Integration with Google services

Service Extensions lets supported Application Load Balancers send Cloud Load Balancing callouts from the data processing path to supported Google services. This page describes such integrations.

For information about other types of callouts, see Callouts to user-managed services.

Integration with Model Armor

Model Armor enhances the security of AI applications by enforcing runtime controls on LLM prompts and responses. This mitigates critical risks, including prompt injection attacks, the generation of harmful content, and the potential loss of sensitive data.

You can configure a traffic extension to call the Model Armor Google service to uniformly apply and enforce security policies to screen LLM prompts and responses for your networking applications.

See how this integration works.

Integration with Agent Gateway

Agent Gateway provides centralized networking and governance for AI agent communication. You can use Agent Gateway to enforce access controls and security policies on the traffic between agents and tools, such as third-party Model Context Protocol (MCP) servers.

Agent Gateway supports Service Extensions to evaluate requests and delegate authorization decisions to Google services—such as Identity-Aware Proxy and Model Armor—or custom authorization services. Authorization extensions let you inspect, modify, or block agent traffic in real time before the traffic reaches its destination.

For more information, see Delegate authorization with Service Extensions.

Supported Application Load Balancers for callouts to Google services

Service Extensions supports traffic extensions by using callouts to selected Google services for the following Application Load Balancers:

Application Load Balancers Model Armor (traffic extensions by using callouts)
Global external Application Load Balancer
Regional external Application Load Balancer
Regional internal Application Load Balancer
Cross-region internal Application Load Balancer
Classic Application Load Balancer

What's next