Service Extensions lets supported Application Load Balancers send Cloud Load Balancing callouts from the data processing path to supported Google services. This page describes such integrations.
For information about other types of callouts, see Callouts to user-managed services.
Integration with Model Armor
Model Armor enhances the security of AI applications by enforcing runtime controls on LLM prompts and responses. This mitigates critical risks, including prompt injection attacks, the generation of harmful content, and the potential loss of sensitive data.
You can configure a traffic extension to call the Model Armor Google service to uniformly apply and enforce security policies to screen LLM prompts and responses for your networking applications.
See how this integration works.
Integration with Agent Gateway
Agent Gateway provides centralized networking and governance for AI agent communication. You can use Agent Gateway to enforce access controls and security policies on the traffic between agents and tools, such as third-party Model Context Protocol (MCP) servers.
Agent Gateway supports Service Extensions to evaluate requests and delegate authorization decisions to Google services—such as Identity-Aware Proxy and Model Armor—or custom authorization services. Authorization extensions let you inspect, modify, or block agent traffic in real time before the traffic reaches its destination.
For more information, see Delegate authorization with Service Extensions.
Supported Application Load Balancers for callouts to Google services
Service Extensions supports traffic extensions by using callouts to selected Google services for the following Application Load Balancers:
| Application Load Balancers | Model Armor (traffic extensions by using callouts) |
|---|---|
| Global external Application Load Balancer | |
| Regional external Application Load Balancer | |
| Regional internal Application Load Balancer | |
| Cross-region internal Application Load Balancer | |
| Classic Application Load Balancer |