Supported versions:
Unsupported versions:
The Apigee hybrid installer uses defaults for many settings; however, there are a few settings that do not have defaults. You must provide values for these settings, as explained next.
hybrid-base-directory/hybrid-files/overrides/ directory.
cd hybrid-base-directory/hybrid-files/overrides
overrides.yaml in your favorite text editor. For
example:
vi overrides.yaml
The overrides.yaml provides the configuration for your unique Apigee hybrid
installation. The overrides file in this step provides a basic configuration for a small-footprint
hybrid runtime installation, suitable for your first installation.
overrides.yaml, add the required property values, shown below. A detailed
description of each property is also provided below:
For installations in production environments, look at the storage requirements for the Cassandra database in Configure Cassandra for production.
Make sure the overrides.yaml file has the following structure and syntax.
Values in red, bold italics are
property values that you must provide. They are described in the table below.
There are differences between the different platforms for the Google Cloud project region and Kubernetes cluster region. Choose the platform where you are installing Apigee hybrid.
gcp:
region: analytics-region
projectID: gcp-project-id
k8sCluster:
name: cluster-name
region: cluster-location # Must be the closest Google Cloud region to your cluster.
org: org-name
instanceID: "unique-instance-identifier" # See the property description table below information about this parameter.
cassandra:
hostNetwork: false
# Set to false for single region installations and multi-region installations
# with connectivity between pods in different clusters, for example GKE installations.
# Set to true for multi-region installations with no communication between
# pods in different clusters, for example GKE On-prem, GKE on AWS, Anthos on bare metal,
# AKS, EKS, and OpenShift installations.
# See Multi-region deployment: Prerequisites
storage:
capacity: 500Gi
resources:
requests:
cpu: 7
memory: 15Gi
maxHeapSize: 8192M
heapNewSize: 1200M
# Minimum storage requirements for a production environment.
# See Configure Cassandra for production.
virtualhosts:
- name: environment-group-name
sslCertPath: ./certs/cert-name.pem
sslKeyPath: ./certs/key-name.key
envs:
- name: environment-name
serviceAccountPaths:
synchronizer: ./service-accounts/synchronizer-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-synchronizer.json
udca: ./service-accounts/udca-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-udca.json
runtime: ./service-accounts/runtime-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-runtime.json
mart:
serviceAccountPath: ./service-accounts/mart-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-mart.json
connectAgent:
serviceAccountPath: ./service-accounts/mart-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-mart.json
# Use the same service account for mart and connectAgent
metrics:
serviceAccountPath: ./service-accounts/metrics-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-metrics.json
udca:
serviceAccountPath: ./service-accounts/udca-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-udca.json
watcher:
serviceAccountPath: ./service-accounts/watcher-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-watcher.json
logger:
enabled: false
# Set to false to disable logger for GKE installations.
# Set to true for all platforms other than GKE.
# See apigee-logger in Service accounts and roles used by hybrid components.
serviceAccountPath: ./service-accounts/logger-service-account-name.json
# for non-production environments, gcp-project-id-apigee-non-prod.json
# for production environments, gcp-project-id-apigee-logger.json
The following example shows a completed overrides file with example property values added:
gcp:
region: us-central1
projectID: hybrid-example
k8sCluster:
name: apigee-hybrid
region: us-central1
org: hybrid-example
instanceID: "my_hybrid_example"
cassandra:
hostNetwork: false
virtualhosts:
- name: example-env-group
sslCertPath: ./certs/keystore.pem
sslKeyPath: ./certs/keystore.key
envs:
- name: test
serviceAccountPaths:
synchronizer: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-synchronizer.json
udca: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-udca.json
runtime: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-runtime.json
mart:
serviceAccountPath: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-mart.json
connectAgent:
serviceAccountPath: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, example-hybrid-apigee-mart.json
metrics:
serviceAccountPath: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-metrics.json
udca:
serviceAccountPath: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-udca.json
watcher:
serviceAccountPath: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, hybrid-project-apigee-watcher.json
logger:
enabled: false # Set to "false" for GKE. Set to "true" for all other kubernetes platforms.
serviceAccountPath: ./service-accounts/hybrid-project-apigee-non-prod.json
# for production environments, logger-service-account-name.json
The following table describes each of the property values that you must provide in the overrides file. For more information, see Configuration property reference.
This is the value you assigned to the environment variable
ANALYTICS_REGION previously.
apigee-logger and the apigee-metrics push
their data. This is the value assigned to the environment variable PROJECT_ID.CLUSTER_NAME.
This is the value you assigned to the environment variable
CLUSTER_LOCATION previously.
ORG_NAME.A unique string to identify this Apigee hybrid instance per cluster. The string can be a combination of letters and numbers up to 63 characters in length.
instanceID value for each time you add a new org to the
same cluster.instanceID.If you need help generating a unique ID, you can use a random string generation tool of your choice, such as random.org/strings.
ENV_GROUP.
base_directory/hybrid-files/certs directory. For example:
sslCertPath: ./certs/keystore.pem sslKeyPath: ./certs/keystore.key
non-prod by default. For production environments, the name of the
apigee-synchronizer service account key file that you generated
with the create-service-account tool in
Hybrid runtime setup -
Step 6: Create service accounts and credentials. You can see the list of service
account files in your service-accounts/ directory. Fore example:
ls ../service-accounts/
non-prod by default. For production environments, the name of the
apigee-udca service account key file that you generated
with the create-service-account tool. non-prod by default. For production environments, the
name of the apigee-runtime service account key file that
you generated with the create-service-account tool. non-prod by default. For production environments, the name of the
apigee-mart service account key file that you generated
with the create-service-account tool.
non-prod by default. For production environments, the name of the
apigee-metrics service account key file that you generated
with the create-service-account tool. non-prod by default. For production environments, the name of the
apigee-udca service account key file that you generated
with the create-service-account tool. non-prod by default. For production environments, the name of the
apigee-watcher service account key file that you generated
with the create-service-account tool. non-prod by default. For production environments, the name of the
apigee-logger service account key file that you generated
with the create-service-account tool. The configuration file tells Kubernetes how to deploy the hybrid components to a cluster. Next, you will enable synchronizer access so the Apigee runtime and management planes will be able to communicate.
1 2 3 4 5 6 7 (NEXT) Step 8: Enable Synchronizer access 9Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-07-23 UTC.