API7 Gateway 3.9.0
Newly Redesigned Developer Portal — The Developer Portal has been completely redesigned.
Release Date: 2026-01-06
Breaking Changes
Developer Portal
-
Newly Redesigned Developer Portal
Upgrade note
The Developer Portal has been completely redesigned. This release introduces breaking changes that require action before upgrading:
- The built-in Portal SSO feature has been removed. Configure authentication through the new Portal-level authentication mechanism instead.
- The Portal frontend is now open-source. Existing Portal customizations must be migrated to the new SDK-based architecture.
Data Plane
-
Health check status control API
Upgrade note
The health check engine has been rewritten, and the response body of the control API endpoints
GET /v1/healthcheckandGET /v1/healthcheck/{src_type}/{src_id}(served on the Data Plane control port,9090by default) has changed. The request paths, methods, and status codes are unchanged. Monitoring scripts, alerting rules, and dashboards that parse these responses must be updated before upgrading.Response in 3.8.x and earlier:
[ { "name": "upstream#/apisix/upstreams/1", "src_type": "upstreams", "src_id": "1", "nodes": [ { "host": "127.0.0.1", "port": 1980, "weight": 1, "priority": 0 }, { "host": "127.0.0.2", "port": 1988, "weight": 1, "priority": 0 } ], "healthy_nodes": [ { "host": "127.0.0.1", "port": 1980, "weight": 1, "priority": 0 } ] } ]Response in 3.9.0 and later:
[ { "name": "/apisix/upstreams/1", "type": "http", "nodes": [ { "ip": "127.0.0.1", "port": 1980, "status": "healthy", "counter": { "success": 0, "http_failure": 0, "tcp_failure": 0, "timeout_failure": 0 } }, { "ip": "127.0.0.2", "port": 1988, "status": "unhealthy", "counter": { "success": 0, "http_failure": 0, "tcp_failure": 2, "timeout_failure": 0 } } ] } ]Field by field:
src_typeandsrc_idare removed. A resource is now identified bynamealone.nameno longer carries theupstream#prefix. It is now the resource path, such as/apisix/upstreams/1.healthy_nodesis removed. Each entry innodesnow carries its ownstatus, which ishealthy,unhealthy,mostly_healthy, ormostly_unhealthy. A node is in service when itsstatusishealthyormostly_healthy—mostly_healthyis a node that is still receiving traffic after some probe failures — so the predicate that reproduces the oldhealthy_nodeslist isstatus == "healthy" || status == "mostly_healthy". Filtering on the literalhealthyalone drops nodes the gateway is still routing to.nodesentries no longer describe the configured upstream node (host,port,weight,priority). They describe the health check target:ip,port,status, and acounterobject holding the consecutivesuccess,http_failure,tcp_failure, andtimeout_failurecounts. A target also reportshostnamewhen the health check is configured with ahost, andhostheaderwhen the request carries a rewrittenHostheader.- A new top-level
typefield reports the type of the configured check, such ashttp,https, ortcp.
Two changes in what the endpoints report:
nodesnow lists the targets registered with the health checker rather than the nodes in the upstream configuration. Whenchecks.active.hostorchecks.active.portoverrides the node address, several upstream nodes collapse into a single target, so the list can be shorter than the upstream's node list.- A resource that has
checksconfigured is now listed as soon as it is loaded, with an emptynodeslist until its health checker is created. Earlier versions listed a resource only after its health checker existed.
Features
- All API7 Enterprise Docker images are now signed using Cosign, enhancing image security.
Developer Portal
- Provides open-source SDKs and a frontend scaffolding project to facilitate user customization and development.
- Introduces a new Portal-level authentication mechanism for API integration.
Plugins
-
Limit Conn (opens in Plugin Hub docs)/Limit Req (opens in Plugin Hub docs)
-
Supported using Redis and Redis Cluster as the rate limiting data storage backend.
Upgrade note
Added a new required field
policy. Existing configurations do not require modification and will continue to function in the data plane. However, when updating a configuration, this field must be supplied (e.g.,policy=local), otherwise the update will be rejected.
-
-
Request ID (opens in Plugin Hub docs)
- Added a new algorithm
ksuidfor ID generation.
- Added a new algorithm
-
Loki Logger (opens in Plugin Hub docs)
- Supported customizing HTTP headers sent to the Loki server.
-
File Logger
- Supported conditional request logging using the
matchfield.
- Supported conditional request logging using the
-
Workflow (opens in Plugin Hub docs)
- The
rulesfield is now required.
- The
Control Plane
- Allowed to completely disable built-in username/password login after enabling SSO login.
- Supported configuring the maximum execution time for database statements.
- Observability Enhancements
- Enabled the pprof performance profiling by default.
- Added database connection pool metrics to the metrics endpoint.
- Supported separate logging for access and error logs.
- Added the
request_idfield to access and error logs.
Fixes
Plugins
- OpenAPI to MCP (opens in Plugin Hub docs)
- Fixed issue: Passing authentication credentials via query parameters could lead to sensitive information leakage.
Data Plane
- Optimized caching behavior for resolution chains that involve CNAME and A records.
Control Plane
- Removed the display of IP and Port from the gateway instance list to avoid misleading users.
- Fixed issue: Database deadlocks could occur during concurrent batch inserts into the API call statistics table.
- Fixed issue: Dashboard failed to start when using a non-
publicschema in PostgreSQL.