Home / Companies / Kong / Blog / September 2025

September 2025 Summaries

17 posts from Kong

Filter
Month: Year:
Post Summaries Back to Blog
AI deployment in regulated industries such as pharmaceuticals, financial services, and insurance presents unique challenges due to strict compliance requirements and the need to protect sensitive data. Despite these hurdles, AI offers significant potential benefits, including accelerating drug discovery, enhancing fraud detection, and improving risk modeling. The pharmaceutical industry, in particular, is poised for transformation through AI, as companies like GSK demonstrate by using AI-powered models to personalize cancer treatments. To safely and effectively implement AI in regulated sectors, a three-layer strategy is recommended: identifying high-value AI use cases, ensuring compliance with regulatory frameworks, and applying AI governance to mitigate risks. This involves building a robust API strategy, which includes securing universal access through a consistent interface, protecting AI and large language models with security and compliance measures, and facilitating discovery and consumption of services. Data privacy remains a significant concern, necessitating careful handling of sensitive information. A unified platform such as Kong Konnect can help streamline these efforts, offering a comprehensive solution for securely and responsibly deploying AI at scale in regulation-heavy environments.
Sep 29, 2025 2,736 words in the original blog post.
The text introduces the concept of event API productization, emphasizing its growing importance in distributed applications and cloud-native development. It highlights the gap in security, governance, and productization tools in the Event-Driven Architecture (EDA) world, particularly for Apache Kafka. The Kong Event Gateway is presented as a solution to extend governance and lifecycle management from synchronous APIs to Kafka event streams, enabling organizations to treat streams as valuable data products. This involves defining a clear lifecycle, ownership, discoverability, and measurable usage for event data products. The Kong Event Gateway facilitates this transformation by providing centralized control over Kafka clusters, offering capabilities like authentication mediation, access control, schema validation, and message encryption. The text encourages attending the API Summit 2025 for further insights into using the Kong Event Gateway to enhance API and event streaming strategies.
Sep 29, 2025 752 words in the original blog post.
Securing microservices at scale involves implementing five key strategies: building complete architecture visibility, applying zero trust authentication, creating defense in depth, automating security throughout the CI/CD pipeline, and enabling real-time monitoring and incident response. Visibility is crucial as it identifies unmonitored attack vectors and undocumented dependencies, while zero trust authentication eliminates implicit trust by verifying every request between services. Defense in depth employs multiple layers such as API gateways, web application firewalls (WAFs), and network segmentation to thwart potential breaches. Automation in the CI/CD pipeline ensures rapid detection and remediation of vulnerabilities, and real-time monitoring allows for prompt threat detection and response, significantly reducing the average detection time from days to minutes. These practices, when implemented incrementally, can lead to measurable security improvements within a short period, supporting organizations in building resilient microservice architectures.
Sep 26, 2025 2,091 words in the original blog post.
As businesses rapidly deploy AI-native applications alongside traditional API infrastructure, managing observability across both domains presents significant challenges, necessitating unified solutions to enhance performance visibility and operational control. AI applications are deeply integrated with existing API ecosystems, requiring comprehensive visibility across entire request flows to address issues like cross-system latency, cost attribution, failure correlation, and security monitoring. Without a unified observability approach, organizations face operational blindness, inefficiencies, and increased security risks. Leading companies have adopted unified observability architectures, such as those enabled by Kong Konnect, to streamline operations and improve analytics capabilities. The API Summit 2025 will focus on these challenges, offering insights from industry leaders on building unified observability architectures, with discussions on proven implementation patterns, advanced analytics platforms, and strategic guidance for scaling observability across global enterprises. As AI adoption grows, organizations with unified observability will gain a competitive advantage by responding faster to incidents, optimizing resource allocation, and maintaining robust security postures.
Sep 25, 2025 1,013 words in the original blog post.
Kong Konnect's Control Plane Groups present a comprehensive solution for managing the complexities of API governance across multiple teams within an organization, addressing the challenges of scaling API infrastructure without compromising security, compliance, or operational efficiency. This federated deployment model allows individual teams to independently deploy and manage their APIs while adhering to overarching global policies set by a central governance team, ensuring consistent security and compliance across the board. Control Plane Groups facilitate a balance between centralized governance and decentralized innovation, where teams can operate autonomously without impacting each other, and platform teams can enforce policies globally to minimize operational overhead and streamline onboarding. The model integrates seamlessly with Kong Konnect's features like analytics dashboards and developer portals, making it a robust backbone for a scalable API ecosystem, where enterprise-level security and compliance are maintained, and the speed and autonomy of API deployments are enhanced.
Sep 24, 2025 1,098 words in the original blog post.
Kong Gateway Enterprise 3.8 will reach its End Of Life (EOL) phase in September 2025, after which it will no longer receive full support from Kong. A 12-month sunset support period will follow, ending in September 2026, during which the focus will be on assisting customers with upgrading to a newer version of Kong Gateway Enterprise. Customers using version 3.8 are advised to upgrade promptly to ensure continued support, and additional details can be found in Kong's support policy, which outlines the support duration for each API gateway version.
Sep 23, 2025 100 words in the original blog post.
Kong Mesh 2.12 introduces significant features such as support for SPIFFE/SPIRE to enhance workload identity and trust models, along with a consistent Kuma Resource Identifier (KRI) naming convention to streamline resource management. Built on the open-source Kuma service mesh, Kong Mesh aims to provide enterprise-level features with simplicity, focusing on security, observability, and traffic control across multiple environments, including cloud providers, Kubernetes clusters, and traditional server setups. The new SPIFFE/SPIRE support in Kong Mesh enables secure mutual TLS between services and allows for granular identity provider management, while the KRI naming convention aids in better resource inspection and management. Additionally, Kong Mesh offers features like zero-trust security, isolated mesh support, and global control planes, all managed through the Konnect Mesh Manager for a comprehensive view of deployments. The update also includes the concept of MeshTrust for organizations not using SPIRE and plans for cross-zone identity support in future releases.
Sep 18, 2025 479 words in the original blog post.
Kong is advancing the capabilities of Kubernetes by leveraging key components such as Kubernetes Ingress Controllers, Operators, and the Gateway API to enhance API exposure, governance, and operations. These elements transform Kubernetes from a mere container orchestration platform into one that supports API-driven workflows, including AI. By integrating these components, Kong simplifies and scales Kubernetes usage, offering a unified experience with its Kong Operator (KO) 2.0 and the forthcoming KO 2.1. KO 2.1, to be launched at API Summit 2025, introduces hybrid mode support, integrating both Gateway API and Konnect control plane for streamlined operations, reducing complexity, and maintaining consistent traffic management across large environments. Additionally, the release enhances visibility and troubleshooting with the Konnect Debugger, automatic service catalog integration, and a developer portal, thereby promoting a self-service model that integrates Kubernetes-hosted APIs into the wider enterprise ecosystem. This unification sets a new standard for deploying, governing, and consuming Kubernetes APIs, aligning with enterprise-level needs and strategies.
Sep 18, 2025 789 words in the original blog post.
Agentic AI is rapidly being adopted by enterprises, driven by motivations such as cost reduction and increased efficiency, with 90% of surveyed organizations actively implementing AI agents and 79% expecting full-scale adoption within three years. Despite the enthusiasm, challenges like integration complexity with legacy systems, security, and compliance concerns present significant barriers, necessitating robust AI governance solutions such as AI gateways that manage and monitor interactions between AI systems and enterprise infrastructure. While 49% of workers believe AI agents will support existing roles, 45% foresee job displacement, a concern amplified by recent labor market data showing stalled IT job growth and wage increases since the rise of AI tools. Enterprises aim to navigate these challenges by preparing systems, APIs, and governance models for autonomous operations, while also evolving workforce skill sets toward higher-value tasks.
Sep 17, 2025 1,108 words in the original blog post.
Modern enterprises are adopting multi-cloud strategies to enhance flexibility and avoid vendor lock-in, and Kong's Dedicated Cloud Gateways (DCGWs) facilitate this by offering fully vendor-managed API and AI infrastructure across AWS, Azure, and GCP. The recent introduction of managed Redis instances for DCGWs aims to eliminate infrastructure barriers by enabling instant activation of critical capabilities like caching and rate limiting, with Redis co-located in chosen cloud regions for optimal performance. This enhancement reduces operational overhead and supports advanced AI use cases such as rate limiting, quota management, and intelligent caching, crucial for cost-effective AI service delivery. By simplifying API infrastructure management, platform teams can now focus on developing AI capabilities, transforming infrastructure from a burden to a business asset. The managed Redis feature lays the groundwork for future intelligent API management features, positioning Kong's DCGWs as essential tools for organizations prioritizing AI innovation and multi-cloud resilience.
Sep 16, 2025 1,034 words in the original blog post.
API security is a multifaceted challenge that cannot be solved by a single tool, requiring a comprehensive, defense-in-depth strategy centered around a robust API management platform. The belief in a "silver bullet" solution is misguided and potentially dangerous, as effective API security demands multiple layers of defense across the API lifecycle, from design to production. An API management platform can serve as a central hub to integrate various security tools and technologies, such as advanced access control, authentication, and authorization frameworks, as well as secure credential management and centralized policy enforcement. The Kong API platform exemplifies this approach by offering a range of plugins and integrations to enhance security, including OAuth security extensions, secrets management, and observability tools. Observability is crucial for maintaining security by providing real-time insights into API transactions, enabling the detection and prevention of threats. By unifying these diverse technologies, API platforms create a resilient and secure ecosystem that supports business growth while adapting to evolving security threats.
Sep 11, 2025 1,542 words in the original blog post.
Kong's recognition in eight categories across six Gartner hype cycles for 2025 highlights its comprehensive capabilities as an API platform that supports innovation, cost reduction, developer productivity, and enhanced security. The inclusion showcases Kong's strengths in areas such as AI-driven API consumption, lightweight API gateways, and service mesh solutions that optimize developer tools without added complexity. In regulated industries like healthcare, Kong's secure FHIR API management allows for faster, compliant development. The platform's unified management across diverse environments reduces costs and operational overhead, while its API observability ensures a secure landscape. Kong's platform offers end-to-end API management, addressing core API needs, AI gateway capabilities, event-driven architecture, and service mesh functionality, ultimately providing a versatile solution that accelerates market entry, lowers ownership costs, and bolsters security. This recognition affirms Kong's position as a leading unified API platform suitable for various strategic objectives, from enhancing internal developer experiences to driving AI initiatives.
Sep 11, 2025 693 words in the original blog post.
Emily, an API product manager at ACME, Inc., faces challenges in accessing crucial API analytics needed to answer questions about top API consumers and performance issues without relying on the engineering team. This dependency creates delays as she waits for technical assistance to obtain insights from logs or dashboards, which are not readily accessible to non-engineering staff. API product managers like Emily are responsible for overseeing APIs as products, ensuring their adoption, reliability, and overall business impact, which requires continuous visibility into key performance indicators (KPIs) such as usage metrics, error rates, and consumer engagement. Kong Konnect's Advanced Analytics offers a solution by providing a user-friendly platform for API product managers to independently access and customize dashboards, offering real-time insights into API traffic, performance, and health, thus allowing them to make informed decisions swiftly without interrupting engineering workflows. This tool empowers API product managers to maintain API growth and reliability without waiting for engineering support, enhancing their ability to lead with data-driven insights.
Sep 09, 2025 1,355 words in the original blog post.
Kong has acquired OpenMeter, a leader in real-time usage metering and billing, to integrate its capabilities into Kong Konnect, enhancing usage-based pricing, entitlements, and invoicing for APIs, events, and AI workloads. This acquisition marks a significant milestone for Kong, enabling their customers to better monetize digital products and understand operational costs in the agentic AI era. OpenMeter offers a developer-friendly solution for real-time usage data, billing infrastructure, and feature access management, which is essential for moving beyond traditional subscription models. The integration with Kong Konnect will provide robust billing insights for AI deployments and offer a powerful usage-based billing system, positioning Kong as a unified platform for managing APIs, events, and AI services. Existing OpenMeter Cloud customers will continue to use the product as usual, and the project remains open-source under an Apache 2.0 license. Kong plans to invest more in OpenMeter's team and technology, with upcoming integrations into Kong Konnect and further announcements expected at the API Summit in October.
Sep 03, 2025 1,035 words in the original blog post.
Many organizations face challenges with API-first strategies, often misunderstanding the approach and resulting in API sprawl, poor governance, and friction among teams. Gartner research highlights the need for a dedicated API platform team, distinct from integration strategy and delivery teams, to manage API strategy and governance effectively. Treating APIs as products rather than mere project byproducts aligns them with clear business objectives, improving adoption and maintenance. AI readiness is closely tied to effective API governance, as APIs are crucial for AI agents' data consumption and action. Organizations are encouraged to shift governance from restrictive rules to enablement, allowing developers to build compliant APIs efficiently. The success of API-led initiatives depends on treating APIs as strategic assets, with governance empowering rather than hindering teams, positioning them advantageously in the evolving AI landscape.
Sep 03, 2025 1,355 words in the original blog post.
FHIR (Fast Healthcare Interoperability Resources) is a widely adopted data standard in healthcare that facilitates the exchange of health information, but the integration of SMART on FHIR, Kong Gateway, and Okta enhances the security, scalability, and usability of digital health platforms. SMART on FHIR extends FHIR by incorporating open standards like OAuth 2.0 and OpenID Connect to secure access to electronic health records, while Kong Gateway acts as a control point that validates access tokens and enforces security policies. Okta serves as the identity and access management authority, handling user authentication and token issuance. Together, these technologies create a robust, centralized security framework that ensures healthcare organizations can connect systems confidently, manage identities responsibly, and share data securely in compliance with regulations like HIPAA. Kong's plugins further enhance FHIR services by offering features like rate limiting, caching, and full observability, ensuring high availability and detailed audit trails. This combination supports a modern, interoperable health data platform that can adapt to changes in standards and regulations, positioning healthcare providers to improve outcomes while maintaining strict data privacy.
Sep 02, 2025 1,246 words in the original blog post.
API testing plays a pivotal role in ensuring the reliability, security, and performance of modern applications by validating that application programming interfaces (APIs) function correctly, seamlessly connecting software components. The process involves different types of testing—functional, security, performance, and integration—to cover all aspects of API quality. API testing is crucial in the software development life cycle for early issue detection, preventing system outages, security breaches, and user frustration. By integrating API testing into CI/CD pipelines, teams can achieve fast feedback loops and consistent quality assurance. Popular tools like Insomnia and Postman aid in managing and executing API tests efficiently, while advanced techniques, such as mocking and chaos engineering, help address the growing complexity of API testing. As APIs underpin modern digital ecosystems, adopting best practices tailored to specific industries, such as healthcare or e-commerce, is essential to meet unique requirements and regulations.
Sep 01, 2025 4,214 words in the original blog post.