github Kong/kongctl v1.13.0

latest releases: v1.20.2, v1.20.1, v1.20.0...
one month ago

Kong logo Kong logo kongctl Release Highlights

⚠️ Breaking Changes

  • AI Gateway child dump selectors removed — Direct selectors like --resources=ai_gateway_models are no longer accepted in dump declarative. Use --resources=ai_gateways --include-child-resources instead. (#1908)

✨ What's New

  • Write-only secret management — A new !secret YAML tag lets you declare sensitive values (API keys, client secrets, tokens) in declarative configs without ever storing the resolved value in plans or state. Secrets can be sourced from environment variables and composed inline (e.g. Bearer + !env TOKEN). New --write-secret and --write-secrets flags give precise control over which fields and resources receive secret writes during plan and apply. Supported across Portal IDPs, DCR providers, AI Gateway providers, identity providers, vaults, Event Gateway schema registries, and AI Consumer Credentials. (#1826)

    client_secret: !secret {source: !env PORTAL_OIDC_CLIENT_SECRET}
    kongctl plan --mode apply -f konnect.yaml \
      --write-secret "workforce-idp#config.client_secret" \
      --output-file rotation.json
    kongctl apply --plan rotation.json --auto-approve

🐛 Fixes & Improvements

  • Bare declarative delete now validates sources — Running kongctl delete without specifying source files now produces a clear validation error instead of silently proceeding. (#1930)
  • Listener policies on external gateways — Policies attached to listeners under external event gateways are now correctly planned and executed. (#1921)
  • Protection label updates no longer silently dropped — Protection-only updates (e.g. toggling kongctl.protected) are now reliably applied across all resource types, fixing cases where the update could produce an empty API request. (#1916, #1913)
  • External portal page lifecycle — Update and delete operations for pages on external portals now correctly carry the resolved portal ID. (#1910)
  • Security dependency update — golang.org/x/mod updated to v0.40.0 to address a security advisory. (#1885)

📚 Docs & DX

  • OpenAI AI Gateway quickstart — A new end-to-end tutorial walks through declaratively creating an AI Gateway, provider, model, and data plane certificate for routing to OpenAI, with a local Docker helper for testing. (#1886)
  • Secrets workflow examples — Complete docs/examples/declarative/secrets workflows covering creates, rotations, saved plans, composed values, and aggregate writes. (#1826)

🔗 Commit References

Features

  • a33d30b feat(declarative): support explicit writes for write-only secrets (#1826)

Fixes

  • 3fcba95 fix(cmd): validate sources for bare declarative delete (#1930)
  • d5c5b80 fix(declarative): support listener policies on external gateways (#1921)
  • 349f001 fix(declarative): centralize managed protection label updates (#1916)
  • efe3709 fix(declarative): apply DCR provider unprotection updates (#1913)
  • c6a65cf fix(declarative): support external portal page lifecycle (#1910)
  • 9e78b3e fix(declarative): remove AI Gateway child dump selectors (#1908)
  • 98c75e7 fix(ci): preserve local Muthur action for post steps (#1923)
  • d0ccbe7 fix(deps): update dependency astro to v7.2.0 (#1903)
  • d2d438c fix(deps): update module github.com/kong/kongctl to v1.12.0 (#1874)
  • bfdf32e fix(deps): update module github.com/lucasb-eyer/go-colorful to v1.4.1 (#1884)
  • 9fbdc35 fix(deps): update module github.com/stretchr/testify to v1.12.0 (#1897)

Other Changes

  • 94c620d task(sdk): update sdk-konnect-go to v0.62 patch (#1942)
  • e4f62d4 task(sdk): update sdk-konnect-go to v0.61 patch (#1938)
  • d4f0d0a task(ci): adopt unified ksai workflow (#1936)
  • 9c0fa1f task(ci): upgrade gh-aw workflows (#1937)
  • 89acda2 task(ci): add federated Claude comment reviews (#1922)
  • 90fc185 refactor(declarative): standardize planner payload contracts (#1924)
  • 29e3c82 refactor(simplify): simplify declarative executor and planner code (#1929)
  • 4df0186 refactor(simplify): dedupe team pagination and field-path traversal (#1892)
  • d335489 refactor(simplify): tidy alias helpers in extensions cobra (#1891)
  • d3fe04a refactor(simplify): tidy service fast-paths and team error labels (#1909)
  • 7173c1e refactor(simplify): simplify external lookup and team detail (#1880)
  • f3d0ae1 refactor(simplify): tidy host-flag helpers in extensions cobra (#1872)
  • c3a7bff chore(deps): update zgosalvez/github-actions-ensure-sha-pinned-actions action to v5.0.7 (#1928)
  • be4680c chore(deps): update step-security/harden-runner action to v2.20.1 (#1896)
  • 2d09230 chore(deps): update github/gh-aw-actions action to v0.87.0 (#1889)
  • 577ee73 chore(deps): update node.js to v24.19.0 (#1888)
  • 1711172 chore(deps): update module golang.org/x/mod to v0.40.0 [security] (#1885)
  • 58e4b89 chore(deps): update zgosalvez/github-actions-ensure-sha-pinned-actions action to v5.0.6 (#1877)
  • aaaf637 test(e2e): cover namespace flag mutual exclusion (#1931)
  • e0cbb7a test(e2e): cover event gateway control plane round trips (#1920)
  • c6299b6 test(e2e): verify user roles after sync (#1917)
  • a166fbd test(e2e): cover portal team diff updates (#1915)
  • eb9153f test(e2e): verify org assignment dump round trips (#1914)
  • 791693d test(e2e): expand portal email dump and idempotency coverage (#1912)
  • 81ce981 test(e2e): cover portal visibility dump round trip (#1911)
  • 662d207 test(e2e): cover backend cluster sasl scram authentication (#1899)
  • f568921 test(e2e): expand event gateway dump backend assertions (#1904)
  • af461c7 test(e2e): add catalog service plan idempotency coverage (#1898)
  • 4458698 test(e2e): add nested API dump round-trip coverage (#1879)
  • b422f31 test(e2e): verify control-plane group apply lifecycle (#1878)

Full Changelog: v1.12.0...v1.13.0> Generated by Release · opus46 · 145.1 AIC · ⌖ 30.4 AIC · ⊞ 4.4K

Don't miss a new kongctl release

NewReleases is sending notifications on new releases.