One control plane.
Data planes anywhere.
AAM is hybrid by design: a managed control plane on Akamai Connected Cloud, and lightweight data planes that run wherever your APIs do. All-on-Akamai is the easy path — and mixed estates across AWS, Azure, GCP, or self-hosted data centers are absolutely possible through an AAM team engagement.
Hybrid by design
Most platforms make you choose between SaaS and self-hosted. AAM splits the product along the line that actually matters: management is centralized, traffic is not.
Control plane — where you manage everything
Managed service on Akamai Connected Cloud
One place to define routes, policies, auth, rate limits, monetization plans, and the developer portal. Every change is versioned and pushed to every data plane you run — no per-region configuration drift, no gateway fleet to patch.
Data planes — where your traffic runs
Lightweight gateway nodes, deployed per data center
Stateless nodes that enforce everything locally: authentication, rate limiting, transforms, routing. They run on any Akamai Connected Cloud region out of the box — and, where a deal calls for it, in AWS, Azure, GCP, or the customer's own Kubernetes next to the workloads they front.
The control plane never sits in the request path
It pushes configuration down and receives telemetry back. Requests are processed entirely inside the data plane's own region.
Data planes keep serving on their own
If a region loses its link to the control plane, traffic keeps flowing on the last-applied configuration. Changes queue and apply on reconnect.
Payloads stay where they're processed
Request and response bodies are handled in-region and don't leave the environment — the foundation for residency and sovereignty requirements.
One estate, many data centers
An example mixed estate: Akamai Connected Cloud regions carry the public traffic behind the Akamai edge, while satellite data planes on AWS and Azure and a self-hosted cluster cover east–west and private workloads — all governed by one control plane. Estates like this are fully supported; they're scoped case by case with the AAM team.
AAM Control Plane
Managed on Akamai Connected Cloud
North–south · behind Akamai edge (App & API Protector, CDN, GTM)
East–west · in-VPC
East–west · in-VNet
Private · behind your firewall
Built for both traffic directions
Mixed mode exists because real estates have two kinds of traffic — and the right place to run the gateway is different for each.
North–south: public and partner APIs
Best served from Akamai Connected Cloud
Internet-facing traffic belongs behind the Akamai edge. App & API Protector absorbs DDoS, bot, and web attacks before they reach the gateway; the CDN offloads cacheable responses; GTM routes every consumer to the nearest healthy region. Data planes on Connected Cloud sit on the same private backbone, so edge-to-gateway traffic never crosses the public internet.
- Attack traffic dies at the edge, not at your origin
- Cache offload and 20ms+ latency gains from edge routing
- Multi-region failover with no client changes
East–west: service-to-service traffic
Best served next to the workloads
Internal APIs — service meshes, partner integrations inside a VPC, data-layer calls — shouldn't hairpin through the public internet just to pass a gateway. Drop a data plane into the same VPC, VNet, or cluster and internal calls get the same auth, quotas, and audit trail as public traffic, with single-digit-millisecond overhead.
- No internet round-trip for internal calls
- Same keys, policies, and analytics as public APIs
- Works inside AWS, Azure, GCP, or on-prem networks
Most enterprises have both, and that's the case for one control plane: a single API catalog, one set of policies and consumers, and one analytics view across public and internal traffic — instead of one gateway product per network.
Deployment models
Every model uses the same managed control plane — the only variable is where the data planes run. All-on-Akamai is the standard offer; mixed estates are fully supported and start with an AAM team engagement.
All on Akamai
Control plane and every data plane on Akamai Connected Cloud. The full better-together story — edge security, CDN, GTM, TrafficPeak, and the gateway on one vendor and one private backbone — with standard packaging and nothing to special-approve. Price it in the calculator and go.
Good fit when
- Public and partner APIs are the main workload
- Consolidating edge + gateway spend onto one platform
- Global, multi-region delivery from day one
Mixed mode — supported through an AAM team engagement
Both shapes below are proven and fully supported. They're approved case by case and still anchor on Akamai Connected Cloud — so bring the AAM team in early in the deal.
Hybrid multi-cloud
Anchor regions on Akamai Connected Cloud for north–south traffic, plus satellite data planes in AWS, Azure, or GCP wherever workloads are pinned by data gravity or existing commitments.
Good fit when
- Workloads that can't move clouds yet
- East–west traffic between services inside a VPC
- A migration path that consolidates onto Akamai over time
Scoped with the AAM team · control plane stays Akamai-managed
Self-hosted data planes
Data planes in the customer's own data centers or private Kubernetes — one part of an estate that still anchors on Akamai Connected Cloud, managed by the same cloud control plane. Governance without giving up the network boundary.
Good fit when
- Residency or sovereignty rules that pin traffic on-prem
- Private networks where the data path can't leave the DC
- Existing data center investments that aren't going away
Scoped with the AAM team · control plane stays Akamai-managed
Same platform, every footprint
Mixed mode isn't a compromise tier. A data plane in a customer's own data center is the same software, enforcing the same policies, reporting into the same analytics as one on Akamai Connected Cloud.
Same policy engine
One policy set enforced identically on Linode, AWS, Azure, GCP, and on-prem.
One catalog & portal
Every API, wherever it runs, in a single catalog and developer portal.
Central auth & keys
Consumers and credentials are managed once and honored by every data plane.
Unified analytics
All traffic streams into one view — TrafficPeak included — regardless of footprint.
Zero-downtime rollout
Config changes version and propagate to every region with no restarts.
Local enforcement
Every decision — auth, quotas, routing — is made in-region at wire speed.
Hosting FAQ
The questions that come up in every hybrid, multi-cloud, or on-prem conversation — with the long answers.
Is AAM a SaaS product or self-hosted?
Both — that's the point of the hybrid architecture. The control plane is a managed service on Akamai Connected Cloud: always current, no servers to run, no upgrade projects. The data planes — the nodes that actually process API traffic — deploy wherever the customer needs them: Akamai regions, other clouds, or their own data centers. Customers get the operating model of SaaS with the placement control of self-hosted.
Can data planes run on AWS, Azure, or GCP?
Yes. AAM supports a mixed estate where different data centers run on different providers — some regions on Akamai Connected Cloud, some on AWS, some on GCP or Azure. The typical shape: Akamai regions anchor the public, north–south traffic behind the Akamai edge, while satellite data planes sit inside another cloud's VPC next to workloads that are pinned there by data gravity or existing commitments. All of them are managed by the same control plane, so policies, keys, and analytics stay unified. One thing to know: mixed estates aren't standard packaging — they're approved case by case, so the path runs through an AAM team engagement. All-on-Akamai needs no such step.
Can AAM run self-hosted or on-prem?
Data planes can, yes — in the customer's own Kubernetes clusters or data centers, behind their firewall, as one part of an estate that still anchors on Akamai Connected Cloud. The control plane stays managed in the cloud, pushing configuration in and pulling telemetry out; the actual request traffic never leaves the private network. That combination covers most "we need on-prem" requirements, which are almost always about where traffic and payloads flow, not where configuration is edited. Like any mixed estate, self-hosted data planes are approved case by case — and a deployment with no Akamai footprint at all is a different conversation entirely — so engage the AAM team early.
Does API traffic pass through the control plane?
No — and this is the question to answer when latency or sovereignty comes up. The control plane distributes configuration and aggregates telemetry; it is never in the request path. A request enters a data plane, is authenticated, rate-limited, transformed, and routed to the origin entirely within that region. There is no cross-region hop and no dependency on a central service per request.
What happens if a data plane can't reach the control plane?
It keeps serving. Data planes hold their full configuration locally, so auth, rate limits, and routing continue on the last-applied config even through an extended control plane outage or a severed network link. Configuration changes made in the meantime queue and apply when the link is restored. Uptime of the traffic path does not depend on uptime of the management path.
Where do request payloads and logs live?
Request and response bodies are processed inside the data plane's own environment and don't leave it as part of normal operation. Metadata and metrics stream to the analytics layer — including TrafficPeak — so teams get one estate-wide view. Full request logs can be shipped to the customer's own sink per region, which is how most regulated customers satisfy residency requirements while keeping unified observability.
How is a mixed estate priced?
The same way as an all-Akamai one: by environments/regions (each cluster the customer deploys counts as one) plus request volume. A data plane on AWS or on-prem is priced like a data plane on Linode — footprint doesn't change the model. The pricing calculator handles all of these shapes.
What has to be true for a deal to be sold as AAM?
An AAM deployment anchors on Akamai Connected Cloud: at least a portion of the estate runs on Linode — ideally all of it. All-on-Akamai is the standard offer and the easy path to close. Mixed estates with some data planes on other clouds or self-hosted are supported but not standard packaging: they're approved case by case through an AAM team engagement, so raise them early in the deal cycle. The practical pitch: start where the customer's workloads are today, land the north–south traffic on Akamai, and consolidate more of the estate onto Connected Cloud over time. See the pricing calculator FAQ for the current deal guidance.
Scoping a hybrid or self-hosted deal?
Mixed estates are approved case by case, so bring the deployment shape into the conversation early. Price the environments in the calculator, then get the AAM team on the call.