Docs

API7 Gateway 3.2.15.0

This is a breaking change.

Release Date: 2024-09-14

Features

Consumer Credentials

This is a breaking change. Creating new authentication plugins (key-auth, basic-auth, JWT-auth, or HMAC-auth) for consumers is no longer supported. Please use consumer credentials instead. Existing plugin configurations will remain accessible and editable until disabled.

Consumer credentials offer enhanced flexibility by allowing multiple credentials per consumer. They replace traditional authentication plugins like key-auth, basic-auth, JWT-auth, and HMAC-auth, providing a more user-friendly experience. See Manage Consumer Credentials for details.

Security

  • The root user, admin, becomes a protected account that cannot be modified by roles, permission policies, or other users. It cannot be deleted or have its password reset by other users.

Improvements

  • Sorted the service list alphabetically by name is now supported.
  • Added gateway group ID to every audit log, so you can search or filter audit logs by gateway group.
  • Recorded audit log for automatically deleted gateway instances that have been offline for more than 7 days.
  • Supported filtering published services on a gateway group by label.
  • Ensured control plane addresses do not end with a slash.
  • Supported annotations in Helm.
  • Provided configuration options to control the timeout for data plane heartbeat and telemetry requests, and adjust the default value to 30s.

Fixes

  • Clarified the error message when a user logs in via SSO after SCIM is enabled, but the user does not exist in the system.
  • Fixed the issue of failed canary configuration adjustments after modifying no version published service.