API7 Gateway 3.2.16.3
A secret object is a piece of sensitive information that needs to be protected from unauthorized access
Release Date: 2024-10-21
Features
Reference Secrets in AWS Secrets Manager
A secret object is a piece of sensitive information that needs to be protected from unauthorized access, while a secret provider object is used to set up integration with an external secret manager(HashiCorp Vault, AWS Secret Manager, etc.), so that API7 Gateway can establish connections and fetch secrets from the secret manager dynamically at runtime.
See Reference Secrets in AWS Secrets Manager for more details.
Anonymous Consumers for API authentication
An anonymous consumer does not need to authenticate, but can be restricted by rate limiting. You should configure anonymous consumers in authentication plugins on the service/route, then combined with rate limiting plugins.
For details, see the following documentation:
- Key Authentication (opens in Plugin Hub docs)
- Basic Authentication (opens in Plugin Hub docs)
- JWT Authentication (opens in Plugin Hub docs)
- HMAC Authentication (opens in Plugin Hub docs)
- Rate Limit with Anonymous Consumers
Security
- Added a status interface for self health checks on the data plane. For details, see enable data plane health check for high availability.
Improvements
- Supported for 2 million consumers.
- Sorted the consumer list by name.
- Removed
conf_serverfrom API7 gateway. - Improved rate limiting related plugins to be more flexible, allowed for consumer-specific rate limits on a per-service/route basis. For details, see Limit Count Plugin (opens in Plugin Hub docs) and Limit Req Plugin (opens in Plugin Hub docs).
- Advanced request & response transformation:
- During request transformation, support passing Lua code to obtain values.
- Aligned the capabilities of Kong's Request Transformation and Response Transformation.
- Displayed the total number of routes added in a service.
- Changed plugin list configuration from data plane to control plane. Not compatible with version under 3.2.15.0
- Added certificate expiration reminder in alert policies.
- Displayed a notification explaining the logout reason before redirecting to the login page due to multi-device login.
- Improved frontend page responsiveness and loading speed.
- Optimized the "Use Upstream Timeout" UI.
- Optimized API7 Portal(Beta) list page rendering speed.
Fixes
- Fixed issue: multiple paths can now be configured for a single route on the Dashboard.
- Fixed issue:the OpenTelemetry Plugin (opens in Plugin Hub docs) did not support
set_ngx_var. - Fixed issue: the ACL Plugin (opens in Plugin Hub docs) should not output warning logs during normal use.
- Enhanced data plane
lua_ssl_trusted_certificateconfiguration item. - Synchronized the Body Transformer Plugin (opens in Plugin Hub docs) code with the APISIX mainline version.
- Resolve issue: when a plugin that is not available to the stream module is configured on a service, the data plane prints error logs.
- Changed the
Editoperation for Token toEdit Name. - Resolve issue: when editing a service registry, the service discovery type does not match the form.