Loading...
No results found.

Apply your skills in Google Cloud console

05

API Development on Google Cloud's Apigee API Platform

Get access to 700+ labs and courses

Apigee Lab 9: Using Shared Flows

Lab 1 hour 30 minutes universal_currency_alt 5 Credits show_chart Introductory
info This lab may incorporate AI tools to support your learning.
Get access to 700+ labs and courses

Overview

Shared flows can be used to encapsulate common tasks so they can be easily shared between proxies.

In this lab, you create a shared flow that adds the required Authorization header to a target request, and then call it from your retail proxy.

Objectives

In this lab, you learn how to perform the following tasks:

  • Create a shared flow.
  • Call a shared flow from a proxy.

Setup and requirements

For each lab, you get a new Google Cloud project and set of resources for a fixed time at no cost.

  1. Sign in to Qwiklabs using an incognito window.

  2. Note the lab's access time (for example, 1:15:00), and make sure you can finish within that time.
    There is no pause feature. You can restart if needed, but you have to start at the beginning.

  3. When ready, click Start lab.

  4. Note your lab credentials (Username and Password). You will use them to sign in to the Google Cloud Console.

  5. Click Open Google Console.

  6. Click Use another account and copy/paste credentials for this lab into the prompts.
    If you use other credentials, you'll receive errors or incur charges.

  7. Accept the terms and skip the recovery resource page.

Activate Google Cloud Shell

Google Cloud Shell is a virtual machine that is loaded with development tools. It offers a persistent 5GB home directory and runs on the Google Cloud.

Google Cloud Shell provides command-line access to your Google Cloud resources.

  1. In Cloud console, on the top right toolbar, click the Open Cloud Shell button.

  2. Click Continue.

It takes a few moments to provision and connect to the environment. When you are connected, you are already authenticated, and the project is set to your PROJECT_ID. For example:

gcloud is the command-line tool for Google Cloud. It comes pre-installed on Cloud Shell and supports tab-completion.

  • You can list the active account name with this command:
gcloud auth list

Output:

Credentialed accounts: - @.com (active)

Example output:

Credentialed accounts: - google1623327_student@qwiklabs.net
  • You can list the project ID with this command:
gcloud config list project

Output:

[core] project =

Example output:

[core] project = qwiklabs-gcp-44776a13dea667a6 Note: Full documentation of gcloud is available in the gcloud CLI overview guide .

Preloaded assets

These assets have already been added to the Apigee organization:

  • The retail-v1 API proxy
  • The oauth-v1 API proxy (for generating OAuth tokens)
  • The TS-Retail target server in the eval environment (used by retail-v1)

These assets will be added to the Apigee organization as soon as the runtime is available:

  • The API products, developer, and developer app (used by retail-v1)
  • The ProductsKVM key value map in the eval environment (currently used by retail-v1, and will be used by the shared flow that is created during this lab)
  • The ProductsKVM key value map will be populated with backendId and backendSecret

The highlighted items are used during this lab.

Note: Revision 1 of the retail-v1 proxy is marked as deployed, and is immutable. If you ever make a mistake in your proxy code that you can't recover from, you can select revision 1 and restart editing from there.

Task 1. Create a new shared flow to build a basic auth header

In this task, you create a new shared flow that is used to build a basic auth header for calling your backend service.

Pin the Apigee console page

  1. In the Google Cloud console, on the Navigation menu (), look for Apigee in the Pinned Products section.

    The Apigee console page will open.

  2. If Apigee is not pinned, search for Apigee in the top search bar and navigate to the Apigee service.

  3. Hover over the name, then click the pin icon ().

    The Apigee console page will now be pinned to the Navigation menu.

Create the shared flow

  1. On the left navigation menu, select Proxy development > Shared flows.
  2. Click +Create.
  3. For Name, enter backend-credentials.
  4. Click Create.

Add the policies

The shared flow will be used to create the basic auth header created in the updateProductById flow of the retail-v1 proxy:

The policies will be identical to those used in the retail-v1 proxy.

  1. In the shared flow, click the Develop tab.

  2. Click Shared flows > default.

    You will add the key value map policy.

  3. On the default flow, click Add Policy Step (+).

  4. In the Add policy step pane, select Create new policy, and then select Mediation > Key Value Map Operations.

  5. Specify the following values:

    Property Value
    Name KVM-GetCredentials
    Display name KVM-GetCredentials
  6. Click Add.

  7. Click on Policies > KVM-GetCredentials.

  8. Set the policy configuration to:

    <KeyValueMapOperations continueOnError="false" enabled="true" name="KVM-GetCredentials"> <MapName>ProductsKVM</MapName> <ExpiryTimeInSecs>60</ExpiryTimeInSecs> <Get assignTo="private.backendId"> <Key> <Parameter>backendId</Parameter> </Key> </Get> <Get assignTo="private.backendSecret"> <Key> <Parameter>backendSecret</Parameter> </Key> </Get> <Scope>environment</Scope> </KeyValueMapOperations>

    This policy configuration is identical to the configuration of the KVM policy in the retail-v1 proxy.

  9. Click Shared flows > default.

    Now you will add the basic authentication policy.

  10. On the default flow, click Add Policy Step (+).

  11. In the Add policy step pane, select Create new policy, and then select Security > Basic Authentication.

  12. Specify the following values:

    Property Value
    Name BA-AddAuthHeader
    Display name BA-AddAuthHeader
  13. Click Add.

  14. Click on Policies > BA-AddAuthHeader.

  15. Set the policy configuration to:

    <BasicAuthentication continueOnError="false" enabled="true" name="BA-AddAuthHeader"> <Operation>Encode</Operation> <IgnoreUnresolvedVariables>false</IgnoreUnresolvedVariables> <User ref="private.backendId"/> <Password ref="private.backendSecret"/> <AssignTo createNew="false">request.header.Authorization</AssignTo> </BasicAuthentication>
  16. Click Shared flows > default.

    Your shared flow should look like this:

  17. Click Save to save the shared flow.

  18. Click Deploy.

    A shared flow cannot be tested without including it in an API proxy, and it must be deployed to an environment before a proxy calling it can be deployed to that environment.

  19. To specify that you want the new revision deployed to the eval environment, select eval as the Environment, and then click Deploy.

  20. Click Confirm.

Task 2. Replace the policies in retail-v1 with a flow callout policy

In this task, you change your retail-v1 proxy to call the shared flow, replacing the KVM and BasicAuthentication policies with a FlowCallout policy.

  1. On the left navigation menu, click Proxy development > API proxies.

  2. Select the retail-v1 proxy.

  3. Click the Develop tab.

    You are modifying the version of the retail-v1 proxy that was created during Labs 1 through 8.

Detach the existing policies

  1. Click Proxy endpoints > default > updateProductById.

  2. To detach the KVM-GetCredentials and BA-AddAuthHeader policies, for each policy, click Policy step actions (), and then click Delete policy step.

Add the flow callout policy

  1. In the updateProductById request flow, click Add Policy Step (+).

  2. In the Add policy step pane, select Create new policy, and then select Extension > Flow Callout.

  3. Specify the following values:

    Property Value
    Name FC-BackendCredentials
    Display name FC-BackendCredentials
    Sharedflow select backend-credentials
  4. Click Add.

    The policy configuration simply specifies the shared flow to call in the SharedFlowBundle element. The policy configuration does not need to be changed.

  5. Click Save, and then click Save as New Revision.

  6. Click Deploy.

  7. To specify that you want the new revision deployed to the eval environment, click Deploy.

  8. Click Confirm.

Check deployment status

A proxy that is deployed and ready to take traffic will show a green status on the Overview tab.

When a proxy is marked as deployed but the runtime is not yet available and the environment is not yet attached, you may see a red warning sign. Hold the pointer over the Status icon to see the current status.

If the proxy is deployed and shows as green, your proxy is ready for API traffic. If your proxy is not deployed because there are no runtime pods, you can check the provisioning status.

Check provisioning status

  • In Cloud Shell, to confirm that the runtime instance has been installed and the eval environment has been attached, run the following commands:

    export PROJECT_ID=$(gcloud config list --format 'value(core.project)'); echo "PROJECT_ID=${PROJECT_ID}"; export INSTANCE_NAME=eval-instance; export ENV_NAME=eval; export PREV_INSTANCE_STATE=; echo "waiting for runtime instance ${INSTANCE_NAME} to be active"; while : ; do export INSTANCE_STATE=$(curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" -X GET "https://apigee.googleapis.com/v1/organizations/${PROJECT_ID}/instances/${INSTANCE_NAME}" | jq "select(.state != null) | .state" --raw-output); [[ "${INSTANCE_STATE}" == "${PREV_INSTANCE_STATE}" ]] || (echo; echo "INSTANCE_STATE=${INSTANCE_STATE}"); export PREV_INSTANCE_STATE=${INSTANCE_STATE}; [[ "${INSTANCE_STATE}" != "ACTIVE" ]] || break; echo -n "."; sleep 5; done; echo; echo "instance created, waiting for environment ${ENV_NAME} to be attached to instance"; while : ; do export ATTACHMENT_DONE=$(curl -s -H "Authorization: Bearer $(gcloud auth print-access-token)" -X GET "https://apigee.googleapis.com/v1/organizations/${PROJECT_ID}/instances/${INSTANCE_NAME}/attachments" | jq "select(.attachments != null) | .attachments[] | select(.environment == \"${ENV_NAME}\") | .environment" --join-output); [[ "${ATTACHMENT_DONE}" != "${ENV_NAME}" ]] || break; echo -n "."; sleep 5; done; echo "***ORG IS READY TO USE***";

    When the script returns ORG IS READY TO USE, you can proceed to the next steps.

While you are waiting

Read:

Task 3. Test the retail API

In this task, you validate that the retail API and shared flow present the credentials to the backend service and the product overall rating is updated.

Test the API proxy using private DNS

The eval environment in the Apigee organization can be called using the hostname eval.example.com. The DNS entry for this hostname has been created within your project, and it resolves to the IP address of the Apigee runtime instance. This DNS entry has been created in a private zone, which means it is only visible on the internal network.

Cloud Shell does not reside on the internal network, so Cloud Shell commands cannot resolve this DNS entry. A virtual machine (VM) within your project can access the private zone DNS. A virtual machine named apigeex-test-vm was automatically created for this purpose. You can make API proxy calls from this machine.

The curl command will be used to send API requests to an API proxy. The -k option for curl tells it to skip verification of the TLS certificate. For this lab, the Apigee runtime uses a self-signed certificate. For a production environment, you should use certificates that have been created by a trusted certificate authority (CA).

  1. In Cloud Shell, open a new tab, and then open an SSH connection to your test VM:

    TEST_VM_ZONE=$(gcloud compute instances list --filter="name=('apigeex-test-vm')" --format "value(zone)") gcloud compute ssh apigeex-test-vm --zone=${TEST_VM_ZONE} --force-key-file-overwrite

    The first gcloud command retrieves the zone of the test VM, and the second opens the SSH connection to the VM.

  2. If asked to authorize, click Authorize.

    For each question asked in the Cloud Shell, click Enter or Return to specify the default input.

    Your logged in identity is the owner of the project, so SSH to this machine is allowed.

    Your Cloud Shell session is now running inside the VM.

Store the app's key in a shell variable

The API key may be retrieved directly from the app accessible on the Publish > Apps page. It can also be retrieved via Apigee API call.

  • In the Cloud Shell SSH session, run the following command:

    export PROJECT_ID=$(gcloud config list --format 'value(core.project)'); echo "PROJECT_ID=${PROJECT_ID}" export API_KEY=$(curl -q -s -H "Authorization: Bearer $(gcloud auth print-access-token)" -X GET "https://apigee.googleapis.com/v1/organizations/${PROJECT_ID}/developers/joe@example.com/apps/retail-app" | jq --raw-output '.credentials[0].consumerKey'); echo "export API_KEY=${API_KEY}" >> ~/.bashrc; echo "API_KEY=${API_KEY}"

    This command retrieves a Google Cloud access token for the logged-in user, sending it as a Bearer token to the Apigee API call. It retrieves the retail-app app details as a JSON response, which is parsed by jq to retrieve the app's key. That key is then put into the API_KEY environment variable, and the export command is concatenated onto the .bashrc file which runs automatically when starting a the SSH session.

    Note: If you run the command and it shows API_KEY=null, the runtime instance is probably not yet available.

Get the list of products

  1. Use this curl command to get a list of products:

    curl -k -H "apikey: ${API_KEY}" -X GET "https://eval.example.com/retail/v1/products" | jq

    The response should be a JSON list of products that resembles this:

    { "00621094000P" : { "category" : "Fitness", "image" : "https://cdn.pixabay.com/photo/2016/04/01/09/30/boy-1299405_1280.png", "name" : "00621094000P", "overall_rating" : 0.2, "product_name" : "AFG 7.1AT Treadmill", "short_description" : "The right treadmill makes a difference, especially for highly active fitness enthusiasts. That's why the AFG 7.1AT treadmill has a highly durable, non-folding frame that's designed to last a lifetime. Built with heavy gauge steel, it delivers a club-like workout experience that won’t shift or creak during the most intense exercise sessions. The commercial-grade 3.25 horsepower continuous-duty motor offers a smooth and silent ride, no matter your pace. This ultra-quiet drive system also features a 15% power incline that delivers more workout options to help you reach every fitness goal faster, distraction- and worry-free." }, "00624932000P" : { "category" : "Fitness", "image" : "https://cdn.pixabay.com/photo/2016/04/01/09/30/boy-1299405_1280.png", "name" : "00624932000P", "overall_rating" : 4.3, "product_name" : "NordicTrack Elite 3700 Treadmill", "short_description" : "Amp it Up with the NordicTrack Elite 3700 Interactive Treadmill. Equipped with the best fitness technology available and banning the boredom of working out, the NordicTrack elite 3700 interactive treadmill puts your goals well within reach. The Intermix Acoustics™ Sound System on the treadmill features two high quality three-inch speakers for amazing sound, delivering the inspiration to press “start” and the motivation to keep moving. Plug in your iPod, ditch your ear buds and turn up the volume for a fun way to workout." },

    The top-level keys are the IDs (00621094000P and 00624932000P are shown here). Choose any one of the IDs in the entire list.

  2. Create an environment variable, replacing REPLACE with the chosen ID:

    export PRODUCT_ID=REPLACE
  3. Look at the current overall_rating for the product, and choose a different positive decimal number. For example, 2.1 is the overall_rating for product 31001 shown above. You could change the rating to 4.5. Create an environment variable, replacing REPLACE with the chosen rating:

    export NEW_RATING=REPLACE
  4. Use this command to update the overall_rating, and then retrieve the product to make sure that the overall_rating has changed:

    curl -k -H "apikey: ${API_KEY}" -X PATCH "https://eval.example.com/retail/v1/products/${PRODUCT_ID}" -H "Content-Type: application/json" -d "{ \"overall_rating\": ${NEW_RATING} }" | jq curl -k -H "apikey: ${API_KEY}" -X GET "https://eval.example.com/retail/v1/products/${PRODUCT_ID}" | jq

    The first curl command will return the same overall_rating that you used to update it. The second curl command will return the entire product, including the updated overall_rating.

    The shared flow has the same functionality in the API proxy.

Congratulations!

In this lab, you moved some common functionality from your proxy into a shared flow and called it using a FlowCallout policy.

End your lab

When you have completed your lab, click End Lab. Google Cloud Skills Boost removes the resources you’ve used and cleans the account for you.

You will be given an opportunity to rate the lab experience. Select the applicable number of stars, type a comment, and then click Submit.

The number of stars indicates the following:

  • 1 star = Very dissatisfied
  • 2 stars = Dissatisfied
  • 3 stars = Neutral
  • 4 stars = Satisfied
  • 5 stars = Very satisfied

You can close the dialog box if you don't want to provide feedback.

For feedback, suggestions, or corrections, please use the Support tab.

Copyright 2024 Google LLC All rights reserved. Google and the Google logo are trademarks of Google LLC. All other company and product names may be trademarks of the respective companies with which they are associated.

Previous Next

Before you begin

  1. Labs create a Google Cloud project and resources for a fixed time
  2. Labs have a time limit and no pause feature. If you end the lab, you'll have to restart from the beginning.
  3. On the top left of your screen, click Start lab to begin

This content is not currently available

We will notify you via email when it becomes available

Great!

We will contact you via email if it becomes available

One lab at a time

Confirm to end all existing labs and start this one

Use private browsing to run the lab

Use an Incognito or private browser window to run this lab. This prevents any conflicts between your personal account and the Student account, which may cause extra charges incurred to your personal account.
Preview