateway/federated-gateways/aws/deploy-on-aws-api-gateway.md - Discover APIs on AWS API Gateway: api-gateway/federated-gateways/aws/discover-apis-on-aws-api-gateway.md