Apigee hybrid v1.17.0 Enhances AI Integration, Security, and Networking
Apigee hybrid v1.17.0 is now available, introducing new capabilities for integrating agentic AI applications and improving overall security and networking. This minor release adds support for the Model Context Protocol (MCP), allowing AI agents to use APIs as tools through managed endpoints. Key security enhancements include root CA certificate rotation without downtime, TLS 1.3 support, and reduced Google Cloud IAM permissions for service accounts. Additionally, it introduces forward proxy support for AI policies, Private Service Connect for semantic caching, and options for non-default Vertex AI Vector Search distance measures.
- →Model Context Protocol (MCP) support
- →Root CA certificate rotation
- →TLS 1.3 support
- →Forward proxy support for AI policies
- →Semantic cache Private Service Connect (PSC) endpoint support
Security (1) ›
- Apigee hybrid
Various security and CVE fixes are included in this release.
Features (7) ›
- Apigee hybrid Model Context Protocol (MCP) support
Model Context Protocol (MCP) support Apigee hybrid now supports Model Context Protocol (MCP) , an open protocol that lets agentic AI applications use your APIs as tools through managed MCP endpoints. Apigee hybrid routes, authorizes, and secures these MCP tool calls the same way it manages your other APIs, so you don't need to run or maintain your own MCP servers. MCP support is an optional feature that is not enabled by default. You must explicitly enable it in your Apigee hybrid configuration. For more information, see Model Context Protocol (MCP) overview , Enable MCP for Apigee hybrid , an
- Apigee hybrid Root CA certificate rotation
Root CA certificate rotation Apigee hybrid v1.17.0 lets you rotate the root certificate authority (CA) certificate that anchors trust for TLS communication between your runtime components. You can now replace the root CA before it expires, without downtime. For more information, see Rotate the root CA .
- Apigee hybrid TLS 1.3 support
TLS 1.3 support Apigee hybrid v1.17.0 adds support for TLS 1.3, a newer version of the Transport Layer Security (TLS) protocol that offers faster connection handshakes and stronger security than earlier TLS versions. For information about configuring TLS on the ingress gateway, see Configuring TLS and mTLS on the Apigee ingress gateway .
- Apigee hybrid Forward proxy support for AI policies
Forward proxy support for AI policies Apigee hybrid v1.17.0 adds forward proxy support for AI policies, such as the Model Armor and semantic caching policies. Outbound calls from these policies can now be routed through an HTTP forward proxy. For more information, see Configure a forward proxy , Get started with the Model Armor policies , and Get started with semantic caching policies .
- Apigee hybrid Semantic cache Private Service Connect (PSC) endpoint support
Semantic cache Private Service Connect (PSC) endpoint support Apigee hybrid v1.17.0 adds Private Service Connect (PSC) endpoint support for semantic caching. The semantic caching policies can now reach their backing services over a Private Service Connect endpoint, which keeps that traffic on your private network. For more information, see Configure semantic caching over Private Service Connect .
- Apigee hybrid Semantic cache distance measure support
Semantic cache distance measure support Apigee hybrid v1.17.0 adds support for non-default Vertex AI Vector Search distance measures in the SemanticCacheLookup policy. A new optional <DistanceMeasureType> element accepts DOT_PRODUCT_DISTANCE (the default, and the existing behavior), COSINE_DISTANCE , SQUARED_L2_DISTANCE , and L1_DISTANCE . The policy compares <Threshold> in the direction the declared measure implies, so declaring a non-default measure requires re-tuning the threshold in the same edit. For more information, see SemanticCacheLookup policy .
- Apigee hybrid Reduced service account permissions
Reduced service account permissions Apigee hybrid v1.17.0 reduces the Google Cloud IAM permissions that Apigee service accounts require. Service accounts that use Cloud Storage now require only the storage.objects.get and storage.objects.create permissions rather than the broader Storage Admin ( roles/storage.admin ) role. The Cassandra components also no longer run with the privileged: true security context. For more information about service accounts, see Create service accounts .
Notes (1) ›
- Apigee hybrid hybrid v1.17.0
On September 14, 2026 we released an updated version of the Apigee hybrid software, 1.17.0. For information on upgrading, see Upgrading Apigee hybrid to version v1.17 . For information on new installations, see The big picture . Note: This is a minor release: The container images used in minor releases are integrated with the Apigee hybrid Helm charts. Upgrading to a minor via the Helm chart automatically updates the images. No manual image changes are typically needed. For information on container image support in Apigee hybrid releases, see Apigee release process .
https://docs.cloud.google.com/release-notes#September_14_2026
Related releases
- Google Cloud Recognized as a Leader in Forrester Wave™: Public Cloud Platforms Q3 2026 Google Cloud Blog ·
- Cloud Storage Intelligence advisor is now Generally Available Google Cloud release notes ·
- Cloud SDK 584.0.0: Breaking Changes, Deprecations, and Security Update Google Cloud release notes ·
- Config Connector 1.156.0 Adds Alpha Resources for AI, Security, and Storage Google Cloud release notes ·
- Google Cloud Introduces Data Agent Kit for Agentic Data Analysis in IDEs Google Cloud Blog ·
- GCP Managed Service for Apache Spark: New Images, Features, and Breaking Changes Google Cloud release notes ·