Docs

API7 Gateway 3.2.16.3

A secret object is a piece of sensitive information that needs to be protected from unauthorized access

Release Date: 2024-10-21

Features

Reference Secrets in AWS Secrets Manager

A secret object is a piece of sensitive information that needs to be protected from unauthorized access, while a secret provider object is used to set up integration with an external secret manager(HashiCorp Vault, AWS Secret Manager, etc.), so that API7 Gateway can establish connections and fetch secrets from the secret manager dynamically at runtime.

See Reference Secrets in AWS Secrets Manager for more details.

Anonymous Consumers for API authentication

An anonymous consumer does not need to authenticate, but can be restricted by rate limiting. You should configure anonymous consumers in authentication plugins on the service/route, then combined with rate limiting plugins.

For details, see the following documentation:

Security

Improvements

  • Supported for 2 million consumers.
  • Sorted the consumer list by name.
  • Removed conf_server from API7 gateway.
  • Improved rate limiting related plugins to be more flexible, allowed for consumer-specific rate limits on a per-service/route basis. For details, see Limit Count Plugin (opens in Plugin Hub docs) and Limit Req Plugin (opens in Plugin Hub docs).
  • Advanced request & response transformation:
    • During request transformation, support passing Lua code to obtain values.
    • Aligned the capabilities of Kong's Request Transformation and Response Transformation.
  • Displayed the total number of routes added in a service.
  • Changed plugin list configuration from data plane to control plane. Not compatible with version under 3.2.15.0
  • Added certificate expiration reminder in alert policies.
  • Displayed a notification explaining the logout reason before redirecting to the login page due to multi-device login.
  • Improved frontend page responsiveness and loading speed.
  • Optimized the "Use Upstream Timeout" UI.
  • Optimized API7 Portal(Beta) list page rendering speed.

Fixes

  • Fixed issue: multiple paths can now be configured for a single route on the Dashboard.
  • Fixed issue:the OpenTelemetry Plugin (opens in Plugin Hub docs) did not support set_ngx_var.
  • Fixed issue: the ACL Plugin (opens in Plugin Hub docs) should not output warning logs during normal use.
  • Enhanced data plane lua_ssl_trusted_certificate configuration item.
  • Synchronized the Body Transformer Plugin (opens in Plugin Hub docs) code with the APISIX mainline version.
  • Resolve issue: when a plugin that is not available to the stream module is configured on a service, the data plane prints error logs.
  • Changed the Edit operation for Token to Edit Name.
  • Resolve issue: when editing a service registry, the service discovery type does not match the form.