kongctl Release Highlights
This patch release fixes two declarative workflow defects in AI Gateway resource management and consolidates deletion ordering into a shared policy.
๐ Fixes & Improvements
MCP server renames no longer delete before creating replacements โ When a sync renamed an MCP server, the old server could be deleted before its replacement was created, breaking live routes. The planner now adds an explicit replacement-create dependency so saved plans order prerequisite creation โ replacement creation โ old server deletion โ unused auth/policy cleanup. Failed replacement creation blocks deletion of the old server. (#2359, fixes #2356)
Auth strategy renames no longer cause foreign-key errors โ Renaming an AI Gateway auth strategy during sync could delete the old strategy before its users (agents, models, MCP servers) detached, triggering a foreign-key error from the API. Deletion now waits for the relevant user updates or deletes to complete, and planning rejects deletion while retained or out-of-scope users still reference the strategy. Additionally, MCP servers now resolve auth-strategy references consistently with agents and models. (#2355, fixes #2354, #2338)
Shared observed-reference deletion ordering โ AI Gateway target deletion (providers, policies, custom policies, auth strategies) now uses a unified policy: every current user must be deleted or demonstrably detached before its target can be removed, and conflicting planned references reject the plan at planning time rather than failing at execution. (#2358, closes #2357)
๐ Commit References
Fixes
3432e37fix(declarative): create MCP replacements before deleting old servers (#2359)f27de77fix(declarative): handle AI Gateway auth strategy renames and references (#2355)6762841fix(deps): update module github.com/kong/kongctl to v1.20.0 (#2360)
Other Changes
Full Changelog: v1.20.0...v1.20.1> Generated by Release ยท opus46 ยท 63.7 AIC ยท โ 28.4 AIC ยท โ 4.4K