Skip to content

Latest commit

 

History

History
685 lines (478 loc) · 23.8 KB

File metadata and controls

685 lines (478 loc) · 23.8 KB

Changelog

3.22.0

Released 2026/08/26

Features

  • Add support for konnect_dcr_provider resource, using which you can manage Dynamic Client Registration (DCR) providers in Konnect. This allows you to configure DCR providers for use with OpenID Connect (OIDC) authentication strategies in Konnect.
  • Add support for cost-accounting fields (cache_read_cost, cache_write_cost, cache_write_cost_list, context_window_factor, service_tier_factor) in konnect_gateway_plugin_ai_proxy_advanced, konnect_gateway_plugin_ai_response_transformer and konnect_gateway_plugin_ai_llm_as_judge resources.
  • Add support for konnect_portal_identity_provider and konnect_portal_identity_provider_team_group_mapping resources, using which you can manage Developer Portal Identity Providers, as well as Identity Provider Group <> Portal Team mapping.

Bug Fixes

  • Fixed in-place update for konnect_application_auth_strategy resource.

3.21.0

Released 2026/08/04

Features

  • Add support for konnect_organization_personal_access_token_settings resource, using which you can control organization-wide personal access token (PAT) policies, such as enabling PATs and setting the maximum token expiration period.
  • Add support for konnect_portal_developer, konnect_portal_application and konnect_portal_application_registration resources, using which you can manage developer accounts in a portal, the applications owned by those developers, and the registration of those applications against APIs published to the portal.
  • Add support for konnect_identity_auth_server_client_secret resource, using which you can create and rotate client secrets for an identity auth server client.
  • Add support for konnect_user_role resource, using which you can assign a role to a user scoped to a specific entity (for example, granting the Viewer role on a control plane).

Bug Fixes

  • Deprecate konnect_portal_appearance resource.

3.20.0

Released 2026/07/06

Features

  • Add support for Kong Gateway v3.15 - including konnect_gateway_cloned_plugin resource.
  • Add support for konnect_portal_team_role resource
  • Add support for konnect_event_gateway_consume_policy_decrypt_fields and konnect_event_gateway_produce_policy_encrypt_fields resources

3.19.0

Released 2026/06/26

Features

  • Dynamic configuration of redis port is now supported in konnect_gateway_plugin_* and konnect_gateway_partial_* resources using a Vault reference

Bug Fixes

  • Fixed drift in access_logs_endpoint field for konnect_gateway_plugin_opentelemetry resource
  • Fix konnect_event_gateway_consume_policy_schema_validation to align with the schema in konnect_event_gateway_produce_policy_schema_validation

3.18.1

Released 2026/06/10

Bug Fixes

  • Fix using partials with plugins
  • Fix drift in konnect_gateway_plugin_openid_connect resource

3.18.0

Released 2026/06/02

Features

  • Add support for konnect_portal_ip_allow_list resource

3.17.0

Released 2026/05/19

Features

  • Add support for assigning roles on entity type name Auth Servers in konnect_system_account_role and konnect_team_role resources
  • Add support for title field, as well as update operation in konnect_gateway_data_plane_client_certificate resource

Bug Fixes

  • Fix drift in konnect_gateway_target resource
  • Fix drift in konnect_cloud_gateway_addon resource

3.16.0

Released 2026/05/12

Features

  • Add support for mapping Identity Provider groups with Konnect teams using konnect_identity_provider_team_group_mapping resource
  • Add support for updating konnect_portal_custom_domain.ssl field

3.15.0

Released 2026/05/05

Features

  • Add support for Add On Admin and Add On Viewer roles in konnect_team_role and konnect_system_account_role resources
  • Add support for larger capacity tiers (up to ~300 GiB capacity), as well as updating the capacity for managed_cache in konnect_cloud_gateway_addon resource
  • Add support for configuring portal audit log webhook using konnect_portal_audit_log_webhook resource

3.14.0

Released 2026/04/24

Features

  • Add support for new Gateway 3.14 plugins:
    • konnect_gateway_plugin_ai_a2a_proxy
    • konnect_gateway_plugin_ai_custom_guardrail
    • konnect_gateway_plugin_metering_and_billing
  • Add support for conditional plugin execution using condition field
  • Add support for konnect_identity_auth_server, konnect_identity_auth_server_scope, konnect_identity_auth_server_claim, konnect_identity_auth_server_client
  • Add konnect_cloud_gateway_network data source

3.13.0

Released 2026/04/07

Features

  • Add support for importing konnect_system_account_role and konnect_team_role

Bug Fixes

  • Fix drift in konnect_gateway_plugin_kafka_upstream and konnect_gateway_plugin_statsd resources

3.12.0

Released 2026/03/27

Features

  • Add support for client authentication on konnect_event_gateway_listener_policy_tls_server using konnect_event_gateway_tls_trust_bundle resource
  • Add support for provisioning custom domain for serverless gateway using konnect_cloud_gateway_custom_domain resource with kind = "serverless.v1"
  • Add support for "Debug Session Creator" role in konnect_team_role and konnect_system_account_role resources

3.11.0

Released 2026/03/12

Features

  • Add support for configuring Serverless Gateways
  • Add support for configuring Managed Cache in Cloud Gateway using konnect_cloud_gateway_addon resource

3.10.0

Released 2026/03/11

Features

  • Support new roles Registration Approver and Content Editor in konnect_team_role resource

Bug Fixes

  • Support free form objects with nested structure as JSON encoded strings in plugins
  • Fix a bug in konnect_gateway_plugin_key_auth resource where config.identity_realms was incorrectly configured when omitted in resource definition

3.9.0

Released 2026/02/20

Features

  • Add support for Azure Private DNS in konnect_cloud_gateway_private_dns resource

3.8.0

Released 2026/02/18

Features

  • Add support for gcp as provider in konnect_cloud_gateway_configuration resource
  • Add support for Azure Private Hosted Zone in konnect_cloud_gateway_private_dns resource
  • Add support for konnect_identity_provider and konnect_authentication_settings resources

Bug Fixes

  • Fix creating konnect_event_gateway_listener_policy_forward_to_virtual_cluster resource using sni routing
  • Fix unmarshalling errors seen while loading konnect_cloud_gateway_provider_account_list data source
  • Fix provisioning key-auth konnect_application_auth_strategy by treating configs.ttl as non-nullable

3.7.0

Released 2026/02/16

Features

  • Support linking APIs to Control Planes using konnect_api_implementation resource
  • Add support for Event Gateway resources.
    • konnect_event_gateway
    • konnect_event_gateway_backend_cluster
    • konnect_event_gateway_virtual_cluster
    • konnect_event_gateway_consume_policy_decrypt
    • konnect_event_gateway_static_key
    • konnect_event_gateway_consume_policy_modify_headers
    • konnect_event_gateway_consume_policy_schema_validation
    • konnect_event_gateway_consume_policy_skip_record
    • konnect_event_gateway_data_plane_certificate
    • konnect_event_gateway_listener
    • konnect_event_gateway_listener_policy_forward_to_virtual_cluster
    • konnect_event_gateway_listener_policy_tls_server
    • konnect_event_gateway_produce_policy_encrypt
    • konnect_event_gateway_produce_policy_modify_headers
    • konnect_event_gateway_produce_policy_schema_validation
    • konnect_event_gateway_cluster_policy_acls
    • konnect_event_gateway_schema_registry

3.6.0

Released 2026/01/30

Features

  • Early access support for Serverless in Cloud Gateways using cloud_gateway_configuration
  • Support for azure_private_dns_resolver in cloud_gateway_network
  • Add support for team, team_list, system_account and system_account_list data sources

Bug Fixes

  • Fix pagination in data sources
  • Treat max_rps as read only property to fix updates in konnect_cloud_gateway_configuration resource
  • Fix drift detection in konnect_portal_auth resource
  • Fix drift detection in konnect_cloud_gateway_configuration resource

3.5.0

Released on 2026/01/12

Features

  • Support PATCH update for certain properties in aws_transit_gateway and aws_resource_endpoint_gateway within konnect_cloud_gateway_transit_gateway resource without replacement
  • Add support for new Gateway 3.13 plugin konnect_gateway_plugin_ai_lakera_guard

3.4.3

Released on 2025/12/16

Bug Fixes

  • Properties related to IDP, SAML and OIDC are deprecated in konnect_portal_auth resource
  • Properties config.tools[*].headers.key and config.tools[*].query.key in konnect_gateway_plugin_ai_mcp_proxy resource now accept list of strings
  • Property config.limits.key in konnect_gateway_plugin_response_ratelimiting resource now accepts an object
  • Fix panic when dynamic ordering is used with custom plugin

3.4.2

Released on 2025/11/11

Bug Fixes

  • Support setting unstructured objects to null - for example config.callouts[*].request.custom in konnect_gateway_plugin_request_callout resource

3.4.1

Released on 2025/10/29

Bug Fixes

  • Support skip_ca_check in konnect_portal_custom_domain resource

3.4.0

Released on 2025/10/29

Features

  • Add support for new Gateway 3.12 plugins:
    • gateway_plugin_ace
    • gateway_plugin_ai_gcp_model_armor
    • gateway_plugin_ai_llm_as_judge
    • gateway_plugin_kafka_consume
    • gateway_plugin_ai_mcp_oauth2
    • gateway_plugin_ai_mcp_proxy
    • gateway_plugin_ai_semantic_response_guard
    • gateway_plugin_solace_consume
    • gateway_plugin_solace_log

Bug Fixes

  • Fix perpetual diff in konnect_gateway_plugin_request_callout and konnect_gateway_plugin_response_transformer
  • Fix unnecessary planned changes seen in child resources when parent was updated.

3.3.0

Released on 2025/10/14

Features

  • Added konnect_gateway_control_plane_list data source

3.2.1

Released on 2025/10/09

Bug Fixes

  • Properties such as theme, menu can now be unset in konnect_portal_customization resource
  • Fixed false diff on the output of terraform plan for konnect_system_account_access_token resource

3.2.0

Released on 2025/09/16

Features

  • Add support for aws_resource_endpoint_gateway in konnect_cloud_gateway_transit_gateway resource
  • Add support for GCP Private Hosted Zone in konnect_cloud_gateway_private_dns resource
  • Add konnect_platform_ip_addresses data source that makes https://ip-addresses.origin.konghq.com/ip-addresses.json accessible programatically

Bug Fixes

  • Fixed false diff on the output of terraform plan for konnect_cloud_gateway_configuration resource
  • Fixed false diff on the output of terraform plan for konnect_gateway_plugin_response_transformer_advanced, konnect_gateway_plugin_datadog and konnect_gateway_plugin_confluent resources
  • Fixed false diff on the output of terraform plan when a plugin uses partial without defining name and path in config

3.1.0

Released on 2025/09/02

Features

  • Add support for the konnect_gateway_config_store_secret resource

Bug Fixes

  • Fixed false diff on the output of terraform plan for konnect_api resource
  • Made instance_name optional on konnect_gateway_custom_plugin

3.0.0

Released on 2025/08/23

BREAKING CHANGES

  • konnect_portal resource on v2.x of terraform-provider-konnect no longer works with v3.x. Kindly import into konnect_portal_classic
  • konnect_control_plane_list data source has been removed. The konnect_control_plane data source is now available

Features

  • New resources konnect_portal, konnect_portal_logo, konnect_portal_favicon, konnect_portal_custom_domain, konnect_portal_snippet, konnect_portal_page, konnect_portal_customization for Portal are now supported
  • New data source konnect_portal is now supported
  • New resources konnect_api, konnect_api_version, konnect_api_implementation, konnect_api_document, konnect_api_specification, konnect_api_publication for API Builder are now supported
  • Add support for gcp_vpc_peering_transit_gateway in konnect_cloud_gateway_transit_gateway resource

Bug Fixes

  • Fields that are nullable can be set to null

2.14.0

Released on 2025/08/13

Features

  • Introduce new resources konnect_portal_classic into which konnect_portal can be imported
  • Introduce new data source konnect_portal_classic_list which is equivalent to konnect_portal_list

2.13.0

Released on 2025/08/12

Features

  • Add support for the konnect_cmek resource for Customer Managed Encryption Keys
  • Add support for the konnect_catalog_service, konnect_integration_instance, konnect_integration_instance_auth_config, konnect_integration_instance_auth_credential resources for Service Catalog
  • Allow the Dashboards entity when configuring roles

Bug fixes

  • namespace is no longer required in plugins
  • The konnect_gateway_plugin_oauth2 resource has been removed. Konnect does not support oauth2. See "Kong Identity" as an alternative for Konnect users.

2.12.0

Released on 2025/07/22

Features

  • Add support for new Gateway 3.11 plugins:
    • ai-aws-guardrails
    • ai-prompt-compressor
    • datakit
    • solace-upstream

2.11.1

Released on 2025/07/14

Bug fixes

  • Fixed error while running terraform apply for konnect_gateway_custom_plugin resource nested under service / route
  • Fixed false diff in the output of terraform plan for konnect_basic_auth resource

2.11.0

Released on 2025/06/27

Features

  • Add support for the konnect_realm, konnect_centralized_consumer and konnect_centralized_consumer_key resources

Bug fixes

  • Fixed error while creating openid-connect strategy in konnect_application_auth_strategy resource
  • Fixed error while running terraform apply for konnect_gateway_data_plane_client_certificate resource when the data plane certificate is deleted
  • The consumer.id field has been removed from plugins. This was accidentally added. Use the consumer_id field instead

2.10.0

Released on 2025/06/19

Features

  • Add support for konnect_cloud_gateway_private_dns resource

Bug fixes

  • Fixed error while running terraform apply for konnect_gateway_custom_plugin_schema resource when custom plugin schema is deleted
  • Fixed false diff in output of terraform plan for konnect_cloud_gateway_configuration resource

2.9.0

Released on 2025/06/16

Features

  • Add support for konnect_mesh_control_planes data source

Bug fixes

  • The token in konnect_system_account_access_token is now marked as sensitive
  • Fixed a false diff in the protocols field in Gateway plugin configurations

2.8.1

Released on 2025/05/22

Bug fixes

  • The provider now works with terraform v1.12.1

2.8.0

Released on 2025/05/20

Features

  • Add support for new resource konnect_gateway_partial which enables users to define shared configuration for Redis.

2.7.4

Released on 2025/05/14

Bug fixes

  • Fixed custom domain hook so that it sets both Host header and URL correctly.

2.7.3

Released on 2025/05/13

Bug fixes

  • Fixed JSON parsing errors when provisioning AWS VPC peering gateway in konnect_cloud_gateway_transit_gateway resource.

2.7.2

Released on 2025/05/06

Bug fixes

  • Fixed output of terraform plan for konnect_api_product_document and konnect_api_product_specification resources.

2.7.1

Released on 2025/05/01

Bug fixes

  • Fixed a bug in the file_log plugin path validation that disallowed /dev/stdout as a path

2.7.0

Released on 2025/05/01

Features

  • Add support for new Gateway 3.10 plugins:
    • gateway_plugin_ai_rag_injector
    • gateway_plugin_ai_sanitizer
    • gateway_plugin_confluent_consume
    • gateway_plugin_kafka_consume
    • gateway_plugin_request_callout

Bug fixes

  • The properties limit and window_size now accept array of values in ai-rate-limiting-advanced plugin according to the Gateway 3.10 schema

2.6.0

Released on 2025/04/22

Features

  • Add support for konnect_gateway_custom_plugin_streaming resource, which allows custom plugins to be deployed to Dedicated Cloud Gateways

Bug fixes

  • The scopes property in konnect_gateway_plugin_upstream_oauth can now be set to an empty array

2.5.0

Released on 2025/04/15

Features

  • Add support for konnect_gateway_control_plane_list data source

Bug fixes

  • The scopes property in konnect_gateway_plugin_openid_connect is no longer required

2.4.1

Released on 2025/03/13

Bug fixes

  • Fixed support for headers in the konnect_gateway_route resource
  • Removed the gateway_plugin_konnect_application_auth plugin as it is a system-managed plugin and can not be configured by users

2.4.0

Released on 2025/03/05

Features

  • Add support for konnect_gateway_route_expression resource
  • konnect_mesh_control_plane now supports features property
  • Add support for AWS VPC peering gateway in konnect_cloud_gateway_transit_gateway resource

Bug fixes

  • Foreign key references (e.g. service.id) in Kong Gateway are now cleared when removed from the manifest

2.3.0

Released on 2025/02/10

Features

  • Add support for konnect_portal_team resource
  • Add support for konnect_audit_log resource
  • Add support for konnect_audit_log_destination resource
  • Add support for konnect_gateway_config_store resource
  • Add support for new Gateway 3.9 plugins:
    • ai-azure-content-safety
    • confluent
    • service-protection
    • standard-webhooks
    • ai-semantic-cache
    • upstream-oauth
    • injection-protection
    • redirect
    • datadog-tracing
    • ai-proxy-advanced
    • ai-semantic-prompt-guard
    • json-threat-protection
    • header-cert-auth
    • ai-rate-limiting-advanced

Bug fixes

  • Make konnect_cloud_gateway_network plan output deterministic
  • Move protocols and foreign key (e.g. service, route) validation for plugins to be at plan time rather than runtime.

2.2.0

Released on 2024/12/06

Features

  • Add support for Portal SAML authentication
  • Added support for Konnect India region

2.1.0

Released on 2024/12/06

Features

  • Add support for konnect_gateway_mtls_auth resource
  • API Products now support public_labels
  • Added support for Konnect Middle-East region

Bug Fixes

  • Fix Expected #sdk.Konnect, got: *sdk.Konnect. error with custom plugins (and add an integration test)

2.0.2

Released on 2024/11/12

Bug Fixes

  • Removing service, route, consumer etc scope from a plugin now sends null to the API, removing the link between the plugin and the resource.

2.0.1

Released on 2024/11/11

Bug Fixes

  • Switched CLUSTER_TYPE_HYBRID to a deprecation rather than a hard removal as changing the type results in resource replacement

2.0.0

Released on 2024/11/11

🚨 BREAKING CHANGES

  • The konnect_cloud_gateway_transit_gateway resource structure has had a bug fix that enables both AWS and Azure support. This has changed the resource structure and you will need to recreate any transit gateway attachments.
  • CLUSTER_TYPE_HYBRID is an internal cluster name which has now been removed from the provider. Use CLUSTER_TYPE_CONTROL_PLANE instead.
  • Setting scopes = [] in the OpenID Connect plugin is now respected. This means that the default has changed from ['openid'] to [].

Features

  • Updated Kong Gateway plugin schemas to 3.8.x
  • Added support for Azure Cloud Gateways deployments

Bug Fixes

  • Fix OpenAPI filename validation in API Products when using variables

1.0.0

Released on 2024/09/11

Features

  • Released terraform-provider-konnect as GA 🎉

0.7.0

Released on 2024/09/11

Features

  • Add the konnect_gateway_custom_plugin resource for managing non-bundled plugins
  • Add support for all bundled Kong plugins
  • Add support for labels to konnect_api_product_version
  • Add support for ordering to konnect_gateway_plugin

Bug fixes

  • Force recreation of konnect_gateway_* entities if control_plane_id changes
  • proxy_urls on konnect_control_plane and dataplane_groups on konnect_cloud_gateway are now marked as sets rather than list. This makes terraform diff ignore the order of items in the list.

0.6.3

Released on 2024/08/25

Features

  • Add support for labels to application_auth_strategies

Bug fixes

  • The cluster_cert_key in serverless_cloud_gateway is now marked as sensitive

0.6.2

Released on 2024/07/24

Features

  • Add the ability for the Kong team to use the provider against development environments

Bug fixes

  • Generate up to date documentation

0.6.1

Released on 2024/07/23

Features

  • Add list of enums for available roles when using the Identity API
  • Add pattern validation based on OpenAPI spec when running terraform validate

Bug Fixes

  • Fixed terraform import for the konnect_portal resource

0.6.0

Released on 2024/07/11

BREAKING CHANGES

  • The konnect_portal resource can no longer be used to adopt the existing default portal without first running terraform import

Features

  • Add support for the konnect_api_product_document, konnect_portal_appearance, konnect_gateway_plugin_pre_function, konnect_gateway_plugin_post_function and konnect_gateway_plugin_statsd resources

0.5.1

Released on 2024/07/03

Features

  • Add tfdocs for all existing resources

0.5.0

Released on 2024/07/03

Features

  • Add support for the konnect_serverless_cloud_gateway, konnect_gateway_plugin_exit_transformer, konnect_gateway_consumer_group and konnect_gateway_consumer_group_member resources

Bug Fixes

  • konnect_gateway_* resources are now updated in place rather than any change causing the entity to be recreated

0.4.0

Released on 2024/06/24

Features

  • Add support for the konnect_api_product_specification, konnect_gateway_custom_plugin_schema, konnect_team, konnect_team_role and konnect_team_user resources

Bug Fixes

  • Make Cloud Gateways + Identity APIs point at global.api.konghq.com rather than the provided server_url

0.3.1

Released on 2024/06/14

Bug Fixes

  • Ensure that konnect_gateway_vault.config is sent via the provider

0.3.0

Released on 2024/06/14

Features

  • Update all schemas to Kong Gateway 3.7.x

Bug Fixes

  • Do not send default values from the provider as they'll be applied on the server automatically
    • This allows terraform-provider-konnect 0.3.0 to be used with Kong Gateway 3.6 and below

0.2.4

Released on 2024/05/31

Features

  • Allow users to set provider attributes via environment variables
    • personal_access_token = KONNECT_TOKEN
    • system_account_access_token = KONNECT_SPAT
    • server_url = KONNECT_SERVER_URL

0.2.3

Released on 2024/05/14

Features

  • Add support for the konnect_cloud_gateway_configuration, konnect_cloud_gateway_custom_domain, konnect_cloud_gateway_network and konnect_cloud_gateway_transit_gateway resources

Bug Fixes

  • Fix konnect_portal_product_version creation bug

0.2.2

Released on 2024/05/04

Features

  • Add support for the konnect_system_account, konnect_system_account_access_token, konnect_system_account_role and konnect_system_account_team resources

0.2.1

Released on 2024/04/26

Features

  • Add support for the konnect_gateway_data_plane_client_certificate resource

0.2.0

Released on 2024/04/18

BREAKING CHANGES

  • The provider server_url no longer contains an API version. Update your provider configuration to use https://us.api.konghq.com (or your chosen region)
  • labels on the konnect_gateway_control_plane resource now accept a map of values rather than using jsonencode()

Fixes

  • Mesh control planes can be created in regions other than NA
  • Gateway control planes now accept CLUSTER_TYPE_CONTROL_PLANE in the cluster_type field

0.1.0

Released on 2024/04/16

  • Initial release