Describe the Bug:
VertexAiSessionService._get_api_client() creates a new vertexai.Client on every session call (create_session, get_session, append_event, ...). Each client creates two ssl.SSLContexts via google.auth.transport.mtls.get_default_ssl_context() (_ensure_httpx_ssl_ctx and _ensure_websocket_ssl_ctx), and they are not freed. On Vertex AI Agent Engine, where a client certificate is available, memory grows about 7 MB per request until the instance is killed.
Steps to Reproduce:
- Deploy an ADK app to Agent Engine with
get_fast_api_app(session_service_uri="agentengine://<engine id>").
- Send a few hundred requests.
- Watch process RSS and live
ssl.SSLContext objects (gc.get_objects()).
Expected Behavior:
One API client is reused across session calls, and memory stays flat.
Observed Behavior:
About 9 live SSLContexts and about 7 MB of RSS are added per request, and none are released while idle. Grouped by creating stack, the largest groups (about 80% of the new contexts) all come from google/adk/sessions/vertex_ai_session_service.py:583 _get_api_client. Locally (no client certificate) it is smaller but still present: 12 session calls created 12 clients and left 3 extra live SSLContexts.
Environment Details:
- ADK Library Version: google-adk 2.10.0 (google-genai 2.25.0, google-cloud-aiplatform 1.165.1, google-auth 2.59.0)
- OS: Linux (Vertex AI Agent Engine)
- Python Version: 3.14
Model Information:
- Are you using LiteLLM: No
- Which model is being used: N/A (session service only)
Regression:
Possibly since google-genai 2.13.0 (googleapis/python-genai#2718), which made each client build an mTLS SSL context via get_default_ssl_context().
Minimal Reproduction Code:
import asyncio
import vertexai
from google.adk.sessions.vertex_ai_session_service import VertexAiSessionService
created = 0
_init = vertexai.Client.__init__
def counting_init(self, *args, **kwargs):
global created
created += 1
_init(self, *args, **kwargs)
vertexai.Client.__init__ = counting_init
async def main() -> None:
service = VertexAiSessionService(project="<project>", location="<location>", agent_engine_id="<engine id>")
session = await service.create_session(app_name="<engine id>", user_id="u1")
for _ in range(10):
await service.get_session(app_name="<engine id>", user_id="u1", session_id=session.id)
print("clients created:", created) # 11: one per call
asyncio.run(main())
Describe the Bug:
VertexAiSessionService._get_api_client()creates a newvertexai.Clienton every session call (create_session,get_session,append_event, ...). Each client creates twossl.SSLContexts viagoogle.auth.transport.mtls.get_default_ssl_context()(_ensure_httpx_ssl_ctxand_ensure_websocket_ssl_ctx), and they are not freed. On Vertex AI Agent Engine, where a client certificate is available, memory grows about 7 MB per request until the instance is killed.Steps to Reproduce:
get_fast_api_app(session_service_uri="agentengine://<engine id>").ssl.SSLContextobjects (gc.get_objects()).Expected Behavior:
One API client is reused across session calls, and memory stays flat.
Observed Behavior:
About 9 live
SSLContexts and about 7 MB of RSS are added per request, and none are released while idle. Grouped by creating stack, the largest groups (about 80% of the new contexts) all come fromgoogle/adk/sessions/vertex_ai_session_service.py:583 _get_api_client. Locally (no client certificate) it is smaller but still present: 12 session calls created 12 clients and left 3 extra liveSSLContexts.Environment Details:
Model Information:
Regression:
Possibly since google-genai 2.13.0 (googleapis/python-genai#2718), which made each client build an mTLS SSL context via
get_default_ssl_context().Minimal Reproduction Code: