kongctl Release Highlights
⚠️ Breaking Changes
- AI Gateway child dump selectors removed — Direct selectors like
--resources=ai_gateway_modelsare no longer accepted indump declarative. Use--resources=ai_gateways --include-child-resourcesinstead. (#1908)
✨ What's New
-
Write-only secret management — A new
!secretYAML tag lets you declare sensitive values (API keys, client secrets, tokens) in declarative configs without ever storing the resolved value in plans or state. Secrets can be sourced from environment variables and composed inline (e.g.Bearer+!env TOKEN). New--write-secretand--write-secretsflags give precise control over which fields and resources receive secret writes duringplanandapply. Supported across Portal IDPs, DCR providers, AI Gateway providers, identity providers, vaults, Event Gateway schema registries, and AI Consumer Credentials. (#1826)client_secret: !secret {source: !env PORTAL_OIDC_CLIENT_SECRET}
kongctl plan --mode apply -f konnect.yaml \ --write-secret "workforce-idp#config.client_secret" \ --output-file rotation.json kongctl apply --plan rotation.json --auto-approve
🐛 Fixes & Improvements
- Bare declarative delete now validates sources — Running
kongctl deletewithout specifying source files now produces a clear validation error instead of silently proceeding. (#1930) - Listener policies on external gateways — Policies attached to listeners under external event gateways are now correctly planned and executed. (#1921)
- Protection label updates no longer silently dropped — Protection-only updates (e.g. toggling
kongctl.protected) are now reliably applied across all resource types, fixing cases where the update could produce an empty API request. (#1916, #1913) - External portal page lifecycle — Update and delete operations for pages on external portals now correctly carry the resolved portal ID. (#1910)
- Security dependency update —
golang.org/x/modupdated to v0.40.0 to address a security advisory. (#1885)
📚 Docs & DX
- OpenAI AI Gateway quickstart — A new end-to-end tutorial walks through declaratively creating an AI Gateway, provider, model, and data plane certificate for routing to OpenAI, with a local Docker helper for testing. (#1886)
- Secrets workflow examples — Complete
docs/examples/declarative/secretsworkflows covering creates, rotations, saved plans, composed values, and aggregate writes. (#1826)
🔗 Commit References
Features
Fixes
3fcba95fix(cmd): validate sources for bare declarative delete (#1930)d5c5b80fix(declarative): support listener policies on external gateways (#1921)349f001fix(declarative): centralize managed protection label updates (#1916)efe3709fix(declarative): apply DCR provider unprotection updates (#1913)c6a65cffix(declarative): support external portal page lifecycle (#1910)9e78b3efix(declarative): remove AI Gateway child dump selectors (#1908)98c75e7fix(ci): preserve local Muthur action for post steps (#1923)d0ccbe7fix(deps): update dependency astro to v7.2.0 (#1903)d2d438cfix(deps): update module github.com/kong/kongctl to v1.12.0 (#1874)bfdf32efix(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 (#1884)9fbdc35fix(deps): update module github.com/stretchr/testify to v1.12.0 (#1897)
Other Changes
94c620dtask(sdk): update sdk-konnect-go to v0.62 patch (#1942)e4f62d4task(sdk): update sdk-konnect-go to v0.61 patch (#1938)d4f0d0atask(ci): adopt unified ksai workflow (#1936)9c0fa1ftask(ci): upgrade gh-aw workflows (#1937)89acda2task(ci): add federated Claude comment reviews (#1922)90fc185refactor(declarative): standardize planner payload contracts (#1924)29e3c82refactor(simplify): simplify declarative executor and planner code (#1929)4df0186refactor(simplify): dedupe team pagination and field-path traversal (#1892)d335489refactor(simplify): tidy alias helpers in extensions cobra (#1891)d3fe04arefactor(simplify): tidy service fast-paths and team error labels (#1909)7173c1erefactor(simplify): simplify external lookup and team detail (#1880)f3d0ae1refactor(simplify): tidy host-flag helpers in extensions cobra (#1872)c3a7bffchore(deps): update zgosalvez/github-actions-ensure-sha-pinned-actions action to v5.0.7 (#1928)be4680cchore(deps): update step-security/harden-runner action to v2.20.1 (#1896)2d09230chore(deps): update github/gh-aw-actions action to v0.87.0 (#1889)577ee73chore(deps): update node.js to v24.19.0 (#1888)1711172chore(deps): update module golang.org/x/mod to v0.40.0 [security] (#1885)58e4b89chore(deps): update zgosalvez/github-actions-ensure-sha-pinned-actions action to v5.0.6 (#1877)aaaf637test(e2e): cover namespace flag mutual exclusion (#1931)e0cbb7atest(e2e): cover event gateway control plane round trips (#1920)c6299b6test(e2e): verify user roles after sync (#1917)a166fbdtest(e2e): cover portal team diff updates (#1915)eb9153ftest(e2e): verify org assignment dump round trips (#1914)791693dtest(e2e): expand portal email dump and idempotency coverage (#1912)81ce981test(e2e): cover portal visibility dump round trip (#1911)662d207test(e2e): cover backend cluster sasl scram authentication (#1899)f568921test(e2e): expand event gateway dump backend assertions (#1904)af461c7test(e2e): add catalog service plan idempotency coverage (#1898)4458698test(e2e): add nested API dump round-trip coverage (#1879)b422f31test(e2e): verify control-plane group apply lifecycle (#1878)
Full Changelog: v1.12.0...v1.13.0> Generated by Release · opus46 · 145.1 AIC · ⌖ 30.4 AIC · ⊞ 4.4K