kongctl Release Highlights
v0.10.0 brings a significant batch of new declarative resource support,
important bug fixes for auth and output handling, and a new extensions system.
✨ What's New
kongctl Extensions (#840)
A new extensions system lets you add custom behaviors and integrations to
kongctl workflows.
Control Plane Data Plane Certificate Resources
(#938)
Manage data plane certificates for control planes declaratively.
Developer Portal Integrations
(#966)
Full declarative lifecycle support for portal integration resources.
Portal IP Allow List
(#993)
Declaratively manage IP allow lists for your developer portals.
Audit Log Destinations _external Resource
(#969)
Root-level audit-logs.destinations _external resource type is now
supported in declarative configuration.
🐛 Fixes & Improvements
- Token refresh: Konnect access tokens are now refreshed per-request,
preventing auth failures on long-running workflows
(#989) - Masked deck env vars: Fixed handling of masked environment variable JSON
output from deck (#991) - Env tags in dynamic maps:
$envtags are now properly resolved inside
dynamic declarative maps (#986) - Portal app auth strategy refs: Reference resolution for portal
application auth strategies is now correct
(#960) apisub-command output: Default JSON output and text config handling
fixed forapisub-commands (#955)- Gateway core entity commands:
getandlistcommands for gateway core
entities are now correctly nested under the control plane parent command
(#939) - Virtual cluster destination refs: Fixed ref resolution for virtual
cluster destinations (#970) - Security: Added URL validation for login and auth flows
(#908); CI workflow hardening
(#916)
📚 Docs & DX
- Added security notice document
(#927) - Improved kongctl declarative skill guidance for AI coding assistants
(#994) - Expanded E2E test coverage:
allresources scenario, portal integrations,
serverless control planes, gateway routes/consumers, and more
🔗 Commit References
Features
966488dFeat: add portal IP allow list resource support (#993)4301b10Feat: kongctl extensions (#840)3d5202dFeat: add root levelaudit-logs.destinations_externalresource support (#969)b5a074aFeat: add developer portal integrations resource support (#966)e69b64cFeat: add control plane data plane certificate resource support (#938)
Fixes
55f9586fix(deps): update module github.com/kong/sdk-konnect-go to v0.33.0 (#976)ea95569Fix: handle masked deck env JSON output (#991)f83c6a0Fix: refresh Konnect access tokens per request (#989)5962032fix: virtual cluster destination ref resolution (#970)5881388Fix: Allow env tags in dynamic declarative maps (#986)a187a13Fix: publish kongctl Pulse without pushing to main (#982)3498e90Fix: allow approved external issue triage (#978)42754f6fix(deps): update module github.com/kong/sdk-konnect-go to v0.32.1 (#957)de3ef38Fix: properly resolve portal app auth strategy refs (#960)593232bFix: api sub-command default json output and ignore text config (#955)400c079Fix: move gateway core entities get & list commands under control plane parent command (#939)65b0d0cfix(deps): update module github.com/daveshanley/vacuum to v0.26.1 (#931)ed0b90dfix(deps): update module github.com/kong/sdk-konnect-go to v0.32.0 (#928)848ee3dfix(deps): update module github.com/daveshanley/vacuum to v0.26.0 (#929)8feb8a9fix(deps): update module charm.land/bubbletea/v2 to v2.0.6 (#921)c8c0422fix(deps): update module github.com/kong/sdk-konnect-go to v0.31.1 (#917)
Other Changes
afd94d0Task: Improve kongctl declarative skill guidance (#994)2b5ae16test: Add E2E coverage forget portal email-domainslist command (#992)a6acce6docs: add security notice document (#927)2f743cdtest: Add dedicated E2E lifecycle scenario forportal_integrationresources (#979)9ab80eeTask: allow maintainer-triggered triage of public issues (#987)aa5069fTask: allow repo metadata in issue triage workflow (#985)3a85800Task: Trigger issue triage from approval label (#984)21a4f35chore(deps): update actions/configure-pages action to v6 (#981)2bdb00fTask: Add kongctl Pulse reporting (#980)dbe35c2Simplify: audit-log destination validation and portal webhook ID resolution paths (#977)09622c4Task: add benchmark regression analyzer and improve reporting (#968)a02a07esimplify: deduplicate resolved-ref synchronization and unresolved-ref errors (#964)9382bb3Test: Addallresources e2e scenario (#961)9a0a6fdchore(deps): update step-security/harden-runner action to v2.19.0 (#958)bb6f4c0Test: add serverless control v1 plane e2e coverage (#959)f04e95aTest: cover portal custom domain replanning (#956)cafc1c6test(e2e): add e2e scenario steps for get gateway control-plane routes and consumers (#953)5cc99fdSimplify: deduplicate gateway flag helpers across verb packages (#950)d610c45test: add e2e scenario for control-plane protected-resource lifecycle (#946)aec36c3simplify: remove duplicate helper, dead code, and redundant comments in data plane certificate planners (#943)24e5f5eTask: updates gh-aw and agentic workflows (#932)54e9b8ee2e: cover single API document lookup (#930)aba18actest(e2e): add single-version lookup coverage forget api versions(#924)0d863a7test: add e2e lifecycle coverage for consume-policy skip_record and schema_validation variants (#920)f4d6c23chore(deps): update github/gh-aw-actions action to v0.68.5 (#915)ffccd7dtest(e2e): add schema_validation produce policy lifecycle scenario (#919)cdd15easimplify: replace magic index access with strings.Join in validateProducePolicyTypeField (#918)bfa9c19Security: enhancements in ci workflows (#916)955e0aeSecurity: added url validation for login and auth flows (#908)
Full Changelog: v0.9.0...v0.10.0
Generated by Release · ● 230.8K