Company
Date Published
Author
Michael Heap
Word count
640
Language
English
Hacker News points
None

Summary

Kong Ingress Controller 3.1 introduces several enhancements aimed at improving the security and management of sensitive information within Kubernetes environments. New Custom Resource Definitions (CRDs) such as KongVault and KongLicense have been added, allowing for more streamlined handling of secrets and licenses. The KongLicense CRD enables the application or update of licenses directly through the Kong Admin API, eliminating the need to cycle pods for updates. The KongVault CRD provides integration with various secret management solutions like AWS Secrets Manager and Hashicorp Vault, enabling runtime injection of sensitive data. Additionally, the KongPlugin configuration has been enhanced to allow individual fields to be populated from Kubernetes secrets, simplifying the configuration process for operators. Furthermore, the introduction of the SanitizeKonnectConfigDumps feature gate ensures that sensitive data like certificate private keys remain within the cluster and are not sent to Konnect. These updates collectively enhance the security and operational efficiency of using Kong Ingress Controller with Kubernetes.