Home / Companies / Kong / Blog / December 2024

December 2024 Summaries

14 posts from Kong

Filter
Month: Year:
Post Summaries Back to Blog
Kong Gateway 3.9 introduces extended AI support with over 1 million new AI models and agentic workflows, enabling organizations to make their services more AI-ready. The release also enhances security and threat protection with injection protection and service-level rate limiting, providing users with better protection against malicious attacks and traffic management. With these updates, Kong Gateway aims to provide a comprehensive API gateway solution that supports the growing demand for AI-powered applications while ensuring security, reliability, and performance.
Dec 20, 2024 670 words in the original blog post.
APIs, essential for communication and data exchange between applications, are particularly vulnerable to cyber threats like injection attacks, which involve inserting malicious code into an application to execute unauthorized actions. These attacks are projected to significantly increase, posing substantial financial risks and leading to more data breaches than average security incidents. The threats exploit weaknesses in API endpoint security, often due to rushed development, inexperienced developers, and poor coding practices. Injection attacks can take various forms, including SQL, NoSQL, and command injections, targeting different parts of the data processing workflow. To combat these threats, a multi-faceted security strategy is necessary, incorporating both preventative and defensive measures such as input validation, parameterized queries, and the use of API gateways. API gateways play a crucial role in scrutinizing requests and blocking malicious ones before they reach backend systems. Solutions like the Injection Protection Plugin in Kong Gateway Enterprise 3.9 are designed to identify and block suspicious patterns, offering both default and customizable protections to secure APIs against a range of injection attacks.
Dec 20, 2024 1,258 words in the original blog post.
The Kong Ingress Controller (KIC) 3.4 release introduces several enhancements, including improved TLS encryption, optimized performance for complex deployments, and the general availability of Kong Custom Entities support. This update simplifies "upstream TLS" configuration, allowing for encrypted traffic between the Ingress and upstream services using the Kubernetes Gateway API or specific annotations. It also includes scalability improvements with flags to limit memory usage by selecting specific Secrets and ConfigMaps. Additionally, new Prometheus metrics are introduced to monitor configuration sizes in DB-less mode, while Kong Custom Entities offer streamlined declarative configuration through CRDs. The release marks the first long-term support (LTS) version in the 3.X series, ensuring critical updates and stability for three years. Users are encouraged to explore the new features and share feedback through Kong Konnect and GitHub discussions.
Dec 19, 2024 772 words in the original blog post.
Kong has released Kong Gateway Operator 1.4, which allows users to manage Konnect configurations declaratively within Kubernetes clusters through Custom Resource Definitions (CRDs). This new feature facilitates the management of Konnect entities using familiar Kubernetes resources such as KongConsumer and KongPlugin. The approach involves defining CRDs for each Konnect entity type and organizing them under a new API group, konnect.konghq.com, while maintaining backward compatibility with existing KIC CRDs. The operator uses a control loop to synchronize desired and observed states of Konnect entities, relying on the Konnect API as the authoritative source in case of conflicts. The implementation leverages Go's generics to create a flexible, type-agnostic system, although it faces limitations due to the lack of generics specialization. The update aims to streamline the process of managing cloud-based and self-hosted configurations without requiring users to manage additional CRDs.
Dec 18, 2024 1,101 words in the original blog post.
Rabobank, a major Dutch bank, has effectively harnessed the power of Kong Gateway and Kong Konnect to enhance its API management capabilities, which has resulted in significant improvements in efficiency, scalability, and security. With about 300 teams working on the Kong platform, Rabobank has seen a 40% annual growth in API traffic, highlighting the platform's critical role in their operations. The bank employs a federated API gateway model with isolated gateways for each team, allowing for autonomous team operations while maintaining central governance. This setup has enabled Rabobank to quickly identify and address anomalies in API usage, thanks to improved observability and ownership. The strong partnership between Rabobank and Kong has facilitated the bank's ambitious API architectural vision, leading to plans for further expansion across various regions and cloud platforms, positioning Kong as the central API management solution within the organization.
Dec 17, 2024 1,283 words in the original blog post.
Allo Bank, a digital bank launched in 2022 and part of the Citicorp group, rapidly gained over 10 million customers and became the most downloaded digital banking app within a year of its debut. To accommodate its expansive digital services ecosystem and customer base, Allo Bank adopted an API-first strategy powered by Kong, enabling seamless integration with various technologies while ensuring compliance, security, and scalability. Daniel Niko, Head of Application Management, highlighted the importance of Kong in supporting the bank's transition from monolithic applications to microservices, enhancing their ability to handle increased transaction volumes and reducing transaction costs by 70%. By leveraging Kong's customizable plugins and open-source capabilities, Allo Bank successfully migrated its services, witnessing a fourfold increase in transaction handling capacity and ultimately phasing out its legacy middleware systems.
Dec 13, 2024 1,159 words in the original blog post.
Kong Konnect has expanded its hosting capabilities to include two new geographic regions, the Middle East (UAE) and India, bringing the total to five global regions alongside the US, EU, and Australia. This expansion allows organizations to deploy Konnect's core services, such as Gateway Manager, Mesh Manager, Dev Portals, Service Catalog, and Analytics, closer to their end-users, enhancing data compliance with regional regulations and minimizing latency for improved user experiences. By offering greater flexibility in choosing hosting regions, Konnect enables companies to build localized, efficient, and secure solutions without compromising on performance or compliance. Users can easily select their preferred geographic region through the Konnect interface to set up control planes and analyze API traffic and performance, ensuring seamless integration and operation tailored to their specific regional needs.
Dec 12, 2024 458 words in the original blog post.
Kong Konnect serves as an infrastructural SaaS solution that manages control planes and API management applications for customers' data planes, highlighting the importance of uptime and resilience. Developers are responsible for reducing Mean Time to Repair (MTTR) and ensuring reliability by being prepared for incidents, especially during high-demand periods like holidays. Effective on-call management involves comprehensive team preparation, setting up reliable notification systems, and ensuring connectivity through hotspots and smart devices to handle alerts efficiently. Preemptive steps such as exporting on-duty schedules, configuring notifications to minimize disruptions, and gearing up with smart bands and power banks help maintain service quality while reducing stress. Tailoring these strategies can lead to a smoother on-call experience, allowing developers to manage incidents confidently and without unnecessary disturbance.
Dec 12, 2024 1,307 words in the original blog post.
Kong Insomnia 10.2 introduces several new features and improvements, including built-in conflict resolution for Git Sync, which allows users to resolve Git conflicts directly within the platform by choosing either their own or another's changes, enhancing collaboration on API collections and design documents. The release also includes a new table view for managing environment variables, aiming to simplify the process for new users while retaining the option to switch back to the traditional JSON view for existing users. Additionally, Insomnia 10.2 offers new enterprise capabilities with the introduction of Teams for scalable RBAC settings and SCIM integration, enabling automatic user association with Insomnia teams through third-party identity providers. These updates underscore Kong's commitment to improving user experience and scalability for both individual and enterprise users.
Dec 11, 2024 326 words in the original blog post.
Kong Insomnia has introduced two new enterprise capabilities—Teams and Domain Capture—to enhance user management at scale, complementing existing features like EE SSO and SCIM. "Teams" allows users to be grouped and managed collectively, simplifying collaboration by enabling invitations to entire teams rather than individuals, with automated user assignments via SCIM and third-party IDPs. This feature streamlines the modification of invite lists across projects and supports automatic user provisioning based on identity provider settings. Domain Capture consolidates users associated with an enterprise's verified domain into a designated team, centralizing control and simplifying license management through a new administration page. These features aim to ease the challenges of managing team members, licenses, and onboarding, thereby improving administration and compliance for larger organizations.
Dec 11, 2024 440 words in the original blog post.
Kong's 2024 API Impact Report highlights the dual nature of AI in enterprises, offering new opportunities for innovation while introducing potential vulnerabilities, particularly in API security. Despite 85% of organizations expressing confidence in their security measures, 55% experienced API security incidents in the past year, with nearly half incurring remediation costs exceeding $100,000. The report reveals a concerning gap between perceived readiness and actual security risks, as 77% acknowledge significant threats posed by AI and large language models. As API attacks are projected to surge by 548% by 2030, the need for robust security measures becomes critical, especially given that API breaches tend to result in more leaked data compared to average security breaches. Organizations are increasingly concerned about AI-enhanced cyberattacks, with 92% taking steps to address these threats, yet many remain uncertain about the adequacy of their current security investments. The report emphasizes the necessity of treating API infrastructure as mission-critical to navigate the evolving landscape of AI-related risks effectively.
Dec 10, 2024 408 words in the original blog post.
Agentic AI represents a significant advancement in artificial intelligence, designed to operate autonomously and achieve goals without human intervention, distinguishing itself from traditional and generative AI by emphasizing adaptive decision-making and real-time interaction with the environment. This technology utilizes complex algorithms and sensory data to navigate intricate scenarios, constantly learning and improving through feedback, which reduces the need for continuous human prompting. Agentic AI's potential applications span diverse industries, including healthcare, finance, manufacturing, and IT, where it can enhance efficiency, personalize experiences, and optimize workflows by making independent decisions. Despite its benefits, implementing agentic AI poses challenges such as ethical considerations, data privacy concerns, and the complexity of developing sophisticated systems that require extensive expertise. As agentic AI becomes increasingly integrated into daily life and various sectors, the focus will be on balancing its transformative potential with responsible use, ensuring secure and equitable implementation through robust governance frameworks and adaptive regulations.
Dec 10, 2024 2,022 words in the original blog post.
Cross-Origin Resource Sharing (CORS) is a crucial concept for web developers, as it facilitates secure communication between different domains in modern web applications. This guide delves into CORS, explaining its role in enabling cross-origin interactions while maintaining security, especially in microservices architecture and distributed applications. CORS operates as a security checkpoint, akin to a security guard that determines whether one website can access resources from another, governed by the Same-Origin Policy. It uses HTTP headers to manage these interactions, involving simple and preflight requests, and requires careful configuration to avoid security vulnerabilities. In modern applications, CORS is often managed centrally via an API Gateway, simplifying policy enforcement and enhancing security. Developers must navigate common errors and security implications, such as avoiding overly permissive settings, to maintain effective cross-origin communication. While CORS is a valuable security mechanism, it should complement other measures like authentication and secure communication protocols to ensure comprehensive protection.
Dec 09, 2024 3,050 words in the original blog post.
AI proxies have emerged as a transformative technology in the software development landscape, offering a significant advancement over traditional middleware by incorporating machine learning and natural language processing to optimize system interactions. Unlike standard API proxies that manage network requests through static rules, AI proxies dynamically adapt to changing needs, enhance communication, and improve overall performance and security by predicting future requirements and identifying potential risks in real time. They play a crucial role in accelerating development processes by reducing the need for manual setups, ensuring reliable performance through smart routing, and enhancing code quality with features like smart validation and threat detection. Despite the challenges of adopting AI proxies, such as the learning curve, performance issues, and managing multiple providers, best practices like step-by-step implementation and regular performance monitoring can mitigate these hurdles. Kong's AI Proxy Plugin exemplifies the benefits of AI proxies by offering easy integration with multiple service providers, smart data routing, and robust security measures, making it an attractive option for developers seeking to streamline their workflows and unlock new levels of efficiency in their software infrastructure.
Dec 05, 2024 1,439 words in the original blog post.