gRPC by the Numbers: 10 Years and Still Growing
gRPC turned 10 and the download numbers back it up. Maven Central records 7 million Java views per week. Python hits 304 million monthly downloads. npm logs 29 million weekly downloads. Netflix, Datadog, Broadcom, and LinkedIn are among active contributors. Google uses gRPC internally across GKE, containerd, and other Cloud projects. The team runs gRPC Conf annually, with 2025 events planned at a Bay Area venue and in Bangalore.
Three Pillars Driving the 2025 Roadmap
John Feig organized every new feature under three themes. Service mesh, where proxyless GA shipped in 2020 and new requests have not slowed since. Observability, where gRPC committed to OpenTelemetry and is still filling gaps. Modernization, covering both existing language improvements and new languages gaining popularity. Almost every feature announced at this talk ties back to service mesh, and several sit at the intersection of service mesh and observability.
Ext_proc, Ext_authz, and Serverless Service Mesh
Two new proxyless mesh plugins remove the need to recompile interceptors into every server. Ext_proc lets a separate gRPC server modify requests and responses. Ext_authz asks a preconfigured server whether a caller is authorized. Both use a callout model: deploy one server, point the mesh at it, and enforcement applies fleet-wide. On the serverless side, XDS host rewriting, JWT token authorization for outgoing RPCs, and MTLS-off via Spiffy identities together make Cloud Run-to-GKE mesh connections first class.
Spiffy Multi-Trust-Domain MTLS and New OpenTelemetry Metrics
gRPC has supported Spiffy-based MTLS via XDS since 2021, but only through CA files. The team is now adding Spiffy trust bundles. This lets dev, staging, and prod run separate roots of trust so staging cannot accidentally reach production. It also lets product areas within a company manage independent identities. C++, Go, and Java will ship this in 2025. On the metrics side, 12 new OpenTelemetry metrics cover weighted round-robin, pick-first, and the XDS client component, with cross-cutting locality labels that map roughly to a cloud zone.
Custom Backend Metrics and Weighted Round-Robin Load Balancing
Custom backend metrics are in production now. Servers attach CPU utilization, QPS, and EPS either as trailing metadata when an RPC finishes or periodically out of band. Weighted round-robin load balancing reads those metrics to pick backends. Configuring it in Go means setting the load balancing config to WRR in JSON at dial time and toggling enable_oo_load_report to true for out-of-band reporting. The developer guide at the linked short URL includes working code samples in multiple languages.
MCP over gRPC and First-Class Rust Support
The Model Context Protocol’s JSON-RPC HTTP transport makes horizontally scaled deployments difficult. Google announced in August 2024 it would work with Anthropic to add a gRPC transport. An experimental fork of the MCP Python and JS SDKs is now being published. The team is contributing a pluggable transport API to Anthropic’s SDK so the gRPC transport ships as a separate package. Separately, Rust is joining C++, Java, and Go as a first-class gRPC language, built on the Tonic crate with full XDS support for proxyless mesh. A preview landed at gRPC Conf in August 2024.
Q&A
Is gRPC planning built-in replication support? The team has no active work on replication but asked the questioner to share specifics via the mailing list. ▶ 25:13
Can gRPC load balancing do topology-aware routing to reduce cross-zone traffic costs? Kevin confirmed load balancer policies get significant engineering time and invited the questioner to file a specific request. ▶ 26:15
Why does GKE not yet support GRPCRoute in Gateway API? John called it a prioritization issue and said the team is looking for a keystone customer willing to adopt early and provide feedback. ▶ 27:25
Notable Quotes
Maven Central um for Java 7 million views a week. So that’s a really really huge number. Uh 304 monthly downloads in Python and uh 29 million weekly downloads on MPM. Kevin Nilson · ▶ 1:31
In 2019, we decided to set out on the long journey of creating service mesh without sidecar proxies. We did our GA in 2020 and haven’t looked back since. John Feig · ▶ 8:57
If you’re a platform team, this is a dream come true. The power of gRPC interceptors will now be available to you to enforce across your entire system. John Feig · ▶ 10:44
A2A was built early from early on with gRPC support and the protocol is fully defined in terms of protobuff. John Feig · ▶ 20:43
no language is complete without first class gRPC support John Feig · ▶ 22:27
Key Takeaways
- gRPC proxyless service mesh GA’d in 2020 and ext_proc plus ext_authz extend it further without recompiling servers.
- Spiffy trust bundle support lands in C++, Go, and Java in 2025, enabling separate roots of trust per environment.
- MCP-over-gRPC is in experimental fork stage, with a pluggable transport API being contributed to Anthropic’s SDK.
About the Speaker(s)
Kevin Nilson is a Software Engineering Manager on the gRPC team at Google, previously working on Chromecast, Google Home, and Stadia. He is a Java Champion and four-time JavaOne Rock Star, with past appearances at Google I/O and JavaOne.
John Feig manages the gRPC team at Google. In nearly a decade at Google he has worked on Smart Home, open health standards, and Wear OS before moving to gRPC. Before Google he was on the founding engineering team of a Y Combinator-backed startup.