1. Registry
  2. Packages
  3. Konnect Provider
  4. API Docs
  5. GatewayPluginEntitlementEnforcement
Viewing docs for konnect 3.24.0
published on Friday, Sep 25, 2026 by kong
Viewing docs for konnect 3.24.0
published on Friday, Sep 25, 2026 by kong

    GatewayPluginEntitlementEnforcement Resource

    Example Usage

    import * as pulumi from "@pulumi/pulumi";
    import * as konnect from "@pulumi/konnect";
    
    const myGatewaypluginentitlementenforcement = new konnect.GatewayPluginEntitlementEnforcement("my_gatewaypluginentitlementenforcement", {
        condition: "...my_condition...",
        config: {
            apiToken: "...my_api_token...",
            creditBalanceRequired: true,
            customer: {
                field: "...my_field...",
                lookUpValueIn: "consumer",
            },
            denyUnknownCustomers: true,
            entitlementAccessEndpoint: "...my_entitlement_access_endpoint...",
            failPolicy: "allow",
            feature: {
                key: "...my_key...",
            },
            keepalive: 60000,
            l1CacheTtlSeconds: 5,
            l2CacheTtlSeconds: 120,
            maxStaleSeconds: 60,
            redis: {
                cloudAuthentication: {
                    authProvider: "oauth",
                    awsAccessKeyId: "...my_aws_access_key_id...",
                    awsAssumeRoleArn: "...my_aws_assume_role_arn...",
                    awsCacheName: "...my_aws_cache_name...",
                    awsIsServerless: true,
                    awsRegion: "...my_aws_region...",
                    awsRoleSessionName: "...my_aws_role_session_name...",
                    awsSecretAccessKey: "...my_aws_secret_access_key...",
                    azureClientId: "...my_azure_client_id...",
                    azureClientSecret: "...my_azure_client_secret...",
                    azureTenantId: "...my_azure_tenant_id...",
                    gcpServiceAccountJson: "...my_gcp_service_account_json...",
                    oauth: {
                        authMethod: "client_secret_post",
                        clientId: "...my_client_id...",
                        clientSecret: "...my_client_secret...",
                        clientSecretJwtAlg: "HS512",
                        grantType: "client_credentials",
                        password: "...my_password...",
                        redisUsername: "...my_redis_username...",
                        redisUsernameClaim: "...my_redis_username_claim...",
                        scopes: ["..."],
                        sslVerify: true,
                        timeout: 10000,
                        tokenEndpoint: "...my_token_endpoint...",
                        tokenHeaders: {
                            key: "value",
                        },
                        tokenPostArgs: {
                            key: "value",
                        },
                        username: "...my_username...",
                    },
                },
                clusterMaxRedirections: 5,
                clusterNodes: [{
                    ip: "127.0.0.1",
                    port: 6379,
                }],
                connectTimeout: 2000,
                connectionIsProxied: false,
                database: 0,
                host: "127.0.0.1",
                keepaliveBacklog: 2020228349,
                keepalivePoolSize: 256,
                password: "...my_password...",
                port: "6379",
                readTimeout: 2000,
                sendTimeout: 2000,
                sentinelMaster: "...my_sentinel_master...",
                sentinelNodes: [{
                    host: "127.0.0.1",
                    port: 6379,
                }],
                sentinelPassword: "...my_sentinel_password...",
                sentinelRole: "master",
                sentinelUsername: "...my_sentinel_username...",
                serverName: "...my_server_name...",
                ssl: false,
                sslVerify: true,
                username: "...my_username...",
            },
            refreshInterval: 30,
            responseCodes: {
                customerNotFound: {
                    httpStatus: 403,
                    message: "Customer is not found by subject.",
                },
                featureNotFound: {
                    httpStatus: 403,
                    message: "Feature not found.",
                },
                featureUnavailable: {
                    httpStatus: 403,
                    message: "Feature is not available for the customer.",
                },
                noCreditAvailable: {
                    httpStatus: 402,
                    message: "Customer has no credit available.",
                },
                usageLimitReached: {
                    httpStatus: 429,
                    message: "Customer has reached usage limit for feature.",
                },
            },
            sslVerify: true,
            syncRate: 2,
            timeout: 10000,
        },
        consumer: {
            id: "...my_id...",
        },
        controlPlaneId: "9524ec7d-36d9-465d-a8c5-83a3c9390458",
        createdAt: 6,
        enabled: true,
        gatewayPluginEntitlementEnforcementId: "...my_id...",
        instanceName: "...my_instance_name...",
        ordering: {
            after: {
                accesses: ["..."],
            },
            before: {
                accesses: ["..."],
            },
        },
        partials: [{
            id: "...my_id...",
            name: "...my_name...",
            path: "...my_path...",
        }],
        protocols: ["http"],
        route: {
            id: "...my_id...",
        },
        service: {
            id: "...my_id...",
        },
        tags: ["..."],
        updatedAt: 9,
    });
    
    import pulumi
    import pulumi_konnect as konnect
    
    my_gatewaypluginentitlementenforcement = konnect.GatewayPluginEntitlementEnforcement("my_gatewaypluginentitlementenforcement",
        condition="...my_condition...",
        config={
            "api_token": "...my_api_token...",
            "credit_balance_required": True,
            "customer": {
                "field": "...my_field...",
                "look_up_value_in": "consumer",
            },
            "deny_unknown_customers": True,
            "entitlement_access_endpoint": "...my_entitlement_access_endpoint...",
            "fail_policy": "allow",
            "feature": {
                "key": "...my_key...",
            },
            "keepalive": 60000,
            "l1_cache_ttl_seconds": 5,
            "l2_cache_ttl_seconds": 120,
            "max_stale_seconds": 60,
            "redis": {
                "cloud_authentication": {
                    "auth_provider": "oauth",
                    "aws_access_key_id": "...my_aws_access_key_id...",
                    "aws_assume_role_arn": "...my_aws_assume_role_arn...",
                    "aws_cache_name": "...my_aws_cache_name...",
                    "aws_is_serverless": True,
                    "aws_region": "...my_aws_region...",
                    "aws_role_session_name": "...my_aws_role_session_name...",
                    "aws_secret_access_key": "...my_aws_secret_access_key...",
                    "azure_client_id": "...my_azure_client_id...",
                    "azure_client_secret": "...my_azure_client_secret...",
                    "azure_tenant_id": "...my_azure_tenant_id...",
                    "gcp_service_account_json": "...my_gcp_service_account_json...",
                    "oauth": {
                        "auth_method": "client_secret_post",
                        "client_id": "...my_client_id...",
                        "client_secret": "...my_client_secret...",
                        "client_secret_jwt_alg": "HS512",
                        "grant_type": "client_credentials",
                        "password": "...my_password...",
                        "redis_username": "...my_redis_username...",
                        "redis_username_claim": "...my_redis_username_claim...",
                        "scopes": ["..."],
                        "ssl_verify": True,
                        "timeout": 10000,
                        "token_endpoint": "...my_token_endpoint...",
                        "token_headers": {
                            "key": "value",
                        },
                        "token_post_args": {
                            "key": "value",
                        },
                        "username": "...my_username...",
                    },
                },
                "cluster_max_redirections": 5,
                "cluster_nodes": [{
                    "ip": "127.0.0.1",
                    "port": 6379,
                }],
                "connect_timeout": 2000,
                "connection_is_proxied": False,
                "database": 0,
                "host": "127.0.0.1",
                "keepalive_backlog": 2020228349,
                "keepalive_pool_size": 256,
                "password": "...my_password...",
                "port": "6379",
                "read_timeout": 2000,
                "send_timeout": 2000,
                "sentinel_master": "...my_sentinel_master...",
                "sentinel_nodes": [{
                    "host": "127.0.0.1",
                    "port": 6379,
                }],
                "sentinel_password": "...my_sentinel_password...",
                "sentinel_role": "master",
                "sentinel_username": "...my_sentinel_username...",
                "server_name": "...my_server_name...",
                "ssl": False,
                "ssl_verify": True,
                "username": "...my_username...",
            },
            "refresh_interval": 30,
            "response_codes": {
                "customer_not_found": {
                    "http_status": 403,
                    "message": "Customer is not found by subject.",
                },
                "feature_not_found": {
                    "http_status": 403,
                    "message": "Feature not found.",
                },
                "feature_unavailable": {
                    "http_status": 403,
                    "message": "Feature is not available for the customer.",
                },
                "no_credit_available": {
                    "http_status": 402,
                    "message": "Customer has no credit available.",
                },
                "usage_limit_reached": {
                    "http_status": 429,
                    "message": "Customer has reached usage limit for feature.",
                },
            },
            "ssl_verify": True,
            "sync_rate": 2,
            "timeout": 10000,
        },
        consumer={
            "id": "...my_id...",
        },
        control_plane_id="9524ec7d-36d9-465d-a8c5-83a3c9390458",
        created_at=6,
        enabled=True,
        gateway_plugin_entitlement_enforcement_id="...my_id...",
        instance_name="...my_instance_name...",
        ordering={
            "after": {
                "accesses": ["..."],
            },
            "before": {
                "accesses": ["..."],
            },
        },
        partials=[{
            "id": "...my_id...",
            "name": "...my_name...",
            "path": "...my_path...",
        }],
        protocols=["http"],
        route={
            "id": "...my_id...",
        },
        service={
            "id": "...my_id...",
        },
        tags=["..."],
        updated_at=9)
    
    package main
    
    import (
    	"github.com/pulumi/pulumi-terraform-provider/sdks/go/konnect/v3/konnect"
    	"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
    )
    
    func main() {
    	pulumi.Run(func(ctx *pulumi.Context) error {
    		_, err := konnect.NewGatewayPluginEntitlementEnforcement(ctx, "my_gatewaypluginentitlementenforcement", &konnect.GatewayPluginEntitlementEnforcementArgs{
    			Condition: pulumi.String("...my_condition..."),
    			Config: &konnect.GatewayPluginEntitlementEnforcementConfigArgs{
    				ApiToken:              pulumi.String("...my_api_token..."),
    				CreditBalanceRequired: pulumi.Bool(true),
    				Customer: &konnect.GatewayPluginEntitlementEnforcementConfigCustomerArgs{
    					Field:         pulumi.String("...my_field..."),
    					LookUpValueIn: pulumi.String("consumer"),
    				},
    				DenyUnknownCustomers:      pulumi.Bool(true),
    				EntitlementAccessEndpoint: pulumi.String("...my_entitlement_access_endpoint..."),
    				FailPolicy:                pulumi.String("allow"),
    				Feature: &konnect.GatewayPluginEntitlementEnforcementConfigFeatureArgs{
    					Key: pulumi.String("...my_key..."),
    				},
    				Keepalive:         pulumi.Float64(60000),
    				L1CacheTtlSeconds: pulumi.Float64(5),
    				L2CacheTtlSeconds: pulumi.Float64(120),
    				MaxStaleSeconds:   pulumi.Float64(60),
    				Redis: &konnect.GatewayPluginEntitlementEnforcementConfigRedisArgs{
    					CloudAuthentication: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs{
    						AuthProvider:          pulumi.String("oauth"),
    						AwsAccessKeyId:        pulumi.String("...my_aws_access_key_id..."),
    						AwsAssumeRoleArn:      pulumi.String("...my_aws_assume_role_arn..."),
    						AwsCacheName:          pulumi.String("...my_aws_cache_name..."),
    						AwsIsServerless:       pulumi.Bool(true),
    						AwsRegion:             pulumi.String("...my_aws_region..."),
    						AwsRoleSessionName:    pulumi.String("...my_aws_role_session_name..."),
    						AwsSecretAccessKey:    pulumi.String("...my_aws_secret_access_key..."),
    						AzureClientId:         pulumi.String("...my_azure_client_id..."),
    						AzureClientSecret:     pulumi.String("...my_azure_client_secret..."),
    						AzureTenantId:         pulumi.String("...my_azure_tenant_id..."),
    						GcpServiceAccountJson: pulumi.String("...my_gcp_service_account_json..."),
    						Oauth: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs{
    							AuthMethod:         pulumi.String("client_secret_post"),
    							ClientId:           pulumi.String("...my_client_id..."),
    							ClientSecret:       pulumi.String("...my_client_secret..."),
    							ClientSecretJwtAlg: pulumi.String("HS512"),
    							GrantType:          pulumi.String("client_credentials"),
    							Password:           pulumi.String("...my_password..."),
    							RedisUsername:      pulumi.String("...my_redis_username..."),
    							RedisUsernameClaim: pulumi.String("...my_redis_username_claim..."),
    							Scopes: pulumi.StringArray{
    								pulumi.String("..."),
    							},
    							SslVerify:     pulumi.Bool(true),
    							Timeout:       pulumi.Float64(10000),
    							TokenEndpoint: pulumi.String("...my_token_endpoint..."),
    							TokenHeaders: pulumi.StringMap{
    								"key": pulumi.String("value"),
    							},
    							TokenPostArgs: pulumi.StringMap{
    								"key": pulumi.String("value"),
    							},
    							Username: pulumi.String("...my_username..."),
    						},
    					},
    					ClusterMaxRedirections: pulumi.Float64(5),
    					ClusterNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArray{
    						&konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs{
    							Ip:   pulumi.String("127.0.0.1"),
    							Port: pulumi.Float64(6379),
    						},
    					},
    					ConnectTimeout:      pulumi.Float64(2000),
    					ConnectionIsProxied: pulumi.Bool(false),
    					Database:            pulumi.Float64(0),
    					Host:                pulumi.String("127.0.0.1"),
    					KeepaliveBacklog:    pulumi.Float64(2020228349),
    					KeepalivePoolSize:   pulumi.Float64(256),
    					Password:            pulumi.String("...my_password..."),
    					Port:                pulumi.String("6379"),
    					ReadTimeout:         pulumi.Float64(2000),
    					SendTimeout:         pulumi.Float64(2000),
    					SentinelMaster:      pulumi.String("...my_sentinel_master..."),
    					SentinelNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArray{
    						&konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs{
    							Host: pulumi.String("127.0.0.1"),
    							Port: pulumi.Float64(6379),
    						},
    					},
    					SentinelPassword: pulumi.String("...my_sentinel_password..."),
    					SentinelRole:     pulumi.String("master"),
    					SentinelUsername: pulumi.String("...my_sentinel_username..."),
    					ServerName:       pulumi.String("...my_server_name..."),
    					Ssl:              pulumi.Bool(false),
    					SslVerify:        pulumi.Bool(true),
    					Username:         pulumi.String("...my_username..."),
    				},
    				RefreshInterval: pulumi.Float64(30),
    				ResponseCodes: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs{
    					CustomerNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs{
    						HttpStatus: pulumi.Float64(403),
    						Message:    pulumi.String("Customer is not found by subject."),
    					},
    					FeatureNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs{
    						HttpStatus: pulumi.Float64(403),
    						Message:    pulumi.String("Feature not found."),
    					},
    					FeatureUnavailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs{
    						HttpStatus: pulumi.Float64(403),
    						Message:    pulumi.String("Feature is not available for the customer."),
    					},
    					NoCreditAvailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs{
    						HttpStatus: pulumi.Float64(402),
    						Message:    pulumi.String("Customer has no credit available."),
    					},
    					UsageLimitReached: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs{
    						HttpStatus: pulumi.Float64(429),
    						Message:    pulumi.String("Customer has reached usage limit for feature."),
    					},
    				},
    				SslVerify: pulumi.Bool(true),
    				SyncRate:  pulumi.Float64(2),
    				Timeout:   pulumi.Float64(10000),
    			},
    			Consumer: &konnect.GatewayPluginEntitlementEnforcementConsumerArgs{
    				Id: pulumi.String("...my_id..."),
    			},
    			ControlPlaneId:                        pulumi.String("9524ec7d-36d9-465d-a8c5-83a3c9390458"),
    			CreatedAt:                             pulumi.Float64(6),
    			Enabled:                               pulumi.Bool(true),
    			GatewayPluginEntitlementEnforcementId: pulumi.String("...my_id..."),
    			InstanceName:                          pulumi.String("...my_instance_name..."),
    			Ordering: &konnect.GatewayPluginEntitlementEnforcementOrderingArgs{
    				After: &konnect.GatewayPluginEntitlementEnforcementOrderingAfterArgs{
    					Accesses: pulumi.StringArray{
    						pulumi.String("..."),
    					},
    				},
    				Before: &konnect.GatewayPluginEntitlementEnforcementOrderingBeforeArgs{
    					Accesses: pulumi.StringArray{
    						pulumi.String("..."),
    					},
    				},
    			},
    			Partials: konnect.GatewayPluginEntitlementEnforcementPartialArray{
    				&konnect.GatewayPluginEntitlementEnforcementPartialArgs{
    					Id:   pulumi.String("...my_id..."),
    					Name: pulumi.String("...my_name..."),
    					Path: pulumi.String("...my_path..."),
    				},
    			},
    			Protocols: pulumi.StringArray{
    				pulumi.String("http"),
    			},
    			Route: &konnect.GatewayPluginEntitlementEnforcementRouteArgs{
    				Id: pulumi.String("...my_id..."),
    			},
    			Service: &konnect.GatewayPluginEntitlementEnforcementServiceArgs{
    				Id: pulumi.String("...my_id..."),
    			},
    			Tags: pulumi.StringArray{
    				pulumi.String("..."),
    			},
    			UpdatedAt: pulumi.Float64(9),
    		})
    		if err != nil {
    			return err
    		}
    		return nil
    	})
    }
    
    using System.Collections.Generic;
    using System.Linq;
    using Pulumi;
    using Konnect = Pulumi.Konnect;
    
    return await Deployment.RunAsync(() => 
    {
        var myGatewaypluginentitlementenforcement = new Konnect.GatewayPluginEntitlementEnforcement("my_gatewaypluginentitlementenforcement", new()
        {
            Condition = "...my_condition...",
            Config = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigArgs
            {
                ApiToken = "...my_api_token...",
                CreditBalanceRequired = true,
                Customer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigCustomerArgs
                {
                    Field = "...my_field...",
                    LookUpValueIn = "consumer",
                },
                DenyUnknownCustomers = true,
                EntitlementAccessEndpoint = "...my_entitlement_access_endpoint...",
                FailPolicy = "allow",
                Feature = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigFeatureArgs
                {
                    Key = "...my_key...",
                },
                Keepalive = 60000,
                L1CacheTtlSeconds = 5,
                L2CacheTtlSeconds = 120,
                MaxStaleSeconds = 60,
                Redis = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisArgs
                {
                    CloudAuthentication = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs
                    {
                        AuthProvider = "oauth",
                        AwsAccessKeyId = "...my_aws_access_key_id...",
                        AwsAssumeRoleArn = "...my_aws_assume_role_arn...",
                        AwsCacheName = "...my_aws_cache_name...",
                        AwsIsServerless = true,
                        AwsRegion = "...my_aws_region...",
                        AwsRoleSessionName = "...my_aws_role_session_name...",
                        AwsSecretAccessKey = "...my_aws_secret_access_key...",
                        AzureClientId = "...my_azure_client_id...",
                        AzureClientSecret = "...my_azure_client_secret...",
                        AzureTenantId = "...my_azure_tenant_id...",
                        GcpServiceAccountJson = "...my_gcp_service_account_json...",
                        Oauth = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs
                        {
                            AuthMethod = "client_secret_post",
                            ClientId = "...my_client_id...",
                            ClientSecret = "...my_client_secret...",
                            ClientSecretJwtAlg = "HS512",
                            GrantType = "client_credentials",
                            Password = "...my_password...",
                            RedisUsername = "...my_redis_username...",
                            RedisUsernameClaim = "...my_redis_username_claim...",
                            Scopes = new[]
                            {
                                "...",
                            },
                            SslVerify = true,
                            Timeout = 10000,
                            TokenEndpoint = "...my_token_endpoint...",
                            TokenHeaders = 
                            {
                                { "key", "value" },
                            },
                            TokenPostArgs = 
                            {
                                { "key", "value" },
                            },
                            Username = "...my_username...",
                        },
                    },
                    ClusterMaxRedirections = 5,
                    ClusterNodes = new[]
                    {
                        new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs
                        {
                            Ip = "127.0.0.1",
                            Port = 6379,
                        },
                    },
                    ConnectTimeout = 2000,
                    ConnectionIsProxied = false,
                    Database = 0,
                    Host = "127.0.0.1",
                    KeepaliveBacklog = 2020228349,
                    KeepalivePoolSize = 256,
                    Password = "...my_password...",
                    Port = "6379",
                    ReadTimeout = 2000,
                    SendTimeout = 2000,
                    SentinelMaster = "...my_sentinel_master...",
                    SentinelNodes = new[]
                    {
                        new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs
                        {
                            Host = "127.0.0.1",
                            Port = 6379,
                        },
                    },
                    SentinelPassword = "...my_sentinel_password...",
                    SentinelRole = "master",
                    SentinelUsername = "...my_sentinel_username...",
                    ServerName = "...my_server_name...",
                    Ssl = false,
                    SslVerify = true,
                    Username = "...my_username...",
                },
                RefreshInterval = 30,
                ResponseCodes = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs
                {
                    CustomerNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs
                    {
                        HttpStatus = 403,
                        Message = "Customer is not found by subject.",
                    },
                    FeatureNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs
                    {
                        HttpStatus = 403,
                        Message = "Feature not found.",
                    },
                    FeatureUnavailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs
                    {
                        HttpStatus = 403,
                        Message = "Feature is not available for the customer.",
                    },
                    NoCreditAvailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs
                    {
                        HttpStatus = 402,
                        Message = "Customer has no credit available.",
                    },
                    UsageLimitReached = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs
                    {
                        HttpStatus = 429,
                        Message = "Customer has reached usage limit for feature.",
                    },
                },
                SslVerify = true,
                SyncRate = 2,
                Timeout = 10000,
            },
            Consumer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConsumerArgs
            {
                Id = "...my_id...",
            },
            ControlPlaneId = "9524ec7d-36d9-465d-a8c5-83a3c9390458",
            CreatedAt = 6,
            Enabled = true,
            GatewayPluginEntitlementEnforcementId = "...my_id...",
            InstanceName = "...my_instance_name...",
            Ordering = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingArgs
            {
                After = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingAfterArgs
                {
                    Accesses = new[]
                    {
                        "...",
                    },
                },
                Before = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingBeforeArgs
                {
                    Accesses = new[]
                    {
                        "...",
                    },
                },
            },
            Partials = new[]
            {
                new Konnect.Inputs.GatewayPluginEntitlementEnforcementPartialArgs
                {
                    Id = "...my_id...",
                    Name = "...my_name...",
                    Path = "...my_path...",
                },
            },
            Protocols = new[]
            {
                "http",
            },
            Route = new Konnect.Inputs.GatewayPluginEntitlementEnforcementRouteArgs
            {
                Id = "...my_id...",
            },
            Service = new Konnect.Inputs.GatewayPluginEntitlementEnforcementServiceArgs
            {
                Id = "...my_id...",
            },
            Tags = new[]
            {
                "...",
            },
            UpdatedAt = 9,
        });
    
    });
    
    package generated_program;
    
    import com.pulumi.Context;
    import com.pulumi.Pulumi;
    import com.pulumi.core.Output;
    import com.pulumi.konnect.GatewayPluginEntitlementEnforcement;
    import com.pulumi.konnect.GatewayPluginEntitlementEnforcementArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigCustomerArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigFeatureArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigRedisArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConsumerArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementOrderingArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementOrderingAfterArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementOrderingBeforeArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementPartialArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementRouteArgs;
    import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementServiceArgs;
    import java.util.List;
    import java.util.ArrayList;
    import java.util.Map;
    import java.io.File;
    import java.nio.file.Files;
    import java.nio.file.Paths;
    
    public class App {
        public static void main(String[] args) {
            Pulumi.run(App::stack);
        }
    
        public static void stack(Context ctx) {
            var myGatewaypluginentitlementenforcement = new GatewayPluginEntitlementEnforcement("myGatewaypluginentitlementenforcement", GatewayPluginEntitlementEnforcementArgs.builder()
                .condition("...my_condition...")
                .config(GatewayPluginEntitlementEnforcementConfigArgs.builder()
                    .apiToken("...my_api_token...")
                    .creditBalanceRequired(true)
                    .customer(GatewayPluginEntitlementEnforcementConfigCustomerArgs.builder()
                        .field("...my_field...")
                        .lookUpValueIn("consumer")
                        .build())
                    .denyUnknownCustomers(true)
                    .entitlementAccessEndpoint("...my_entitlement_access_endpoint...")
                    .failPolicy("allow")
                    .feature(GatewayPluginEntitlementEnforcementConfigFeatureArgs.builder()
                        .key("...my_key...")
                        .build())
                    .keepalive(60000.0)
                    .l1CacheTtlSeconds(5.0)
                    .l2CacheTtlSeconds(120.0)
                    .maxStaleSeconds(60.0)
                    .redis(GatewayPluginEntitlementEnforcementConfigRedisArgs.builder()
                        .cloudAuthentication(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs.builder()
                            .authProvider("oauth")
                            .awsAccessKeyId("...my_aws_access_key_id...")
                            .awsAssumeRoleArn("...my_aws_assume_role_arn...")
                            .awsCacheName("...my_aws_cache_name...")
                            .awsIsServerless(true)
                            .awsRegion("...my_aws_region...")
                            .awsRoleSessionName("...my_aws_role_session_name...")
                            .awsSecretAccessKey("...my_aws_secret_access_key...")
                            .azureClientId("...my_azure_client_id...")
                            .azureClientSecret("...my_azure_client_secret...")
                            .azureTenantId("...my_azure_tenant_id...")
                            .gcpServiceAccountJson("...my_gcp_service_account_json...")
                            .oauth(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs.builder()
                                .authMethod("client_secret_post")
                                .clientId("...my_client_id...")
                                .clientSecret("...my_client_secret...")
                                .clientSecretJwtAlg("HS512")
                                .grantType("client_credentials")
                                .password("...my_password...")
                                .redisUsername("...my_redis_username...")
                                .redisUsernameClaim("...my_redis_username_claim...")
                                .scopes("...")
                                .sslVerify(true)
                                .timeout(10000.0)
                                .tokenEndpoint("...my_token_endpoint...")
                                .tokenHeaders(Map.of("key", "value"))
                                .tokenPostArgs(Map.of("key", "value"))
                                .username("...my_username...")
                                .build())
                            .build())
                        .clusterMaxRedirections(5.0)
                        .clusterNodes(GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs.builder()
                            .ip("127.0.0.1")
                            .port(6379.0)
                            .build())
                        .connectTimeout(2000.0)
                        .connectionIsProxied(false)
                        .database(0.0)
                        .host("127.0.0.1")
                        .keepaliveBacklog(2020228349.0)
                        .keepalivePoolSize(256.0)
                        .password("...my_password...")
                        .port("6379")
                        .readTimeout(2000.0)
                        .sendTimeout(2000.0)
                        .sentinelMaster("...my_sentinel_master...")
                        .sentinelNodes(GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs.builder()
                            .host("127.0.0.1")
                            .port(6379.0)
                            .build())
                        .sentinelPassword("...my_sentinel_password...")
                        .sentinelRole("master")
                        .sentinelUsername("...my_sentinel_username...")
                        .serverName("...my_server_name...")
                        .ssl(false)
                        .sslVerify(true)
                        .username("...my_username...")
                        .build())
                    .refreshInterval(30.0)
                    .responseCodes(GatewayPluginEntitlementEnforcementConfigResponseCodesArgs.builder()
                        .customerNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs.builder()
                            .httpStatus(403.0)
                            .message("Customer is not found by subject.")
                            .build())
                        .featureNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs.builder()
                            .httpStatus(403.0)
                            .message("Feature not found.")
                            .build())
                        .featureUnavailable(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs.builder()
                            .httpStatus(403.0)
                            .message("Feature is not available for the customer.")
                            .build())
                        .noCreditAvailable(GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs.builder()
                            .httpStatus(402.0)
                            .message("Customer has no credit available.")
                            .build())
                        .usageLimitReached(GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs.builder()
                            .httpStatus(429.0)
                            .message("Customer has reached usage limit for feature.")
                            .build())
                        .build())
                    .sslVerify(true)
                    .syncRate(2.0)
                    .timeout(10000.0)
                    .build())
                .consumer(GatewayPluginEntitlementEnforcementConsumerArgs.builder()
                    .id("...my_id...")
                    .build())
                .controlPlaneId("9524ec7d-36d9-465d-a8c5-83a3c9390458")
                .createdAt(6.0)
                .enabled(true)
                .gatewayPluginEntitlementEnforcementId("...my_id...")
                .instanceName("...my_instance_name...")
                .ordering(GatewayPluginEntitlementEnforcementOrderingArgs.builder()
                    .after(GatewayPluginEntitlementEnforcementOrderingAfterArgs.builder()
                        .accesses("...")
                        .build())
                    .before(GatewayPluginEntitlementEnforcementOrderingBeforeArgs.builder()
                        .accesses("...")
                        .build())
                    .build())
                .partials(GatewayPluginEntitlementEnforcementPartialArgs.builder()
                    .id("...my_id...")
                    .name("...my_name...")
                    .path("...my_path...")
                    .build())
                .protocols("http")
                .route(GatewayPluginEntitlementEnforcementRouteArgs.builder()
                    .id("...my_id...")
                    .build())
                .service(GatewayPluginEntitlementEnforcementServiceArgs.builder()
                    .id("...my_id...")
                    .build())
                .tags("...")
                .updatedAt(9.0)
                .build());
    
        }
    }
    
    resources:
      myGatewaypluginentitlementenforcement:
        type: konnect:GatewayPluginEntitlementEnforcement
        name: my_gatewaypluginentitlementenforcement
        properties:
          condition: '...my_condition...'
          config:
            apiToken: '...my_api_token...'
            creditBalanceRequired: true
            customer:
              field: '...my_field...'
              lookUpValueIn: consumer
            denyUnknownCustomers: true
            entitlementAccessEndpoint: '...my_entitlement_access_endpoint...'
            failPolicy: allow
            feature:
              key: '...my_key...'
            keepalive: 60000
            l1CacheTtlSeconds: 5
            l2CacheTtlSeconds: 120
            maxStaleSeconds: 60
            redis:
              cloudAuthentication:
                authProvider: oauth
                awsAccessKeyId: '...my_aws_access_key_id...'
                awsAssumeRoleArn: '...my_aws_assume_role_arn...'
                awsCacheName: '...my_aws_cache_name...'
                awsIsServerless: true
                awsRegion: '...my_aws_region...'
                awsRoleSessionName: '...my_aws_role_session_name...'
                awsSecretAccessKey: '...my_aws_secret_access_key...'
                azureClientId: '...my_azure_client_id...'
                azureClientSecret: '...my_azure_client_secret...'
                azureTenantId: '...my_azure_tenant_id...'
                gcpServiceAccountJson: '...my_gcp_service_account_json...'
                oauth:
                  authMethod: client_secret_post
                  clientId: '...my_client_id...'
                  clientSecret: '...my_client_secret...'
                  clientSecretJwtAlg: HS512
                  grantType: client_credentials
                  password: '...my_password...'
                  redisUsername: '...my_redis_username...'
                  redisUsernameClaim: '...my_redis_username_claim...'
                  scopes:
                    - '...'
                  sslVerify: true
                  timeout: 10000
                  tokenEndpoint: '...my_token_endpoint...'
                  tokenHeaders:
                    key: value
                  tokenPostArgs:
                    key: value
                  username: '...my_username...'
              clusterMaxRedirections: 5
              clusterNodes:
                - ip: 127.0.0.1
                  port: 6379
              connectTimeout: 2000
              connectionIsProxied: false
              database: 0
              host: 127.0.0.1
              keepaliveBacklog: 2.020228349e+09
              keepalivePoolSize: 256
              password: '...my_password...'
              port: '6379'
              readTimeout: 2000
              sendTimeout: 2000
              sentinelMaster: '...my_sentinel_master...'
              sentinelNodes:
                - host: 127.0.0.1
                  port: 6379
              sentinelPassword: '...my_sentinel_password...'
              sentinelRole: master
              sentinelUsername: '...my_sentinel_username...'
              serverName: '...my_server_name...'
              ssl: false
              sslVerify: true
              username: '...my_username...'
            refreshInterval: 30
            responseCodes:
              customerNotFound:
                httpStatus: 403
                message: Customer is not found by subject.
              featureNotFound:
                httpStatus: 403
                message: Feature not found.
              featureUnavailable:
                httpStatus: 403
                message: Feature is not available for the customer.
              noCreditAvailable:
                httpStatus: 402
                message: Customer has no credit available.
              usageLimitReached:
                httpStatus: 429
                message: Customer has reached usage limit for feature.
            sslVerify: true
            syncRate: 2
            timeout: 10000
          consumer:
            id: '...my_id...'
          controlPlaneId: 9524ec7d-36d9-465d-a8c5-83a3c9390458
          createdAt: 6
          enabled: true
          gatewayPluginEntitlementEnforcementId: '...my_id...'
          instanceName: '...my_instance_name...'
          ordering:
            after:
              accesses:
                - '...'
            before:
              accesses:
                - '...'
          partials:
            - id: '...my_id...'
              name: '...my_name...'
              path: '...my_path...'
          protocols:
            - http
          route:
            id: '...my_id...'
          service:
            id: '...my_id...'
          tags:
            - '...'
          updatedAt: 9
    
    Example coming soon!
    

    Create GatewayPluginEntitlementEnforcement Resource

    Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.

    Constructor syntax

    new GatewayPluginEntitlementEnforcement(name: string, args: GatewayPluginEntitlementEnforcementArgs, opts?: CustomResourceOptions);
    @overload
    def GatewayPluginEntitlementEnforcement(resource_name: str,
                                            args: GatewayPluginEntitlementEnforcementArgs,
                                            opts: Optional[ResourceOptions] = None)
    
    @overload
    def GatewayPluginEntitlementEnforcement(resource_name: str,
                                            opts: Optional[ResourceOptions] = None,
                                            control_plane_id: Optional[str] = None,
                                            config: Optional[GatewayPluginEntitlementEnforcementConfigArgs] = None,
                                            gateway_plugin_entitlement_enforcement_id: Optional[str] = None,
                                            consumer: Optional[GatewayPluginEntitlementEnforcementConsumerArgs] = None,
                                            created_at: Optional[float] = None,
                                            enabled: Optional[bool] = None,
                                            condition: Optional[str] = None,
                                            instance_name: Optional[str] = None,
                                            ordering: Optional[GatewayPluginEntitlementEnforcementOrderingArgs] = None,
                                            partials: Optional[Sequence[GatewayPluginEntitlementEnforcementPartialArgs]] = None,
                                            protocols: Optional[Sequence[str]] = None,
                                            route: Optional[GatewayPluginEntitlementEnforcementRouteArgs] = None,
                                            service: Optional[GatewayPluginEntitlementEnforcementServiceArgs] = None,
                                            tags: Optional[Sequence[str]] = None,
                                            updated_at: Optional[float] = None)
    func NewGatewayPluginEntitlementEnforcement(ctx *Context, name string, args GatewayPluginEntitlementEnforcementArgs, opts ...ResourceOption) (*GatewayPluginEntitlementEnforcement, error)
    public GatewayPluginEntitlementEnforcement(string name, GatewayPluginEntitlementEnforcementArgs args, CustomResourceOptions? opts = null)
    public GatewayPluginEntitlementEnforcement(String name, GatewayPluginEntitlementEnforcementArgs args)
    public GatewayPluginEntitlementEnforcement(String name, GatewayPluginEntitlementEnforcementArgs args, CustomResourceOptions options)
    
    type: konnect:GatewayPluginEntitlementEnforcement
    properties: # The arguments to resource properties.
    options: # Bag of options to control resource's behavior.
    
    
    resource "konnect_gateway_plugin_entitlement_enforcement" "name" {
        # resource properties
    }

    Parameters

    name string
    The unique name of the resource.
    args GatewayPluginEntitlementEnforcementArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    resource_name str
    The unique name of the resource.
    args GatewayPluginEntitlementEnforcementArgs
    The arguments to resource properties.
    opts ResourceOptions
    Bag of options to control resource's behavior.
    ctx Context
    Context object for the current deployment.
    name string
    The unique name of the resource.
    args GatewayPluginEntitlementEnforcementArgs
    The arguments to resource properties.
    opts ResourceOption
    Bag of options to control resource's behavior.
    name string
    The unique name of the resource.
    args GatewayPluginEntitlementEnforcementArgs
    The arguments to resource properties.
    opts CustomResourceOptions
    Bag of options to control resource's behavior.
    name String
    The unique name of the resource.
    args GatewayPluginEntitlementEnforcementArgs
    The arguments to resource properties.
    options CustomResourceOptions
    Bag of options to control resource's behavior.

    Constructor example

    The following reference example uses placeholder values for all input properties.

    var gatewayPluginEntitlementEnforcementResource = new Konnect.GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource", new()
    {
        ControlPlaneId = "string",
        Config = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigArgs
        {
            EntitlementAccessEndpoint = "string",
            ApiToken = "string",
            Feature = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigFeatureArgs
            {
                Key = "string",
            },
            L1CacheTtlSeconds = 0.0,
            MaxStaleSeconds = 0.0,
            FailPolicy = "string",
            Customer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigCustomerArgs
            {
                Field = "string",
                LookUpValueIn = "string",
            },
            Keepalive = 0.0,
            CreditBalanceRequired = false,
            L2CacheTtlSeconds = 0.0,
            DenyUnknownCustomers = false,
            Redis = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisArgs
            {
                CloudAuthentication = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs
                {
                    AuthProvider = "string",
                    AwsAccessKeyId = "string",
                    AwsAssumeRoleArn = "string",
                    AwsCacheName = "string",
                    AwsIsServerless = false,
                    AwsRegion = "string",
                    AwsRoleSessionName = "string",
                    AwsSecretAccessKey = "string",
                    AzureClientId = "string",
                    AzureClientSecret = "string",
                    AzureTenantId = "string",
                    GcpServiceAccountJson = "string",
                    Oauth = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs
                    {
                        AuthMethod = "string",
                        ClientId = "string",
                        ClientSecret = "string",
                        ClientSecretJwtAlg = "string",
                        GrantType = "string",
                        Password = "string",
                        RedisUsername = "string",
                        RedisUsernameClaim = "string",
                        Scopes = new[]
                        {
                            "string",
                        },
                        SslVerify = false,
                        Timeout = 0.0,
                        TokenEndpoint = "string",
                        TokenHeaders = 
                        {
                            { "string", "string" },
                        },
                        TokenPostArgs = 
                        {
                            { "string", "string" },
                        },
                        Username = "string",
                    },
                },
                ClusterMaxRedirections = 0.0,
                ClusterNodes = new[]
                {
                    new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs
                    {
                        Ip = "string",
                        Port = 0.0,
                    },
                },
                ConnectTimeout = 0.0,
                ConnectionIsProxied = false,
                Database = 0.0,
                Host = "string",
                KeepaliveBacklog = 0.0,
                KeepalivePoolSize = 0.0,
                Password = "string",
                Port = "string",
                ReadTimeout = 0.0,
                SendTimeout = 0.0,
                SentinelMaster = "string",
                SentinelNodes = new[]
                {
                    new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs
                    {
                        Host = "string",
                        Port = 0.0,
                    },
                },
                SentinelPassword = "string",
                SentinelRole = "string",
                SentinelUsername = "string",
                ServerName = "string",
                Ssl = false,
                SslVerify = false,
                Username = "string",
            },
            RefreshInterval = 0.0,
            ResponseCodes = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs
            {
                CustomerNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs
                {
                    HttpStatus = 0.0,
                    Message = "string",
                },
                FeatureNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs
                {
                    HttpStatus = 0.0,
                    Message = "string",
                },
                FeatureUnavailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs
                {
                    HttpStatus = 0.0,
                    Message = "string",
                },
                NoCreditAvailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs
                {
                    HttpStatus = 0.0,
                    Message = "string",
                },
                UsageLimitReached = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs
                {
                    HttpStatus = 0.0,
                    Message = "string",
                },
            },
            SslVerify = false,
            SyncRate = 0.0,
            Timeout = 0.0,
        },
        GatewayPluginEntitlementEnforcementId = "string",
        Consumer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConsumerArgs
        {
            Id = "string",
        },
        CreatedAt = 0.0,
        Enabled = false,
        Condition = "string",
        InstanceName = "string",
        Ordering = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingArgs
        {
            After = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingAfterArgs
            {
                Accesses = new[]
                {
                    "string",
                },
            },
            Before = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingBeforeArgs
            {
                Accesses = new[]
                {
                    "string",
                },
            },
        },
        Partials = new[]
        {
            new Konnect.Inputs.GatewayPluginEntitlementEnforcementPartialArgs
            {
                Id = "string",
                Name = "string",
                Path = "string",
            },
        },
        Protocols = new[]
        {
            "string",
        },
        Route = new Konnect.Inputs.GatewayPluginEntitlementEnforcementRouteArgs
        {
            Id = "string",
        },
        Service = new Konnect.Inputs.GatewayPluginEntitlementEnforcementServiceArgs
        {
            Id = "string",
        },
        Tags = new[]
        {
            "string",
        },
        UpdatedAt = 0.0,
    });
    
    example, err := konnect.NewGatewayPluginEntitlementEnforcement(ctx, "gatewayPluginEntitlementEnforcementResource", &konnect.GatewayPluginEntitlementEnforcementArgs{
    	ControlPlaneId: pulumi.String("string"),
    	Config: &konnect.GatewayPluginEntitlementEnforcementConfigArgs{
    		EntitlementAccessEndpoint: pulumi.String("string"),
    		ApiToken:                  pulumi.String("string"),
    		Feature: &konnect.GatewayPluginEntitlementEnforcementConfigFeatureArgs{
    			Key: pulumi.String("string"),
    		},
    		L1CacheTtlSeconds: pulumi.Float64(0),
    		MaxStaleSeconds:   pulumi.Float64(0),
    		FailPolicy:        pulumi.String("string"),
    		Customer: &konnect.GatewayPluginEntitlementEnforcementConfigCustomerArgs{
    			Field:         pulumi.String("string"),
    			LookUpValueIn: pulumi.String("string"),
    		},
    		Keepalive:             pulumi.Float64(0),
    		CreditBalanceRequired: pulumi.Bool(false),
    		L2CacheTtlSeconds:     pulumi.Float64(0),
    		DenyUnknownCustomers:  pulumi.Bool(false),
    		Redis: &konnect.GatewayPluginEntitlementEnforcementConfigRedisArgs{
    			CloudAuthentication: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs{
    				AuthProvider:          pulumi.String("string"),
    				AwsAccessKeyId:        pulumi.String("string"),
    				AwsAssumeRoleArn:      pulumi.String("string"),
    				AwsCacheName:          pulumi.String("string"),
    				AwsIsServerless:       pulumi.Bool(false),
    				AwsRegion:             pulumi.String("string"),
    				AwsRoleSessionName:    pulumi.String("string"),
    				AwsSecretAccessKey:    pulumi.String("string"),
    				AzureClientId:         pulumi.String("string"),
    				AzureClientSecret:     pulumi.String("string"),
    				AzureTenantId:         pulumi.String("string"),
    				GcpServiceAccountJson: pulumi.String("string"),
    				Oauth: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs{
    					AuthMethod:         pulumi.String("string"),
    					ClientId:           pulumi.String("string"),
    					ClientSecret:       pulumi.String("string"),
    					ClientSecretJwtAlg: pulumi.String("string"),
    					GrantType:          pulumi.String("string"),
    					Password:           pulumi.String("string"),
    					RedisUsername:      pulumi.String("string"),
    					RedisUsernameClaim: pulumi.String("string"),
    					Scopes: pulumi.StringArray{
    						pulumi.String("string"),
    					},
    					SslVerify:     pulumi.Bool(false),
    					Timeout:       pulumi.Float64(0),
    					TokenEndpoint: pulumi.String("string"),
    					TokenHeaders: pulumi.StringMap{
    						"string": pulumi.String("string"),
    					},
    					TokenPostArgs: pulumi.StringMap{
    						"string": pulumi.String("string"),
    					},
    					Username: pulumi.String("string"),
    				},
    			},
    			ClusterMaxRedirections: pulumi.Float64(0),
    			ClusterNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArray{
    				&konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs{
    					Ip:   pulumi.String("string"),
    					Port: pulumi.Float64(0),
    				},
    			},
    			ConnectTimeout:      pulumi.Float64(0),
    			ConnectionIsProxied: pulumi.Bool(false),
    			Database:            pulumi.Float64(0),
    			Host:                pulumi.String("string"),
    			KeepaliveBacklog:    pulumi.Float64(0),
    			KeepalivePoolSize:   pulumi.Float64(0),
    			Password:            pulumi.String("string"),
    			Port:                pulumi.String("string"),
    			ReadTimeout:         pulumi.Float64(0),
    			SendTimeout:         pulumi.Float64(0),
    			SentinelMaster:      pulumi.String("string"),
    			SentinelNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArray{
    				&konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs{
    					Host: pulumi.String("string"),
    					Port: pulumi.Float64(0),
    				},
    			},
    			SentinelPassword: pulumi.String("string"),
    			SentinelRole:     pulumi.String("string"),
    			SentinelUsername: pulumi.String("string"),
    			ServerName:       pulumi.String("string"),
    			Ssl:              pulumi.Bool(false),
    			SslVerify:        pulumi.Bool(false),
    			Username:         pulumi.String("string"),
    		},
    		RefreshInterval: pulumi.Float64(0),
    		ResponseCodes: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs{
    			CustomerNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs{
    				HttpStatus: pulumi.Float64(0),
    				Message:    pulumi.String("string"),
    			},
    			FeatureNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs{
    				HttpStatus: pulumi.Float64(0),
    				Message:    pulumi.String("string"),
    			},
    			FeatureUnavailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs{
    				HttpStatus: pulumi.Float64(0),
    				Message:    pulumi.String("string"),
    			},
    			NoCreditAvailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs{
    				HttpStatus: pulumi.Float64(0),
    				Message:    pulumi.String("string"),
    			},
    			UsageLimitReached: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs{
    				HttpStatus: pulumi.Float64(0),
    				Message:    pulumi.String("string"),
    			},
    		},
    		SslVerify: pulumi.Bool(false),
    		SyncRate:  pulumi.Float64(0),
    		Timeout:   pulumi.Float64(0),
    	},
    	GatewayPluginEntitlementEnforcementId: pulumi.String("string"),
    	Consumer: &konnect.GatewayPluginEntitlementEnforcementConsumerArgs{
    		Id: pulumi.String("string"),
    	},
    	CreatedAt:    pulumi.Float64(0),
    	Enabled:      pulumi.Bool(false),
    	Condition:    pulumi.String("string"),
    	InstanceName: pulumi.String("string"),
    	Ordering: &konnect.GatewayPluginEntitlementEnforcementOrderingArgs{
    		After: &konnect.GatewayPluginEntitlementEnforcementOrderingAfterArgs{
    			Accesses: pulumi.StringArray{
    				pulumi.String("string"),
    			},
    		},
    		Before: &konnect.GatewayPluginEntitlementEnforcementOrderingBeforeArgs{
    			Accesses: pulumi.StringArray{
    				pulumi.String("string"),
    			},
    		},
    	},
    	Partials: konnect.GatewayPluginEntitlementEnforcementPartialArray{
    		&konnect.GatewayPluginEntitlementEnforcementPartialArgs{
    			Id:   pulumi.String("string"),
    			Name: pulumi.String("string"),
    			Path: pulumi.String("string"),
    		},
    	},
    	Protocols: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	Route: &konnect.GatewayPluginEntitlementEnforcementRouteArgs{
    		Id: pulumi.String("string"),
    	},
    	Service: &konnect.GatewayPluginEntitlementEnforcementServiceArgs{
    		Id: pulumi.String("string"),
    	},
    	Tags: pulumi.StringArray{
    		pulumi.String("string"),
    	},
    	UpdatedAt: pulumi.Float64(0),
    })
    
    resource "konnect_gateway_plugin_entitlement_enforcement" "gatewayPluginEntitlementEnforcementResource" {
      lifecycle {
        create_before_destroy = true
      }
      control_plane_id = "string"
      config = {
        entitlement_access_endpoint = "string"
        api_token                   = "string"
        feature = {
          key = "string"
        }
        l1_cache_ttl_seconds = 0
        max_stale_seconds    = 0
        fail_policy          = "string"
        customer = {
          field            = "string"
          look_up_value_in = "string"
        }
        keepalive               = 0
        credit_balance_required = false
        l2_cache_ttl_seconds    = 0
        deny_unknown_customers  = false
        redis = {
          cloud_authentication = {
            auth_provider            = "string"
            aws_access_key_id        = "string"
            aws_assume_role_arn      = "string"
            aws_cache_name           = "string"
            aws_is_serverless        = false
            aws_region               = "string"
            aws_role_session_name    = "string"
            aws_secret_access_key    = "string"
            azure_client_id          = "string"
            azure_client_secret      = "string"
            azure_tenant_id          = "string"
            gcp_service_account_json = "string"
            oauth = {
              auth_method           = "string"
              client_id             = "string"
              client_secret         = "string"
              client_secret_jwt_alg = "string"
              grant_type            = "string"
              password              = "string"
              redis_username        = "string"
              redis_username_claim  = "string"
              scopes                = ["string"]
              ssl_verify            = false
              timeout               = 0
              token_endpoint        = "string"
              token_headers = {
                "string" = "string"
              }
              token_post_args = {
                "string" = "string"
              }
              username = "string"
            }
          }
          cluster_max_redirections = 0
          cluster_nodes = [{
            ip   = "string"
            port = 0
          }]
          connect_timeout       = 0
          connection_is_proxied = false
          database              = 0
          host                  = "string"
          keepalive_backlog     = 0
          keepalive_pool_size   = 0
          password              = "string"
          port                  = "string"
          read_timeout          = 0
          send_timeout          = 0
          sentinel_master       = "string"
          sentinel_nodes = [{
            host = "string"
            port = 0
          }]
          sentinel_password = "string"
          sentinel_role     = "string"
          sentinel_username = "string"
          server_name       = "string"
          ssl               = false
          ssl_verify        = false
          username          = "string"
        }
        refresh_interval = 0
        response_codes = {
          customer_not_found = {
            http_status = 0
            message     = "string"
          }
          feature_not_found = {
            http_status = 0
            message     = "string"
          }
          feature_unavailable = {
            http_status = 0
            message     = "string"
          }
          no_credit_available = {
            http_status = 0
            message     = "string"
          }
          usage_limit_reached = {
            http_status = 0
            message     = "string"
          }
        }
        ssl_verify = false
        sync_rate  = 0
        timeout    = 0
      }
      gateway_plugin_entitlement_enforcement_id = "string"
      consumer = {
        id = "string"
      }
      created_at    = 0
      enabled       = false
      condition     = "string"
      instance_name = "string"
      ordering = {
        after = {
          accesses = ["string"]
        }
        before = {
          accesses = ["string"]
        }
      }
      partials {
        id   = "string"
        name = "string"
        path = "string"
      }
      protocols = ["string"]
      route = {
        id = "string"
      }
      service = {
        id = "string"
      }
      tags       = ["string"]
      updated_at = 0
    }
    
    var gatewayPluginEntitlementEnforcementResource = new GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource", GatewayPluginEntitlementEnforcementArgs.builder()
        .controlPlaneId("string")
        .config(GatewayPluginEntitlementEnforcementConfigArgs.builder()
            .entitlementAccessEndpoint("string")
            .apiToken("string")
            .feature(GatewayPluginEntitlementEnforcementConfigFeatureArgs.builder()
                .key("string")
                .build())
            .l1CacheTtlSeconds(0.0)
            .maxStaleSeconds(0.0)
            .failPolicy("string")
            .customer(GatewayPluginEntitlementEnforcementConfigCustomerArgs.builder()
                .field("string")
                .lookUpValueIn("string")
                .build())
            .keepalive(0.0)
            .creditBalanceRequired(false)
            .l2CacheTtlSeconds(0.0)
            .denyUnknownCustomers(false)
            .redis(GatewayPluginEntitlementEnforcementConfigRedisArgs.builder()
                .cloudAuthentication(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs.builder()
                    .authProvider("string")
                    .awsAccessKeyId("string")
                    .awsAssumeRoleArn("string")
                    .awsCacheName("string")
                    .awsIsServerless(false)
                    .awsRegion("string")
                    .awsRoleSessionName("string")
                    .awsSecretAccessKey("string")
                    .azureClientId("string")
                    .azureClientSecret("string")
                    .azureTenantId("string")
                    .gcpServiceAccountJson("string")
                    .oauth(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs.builder()
                        .authMethod("string")
                        .clientId("string")
                        .clientSecret("string")
                        .clientSecretJwtAlg("string")
                        .grantType("string")
                        .password("string")
                        .redisUsername("string")
                        .redisUsernameClaim("string")
                        .scopes("string")
                        .sslVerify(false)
                        .timeout(0.0)
                        .tokenEndpoint("string")
                        .tokenHeaders(Map.of("string", "string"))
                        .tokenPostArgs(Map.of("string", "string"))
                        .username("string")
                        .build())
                    .build())
                .clusterMaxRedirections(0.0)
                .clusterNodes(GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs.builder()
                    .ip("string")
                    .port(0.0)
                    .build())
                .connectTimeout(0.0)
                .connectionIsProxied(false)
                .database(0.0)
                .host("string")
                .keepaliveBacklog(0.0)
                .keepalivePoolSize(0.0)
                .password("string")
                .port("string")
                .readTimeout(0.0)
                .sendTimeout(0.0)
                .sentinelMaster("string")
                .sentinelNodes(GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs.builder()
                    .host("string")
                    .port(0.0)
                    .build())
                .sentinelPassword("string")
                .sentinelRole("string")
                .sentinelUsername("string")
                .serverName("string")
                .ssl(false)
                .sslVerify(false)
                .username("string")
                .build())
            .refreshInterval(0.0)
            .responseCodes(GatewayPluginEntitlementEnforcementConfigResponseCodesArgs.builder()
                .customerNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs.builder()
                    .httpStatus(0.0)
                    .message("string")
                    .build())
                .featureNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs.builder()
                    .httpStatus(0.0)
                    .message("string")
                    .build())
                .featureUnavailable(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs.builder()
                    .httpStatus(0.0)
                    .message("string")
                    .build())
                .noCreditAvailable(GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs.builder()
                    .httpStatus(0.0)
                    .message("string")
                    .build())
                .usageLimitReached(GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs.builder()
                    .httpStatus(0.0)
                    .message("string")
                    .build())
                .build())
            .sslVerify(false)
            .syncRate(0.0)
            .timeout(0.0)
            .build())
        .gatewayPluginEntitlementEnforcementId("string")
        .consumer(GatewayPluginEntitlementEnforcementConsumerArgs.builder()
            .id("string")
            .build())
        .createdAt(0.0)
        .enabled(false)
        .condition("string")
        .instanceName("string")
        .ordering(GatewayPluginEntitlementEnforcementOrderingArgs.builder()
            .after(GatewayPluginEntitlementEnforcementOrderingAfterArgs.builder()
                .accesses("string")
                .build())
            .before(GatewayPluginEntitlementEnforcementOrderingBeforeArgs.builder()
                .accesses("string")
                .build())
            .build())
        .partials(GatewayPluginEntitlementEnforcementPartialArgs.builder()
            .id("string")
            .name("string")
            .path("string")
            .build())
        .protocols("string")
        .route(GatewayPluginEntitlementEnforcementRouteArgs.builder()
            .id("string")
            .build())
        .service(GatewayPluginEntitlementEnforcementServiceArgs.builder()
            .id("string")
            .build())
        .tags("string")
        .updatedAt(0.0)
        .build());
    
    gateway_plugin_entitlement_enforcement_resource = konnect.GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource",
        control_plane_id="string",
        config={
            "entitlement_access_endpoint": "string",
            "api_token": "string",
            "feature": {
                "key": "string",
            },
            "l1_cache_ttl_seconds": float(0),
            "max_stale_seconds": float(0),
            "fail_policy": "string",
            "customer": {
                "field": "string",
                "look_up_value_in": "string",
            },
            "keepalive": float(0),
            "credit_balance_required": False,
            "l2_cache_ttl_seconds": float(0),
            "deny_unknown_customers": False,
            "redis": {
                "cloud_authentication": {
                    "auth_provider": "string",
                    "aws_access_key_id": "string",
                    "aws_assume_role_arn": "string",
                    "aws_cache_name": "string",
                    "aws_is_serverless": False,
                    "aws_region": "string",
                    "aws_role_session_name": "string",
                    "aws_secret_access_key": "string",
                    "azure_client_id": "string",
                    "azure_client_secret": "string",
                    "azure_tenant_id": "string",
                    "gcp_service_account_json": "string",
                    "oauth": {
                        "auth_method": "string",
                        "client_id": "string",
                        "client_secret": "string",
                        "client_secret_jwt_alg": "string",
                        "grant_type": "string",
                        "password": "string",
                        "redis_username": "string",
                        "redis_username_claim": "string",
                        "scopes": ["string"],
                        "ssl_verify": False,
                        "timeout": float(0),
                        "token_endpoint": "string",
                        "token_headers": {
                            "string": "string",
                        },
                        "token_post_args": {
                            "string": "string",
                        },
                        "username": "string",
                    },
                },
                "cluster_max_redirections": float(0),
                "cluster_nodes": [{
                    "ip": "string",
                    "port": float(0),
                }],
                "connect_timeout": float(0),
                "connection_is_proxied": False,
                "database": float(0),
                "host": "string",
                "keepalive_backlog": float(0),
                "keepalive_pool_size": float(0),
                "password": "string",
                "port": "string",
                "read_timeout": float(0),
                "send_timeout": float(0),
                "sentinel_master": "string",
                "sentinel_nodes": [{
                    "host": "string",
                    "port": float(0),
                }],
                "sentinel_password": "string",
                "sentinel_role": "string",
                "sentinel_username": "string",
                "server_name": "string",
                "ssl": False,
                "ssl_verify": False,
                "username": "string",
            },
            "refresh_interval": float(0),
            "response_codes": {
                "customer_not_found": {
                    "http_status": float(0),
                    "message": "string",
                },
                "feature_not_found": {
                    "http_status": float(0),
                    "message": "string",
                },
                "feature_unavailable": {
                    "http_status": float(0),
                    "message": "string",
                },
                "no_credit_available": {
                    "http_status": float(0),
                    "message": "string",
                },
                "usage_limit_reached": {
                    "http_status": float(0),
                    "message": "string",
                },
            },
            "ssl_verify": False,
            "sync_rate": float(0),
            "timeout": float(0),
        },
        gateway_plugin_entitlement_enforcement_id="string",
        consumer={
            "id": "string",
        },
        created_at=float(0),
        enabled=False,
        condition="string",
        instance_name="string",
        ordering={
            "after": {
                "accesses": ["string"],
            },
            "before": {
                "accesses": ["string"],
            },
        },
        partials=[{
            "id": "string",
            "name": "string",
            "path": "string",
        }],
        protocols=["string"],
        route={
            "id": "string",
        },
        service={
            "id": "string",
        },
        tags=["string"],
        updated_at=float(0))
    
    const gatewayPluginEntitlementEnforcementResource = new konnect.GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource", {
        controlPlaneId: "string",
        config: {
            entitlementAccessEndpoint: "string",
            apiToken: "string",
            feature: {
                key: "string",
            },
            l1CacheTtlSeconds: 0,
            maxStaleSeconds: 0,
            failPolicy: "string",
            customer: {
                field: "string",
                lookUpValueIn: "string",
            },
            keepalive: 0,
            creditBalanceRequired: false,
            l2CacheTtlSeconds: 0,
            denyUnknownCustomers: false,
            redis: {
                cloudAuthentication: {
                    authProvider: "string",
                    awsAccessKeyId: "string",
                    awsAssumeRoleArn: "string",
                    awsCacheName: "string",
                    awsIsServerless: false,
                    awsRegion: "string",
                    awsRoleSessionName: "string",
                    awsSecretAccessKey: "string",
                    azureClientId: "string",
                    azureClientSecret: "string",
                    azureTenantId: "string",
                    gcpServiceAccountJson: "string",
                    oauth: {
                        authMethod: "string",
                        clientId: "string",
                        clientSecret: "string",
                        clientSecretJwtAlg: "string",
                        grantType: "string",
                        password: "string",
                        redisUsername: "string",
                        redisUsernameClaim: "string",
                        scopes: ["string"],
                        sslVerify: false,
                        timeout: 0,
                        tokenEndpoint: "string",
                        tokenHeaders: {
                            string: "string",
                        },
                        tokenPostArgs: {
                            string: "string",
                        },
                        username: "string",
                    },
                },
                clusterMaxRedirections: 0,
                clusterNodes: [{
                    ip: "string",
                    port: 0,
                }],
                connectTimeout: 0,
                connectionIsProxied: false,
                database: 0,
                host: "string",
                keepaliveBacklog: 0,
                keepalivePoolSize: 0,
                password: "string",
                port: "string",
                readTimeout: 0,
                sendTimeout: 0,
                sentinelMaster: "string",
                sentinelNodes: [{
                    host: "string",
                    port: 0,
                }],
                sentinelPassword: "string",
                sentinelRole: "string",
                sentinelUsername: "string",
                serverName: "string",
                ssl: false,
                sslVerify: false,
                username: "string",
            },
            refreshInterval: 0,
            responseCodes: {
                customerNotFound: {
                    httpStatus: 0,
                    message: "string",
                },
                featureNotFound: {
                    httpStatus: 0,
                    message: "string",
                },
                featureUnavailable: {
                    httpStatus: 0,
                    message: "string",
                },
                noCreditAvailable: {
                    httpStatus: 0,
                    message: "string",
                },
                usageLimitReached: {
                    httpStatus: 0,
                    message: "string",
                },
            },
            sslVerify: false,
            syncRate: 0,
            timeout: 0,
        },
        gatewayPluginEntitlementEnforcementId: "string",
        consumer: {
            id: "string",
        },
        createdAt: 0,
        enabled: false,
        condition: "string",
        instanceName: "string",
        ordering: {
            after: {
                accesses: ["string"],
            },
            before: {
                accesses: ["string"],
            },
        },
        partials: [{
            id: "string",
            name: "string",
            path: "string",
        }],
        protocols: ["string"],
        route: {
            id: "string",
        },
        service: {
            id: "string",
        },
        tags: ["string"],
        updatedAt: 0,
    });
    
    type: konnect:GatewayPluginEntitlementEnforcement
    properties:
        condition: string
        config:
            apiToken: string
            creditBalanceRequired: false
            customer:
                field: string
                lookUpValueIn: string
            denyUnknownCustomers: false
            entitlementAccessEndpoint: string
            failPolicy: string
            feature:
                key: string
            keepalive: 0
            l1CacheTtlSeconds: 0
            l2CacheTtlSeconds: 0
            maxStaleSeconds: 0
            redis:
                cloudAuthentication:
                    authProvider: string
                    awsAccessKeyId: string
                    awsAssumeRoleArn: string
                    awsCacheName: string
                    awsIsServerless: false
                    awsRegion: string
                    awsRoleSessionName: string
                    awsSecretAccessKey: string
                    azureClientId: string
                    azureClientSecret: string
                    azureTenantId: string
                    gcpServiceAccountJson: string
                    oauth:
                        authMethod: string
                        clientId: string
                        clientSecret: string
                        clientSecretJwtAlg: string
                        grantType: string
                        password: string
                        redisUsername: string
                        redisUsernameClaim: string
                        scopes:
                            - string
                        sslVerify: false
                        timeout: 0
                        tokenEndpoint: string
                        tokenHeaders:
                            string: string
                        tokenPostArgs:
                            string: string
                        username: string
                clusterMaxRedirections: 0
                clusterNodes:
                    - ip: string
                      port: 0
                connectTimeout: 0
                connectionIsProxied: false
                database: 0
                host: string
                keepaliveBacklog: 0
                keepalivePoolSize: 0
                password: string
                port: string
                readTimeout: 0
                sendTimeout: 0
                sentinelMaster: string
                sentinelNodes:
                    - host: string
                      port: 0
                sentinelPassword: string
                sentinelRole: string
                sentinelUsername: string
                serverName: string
                ssl: false
                sslVerify: false
                username: string
            refreshInterval: 0
            responseCodes:
                customerNotFound:
                    httpStatus: 0
                    message: string
                featureNotFound:
                    httpStatus: 0
                    message: string
                featureUnavailable:
                    httpStatus: 0
                    message: string
                noCreditAvailable:
                    httpStatus: 0
                    message: string
                usageLimitReached:
                    httpStatus: 0
                    message: string
            sslVerify: false
            syncRate: 0
            timeout: 0
        consumer:
            id: string
        controlPlaneId: string
        createdAt: 0
        enabled: false
        gatewayPluginEntitlementEnforcementId: string
        instanceName: string
        ordering:
            after:
                accesses:
                    - string
            before:
                accesses:
                    - string
        partials:
            - id: string
              name: string
              path: string
        protocols:
            - string
        route:
            id: string
        service:
            id: string
        tags:
            - string
        updatedAt: 0
    

    GatewayPluginEntitlementEnforcement Resource Properties

    To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.

    Inputs

    In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.

    The GatewayPluginEntitlementEnforcement resource accepts the following input properties:

    Config GatewayPluginEntitlementEnforcementConfig
    ControlPlaneId string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    Condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    Consumer GatewayPluginEntitlementEnforcementConsumer
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    CreatedAt double
    Unix epoch when the resource was created.
    Enabled bool
    Whether the plugin is applied. Default: true
    GatewayPluginEntitlementEnforcementId string
    A string representing a UUID (universally unique identifier).
    InstanceName string
    A unique string representing a UTF-8 encoded name.
    Ordering GatewayPluginEntitlementEnforcementOrdering
    Partials List<GatewayPluginEntitlementEnforcementPartial>
    A list of partials to be used by the plugin.
    Protocols List<string>
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    Route GatewayPluginEntitlementEnforcementRoute
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    Service GatewayPluginEntitlementEnforcementService
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    Tags List<string>
    An optional set of strings associated with the Plugin for grouping and filtering.
    UpdatedAt double
    Unix epoch when the resource was last updated.
    Config GatewayPluginEntitlementEnforcementConfigArgs
    ControlPlaneId string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    Condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    Consumer GatewayPluginEntitlementEnforcementConsumerArgs
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    CreatedAt float64
    Unix epoch when the resource was created.
    Enabled bool
    Whether the plugin is applied. Default: true
    GatewayPluginEntitlementEnforcementId string
    A string representing a UUID (universally unique identifier).
    InstanceName string
    A unique string representing a UTF-8 encoded name.
    Ordering GatewayPluginEntitlementEnforcementOrderingArgs
    Partials []GatewayPluginEntitlementEnforcementPartialArgs
    A list of partials to be used by the plugin.
    Protocols []string
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    Route GatewayPluginEntitlementEnforcementRouteArgs
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    Service GatewayPluginEntitlementEnforcementServiceArgs
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    Tags []string
    An optional set of strings associated with the Plugin for grouping and filtering.
    UpdatedAt float64
    Unix epoch when the resource was last updated.
    config object
    control_plane_id string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    consumer object
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    created_at number
    Unix epoch when the resource was created.
    enabled bool
    Whether the plugin is applied. Default: true
    gateway_plugin_entitlement_enforcement_id string
    A string representing a UUID (universally unique identifier).
    instance_name string
    A unique string representing a UTF-8 encoded name.
    ordering object
    partials list(object)
    A list of partials to be used by the plugin.
    protocols list(string)
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route object
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service object
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags list(string)
    An optional set of strings associated with the Plugin for grouping and filtering.
    updated_at number
    Unix epoch when the resource was last updated.
    config GatewayPluginEntitlementEnforcementConfig
    controlPlaneId String
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    condition String
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    consumer GatewayPluginEntitlementEnforcementConsumer
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    createdAt Double
    Unix epoch when the resource was created.
    enabled Boolean
    Whether the plugin is applied. Default: true
    gatewayPluginEntitlementEnforcementId String
    A string representing a UUID (universally unique identifier).
    instanceName String
    A unique string representing a UTF-8 encoded name.
    ordering GatewayPluginEntitlementEnforcementOrdering
    partials List<GatewayPluginEntitlementEnforcementPartial>
    A list of partials to be used by the plugin.
    protocols List<String>
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route GatewayPluginEntitlementEnforcementRoute
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service GatewayPluginEntitlementEnforcementService
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags List<String>
    An optional set of strings associated with the Plugin for grouping and filtering.
    updatedAt Double
    Unix epoch when the resource was last updated.
    config GatewayPluginEntitlementEnforcementConfig
    controlPlaneId string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    consumer GatewayPluginEntitlementEnforcementConsumer
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    createdAt number
    Unix epoch when the resource was created.
    enabled boolean
    Whether the plugin is applied. Default: true
    gatewayPluginEntitlementEnforcementId string
    A string representing a UUID (universally unique identifier).
    instanceName string
    A unique string representing a UTF-8 encoded name.
    ordering GatewayPluginEntitlementEnforcementOrdering
    partials GatewayPluginEntitlementEnforcementPartial[]
    A list of partials to be used by the plugin.
    protocols string[]
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route GatewayPluginEntitlementEnforcementRoute
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service GatewayPluginEntitlementEnforcementService
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags string[]
    An optional set of strings associated with the Plugin for grouping and filtering.
    updatedAt number
    Unix epoch when the resource was last updated.
    config GatewayPluginEntitlementEnforcementConfigArgs
    control_plane_id str
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    condition str
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    consumer GatewayPluginEntitlementEnforcementConsumerArgs
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    created_at float
    Unix epoch when the resource was created.
    enabled bool
    Whether the plugin is applied. Default: true
    gateway_plugin_entitlement_enforcement_id str
    A string representing a UUID (universally unique identifier).
    instance_name str
    A unique string representing a UTF-8 encoded name.
    ordering GatewayPluginEntitlementEnforcementOrderingArgs
    partials Sequence[GatewayPluginEntitlementEnforcementPartialArgs]
    A list of partials to be used by the plugin.
    protocols Sequence[str]
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route GatewayPluginEntitlementEnforcementRouteArgs
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service GatewayPluginEntitlementEnforcementServiceArgs
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags Sequence[str]
    An optional set of strings associated with the Plugin for grouping and filtering.
    updated_at float
    Unix epoch when the resource was last updated.
    config Property Map
    controlPlaneId String
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    condition String
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    consumer Property Map
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    createdAt Number
    Unix epoch when the resource was created.
    enabled Boolean
    Whether the plugin is applied. Default: true
    gatewayPluginEntitlementEnforcementId String
    A string representing a UUID (universally unique identifier).
    instanceName String
    A unique string representing a UTF-8 encoded name.
    ordering Property Map
    partials List<Property Map>
    A list of partials to be used by the plugin.
    protocols List<String>
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route Property Map
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service Property Map
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags List<String>
    An optional set of strings associated with the Plugin for grouping and filtering.
    updatedAt Number
    Unix epoch when the resource was last updated.

    Outputs

    All input properties are implicitly available as output properties. Additionally, the GatewayPluginEntitlementEnforcement resource produces the following output properties:

    Id string
    The provider-assigned unique ID for this managed resource.
    Id string
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.
    id string
    The provider-assigned unique ID for this managed resource.
    id str
    The provider-assigned unique ID for this managed resource.
    id String
    The provider-assigned unique ID for this managed resource.

    Look up Existing GatewayPluginEntitlementEnforcement Resource

    Get an existing GatewayPluginEntitlementEnforcement resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.

    public static get(name: string, id: Input<ID>, state?: GatewayPluginEntitlementEnforcementState, opts?: CustomResourceOptions): GatewayPluginEntitlementEnforcement
    @staticmethod
    def get(resource_name: str,
            id: str,
            opts: Optional[ResourceOptions] = None,
            condition: Optional[str] = None,
            config: Optional[GatewayPluginEntitlementEnforcementConfigArgs] = None,
            consumer: Optional[GatewayPluginEntitlementEnforcementConsumerArgs] = None,
            control_plane_id: Optional[str] = None,
            created_at: Optional[float] = None,
            enabled: Optional[bool] = None,
            gateway_plugin_entitlement_enforcement_id: Optional[str] = None,
            instance_name: Optional[str] = None,
            ordering: Optional[GatewayPluginEntitlementEnforcementOrderingArgs] = None,
            partials: Optional[Sequence[GatewayPluginEntitlementEnforcementPartialArgs]] = None,
            protocols: Optional[Sequence[str]] = None,
            route: Optional[GatewayPluginEntitlementEnforcementRouteArgs] = None,
            service: Optional[GatewayPluginEntitlementEnforcementServiceArgs] = None,
            tags: Optional[Sequence[str]] = None,
            updated_at: Optional[float] = None) -> GatewayPluginEntitlementEnforcement
    func GetGatewayPluginEntitlementEnforcement(ctx *Context, name string, id IDInput, state *GatewayPluginEntitlementEnforcementState, opts ...ResourceOption) (*GatewayPluginEntitlementEnforcement, error)
    public static GatewayPluginEntitlementEnforcement Get(string name, Input<string> id, GatewayPluginEntitlementEnforcementState? state, CustomResourceOptions? opts = null)
    public static GatewayPluginEntitlementEnforcement get(String name, Output<String> id, GatewayPluginEntitlementEnforcementState state, CustomResourceOptions options)
    resources:  _:    type: konnect:GatewayPluginEntitlementEnforcement    get:      id: ${id}
    import {
      to = konnect_gateway_plugin_entitlement_enforcement.example
      id = "${id}"
    }
    
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    resource_name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    name
    The unique name of the resulting resource.
    id
    The unique provider ID of the resource to lookup.
    state
    Any extra arguments used during the lookup.
    opts
    A bag of options that control this resource's behavior.
    The following state arguments are supported:
    Condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    Config GatewayPluginEntitlementEnforcementConfig
    Consumer GatewayPluginEntitlementEnforcementConsumer
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    ControlPlaneId string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    CreatedAt double
    Unix epoch when the resource was created.
    Enabled bool
    Whether the plugin is applied. Default: true
    GatewayPluginEntitlementEnforcementId string
    A string representing a UUID (universally unique identifier).
    InstanceName string
    A unique string representing a UTF-8 encoded name.
    Ordering GatewayPluginEntitlementEnforcementOrdering
    Partials List<GatewayPluginEntitlementEnforcementPartial>
    A list of partials to be used by the plugin.
    Protocols List<string>
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    Route GatewayPluginEntitlementEnforcementRoute
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    Service GatewayPluginEntitlementEnforcementService
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    Tags List<string>
    An optional set of strings associated with the Plugin for grouping and filtering.
    UpdatedAt double
    Unix epoch when the resource was last updated.
    Condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    Config GatewayPluginEntitlementEnforcementConfigArgs
    Consumer GatewayPluginEntitlementEnforcementConsumerArgs
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    ControlPlaneId string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    CreatedAt float64
    Unix epoch when the resource was created.
    Enabled bool
    Whether the plugin is applied. Default: true
    GatewayPluginEntitlementEnforcementId string
    A string representing a UUID (universally unique identifier).
    InstanceName string
    A unique string representing a UTF-8 encoded name.
    Ordering GatewayPluginEntitlementEnforcementOrderingArgs
    Partials []GatewayPluginEntitlementEnforcementPartialArgs
    A list of partials to be used by the plugin.
    Protocols []string
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    Route GatewayPluginEntitlementEnforcementRouteArgs
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    Service GatewayPluginEntitlementEnforcementServiceArgs
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    Tags []string
    An optional set of strings associated with the Plugin for grouping and filtering.
    UpdatedAt float64
    Unix epoch when the resource was last updated.
    condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    config object
    consumer object
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    control_plane_id string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    created_at number
    Unix epoch when the resource was created.
    enabled bool
    Whether the plugin is applied. Default: true
    gateway_plugin_entitlement_enforcement_id string
    A string representing a UUID (universally unique identifier).
    instance_name string
    A unique string representing a UTF-8 encoded name.
    ordering object
    partials list(object)
    A list of partials to be used by the plugin.
    protocols list(string)
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route object
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service object
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags list(string)
    An optional set of strings associated with the Plugin for grouping and filtering.
    updated_at number
    Unix epoch when the resource was last updated.
    condition String
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    config GatewayPluginEntitlementEnforcementConfig
    consumer GatewayPluginEntitlementEnforcementConsumer
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    controlPlaneId String
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    createdAt Double
    Unix epoch when the resource was created.
    enabled Boolean
    Whether the plugin is applied. Default: true
    gatewayPluginEntitlementEnforcementId String
    A string representing a UUID (universally unique identifier).
    instanceName String
    A unique string representing a UTF-8 encoded name.
    ordering GatewayPluginEntitlementEnforcementOrdering
    partials List<GatewayPluginEntitlementEnforcementPartial>
    A list of partials to be used by the plugin.
    protocols List<String>
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route GatewayPluginEntitlementEnforcementRoute
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service GatewayPluginEntitlementEnforcementService
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags List<String>
    An optional set of strings associated with the Plugin for grouping and filtering.
    updatedAt Double
    Unix epoch when the resource was last updated.
    condition string
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    config GatewayPluginEntitlementEnforcementConfig
    consumer GatewayPluginEntitlementEnforcementConsumer
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    controlPlaneId string
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    createdAt number
    Unix epoch when the resource was created.
    enabled boolean
    Whether the plugin is applied. Default: true
    gatewayPluginEntitlementEnforcementId string
    A string representing a UUID (universally unique identifier).
    instanceName string
    A unique string representing a UTF-8 encoded name.
    ordering GatewayPluginEntitlementEnforcementOrdering
    partials GatewayPluginEntitlementEnforcementPartial[]
    A list of partials to be used by the plugin.
    protocols string[]
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route GatewayPluginEntitlementEnforcementRoute
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service GatewayPluginEntitlementEnforcementService
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags string[]
    An optional set of strings associated with the Plugin for grouping and filtering.
    updatedAt number
    Unix epoch when the resource was last updated.
    condition str
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    config GatewayPluginEntitlementEnforcementConfigArgs
    consumer GatewayPluginEntitlementEnforcementConsumerArgs
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    control_plane_id str
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    created_at float
    Unix epoch when the resource was created.
    enabled bool
    Whether the plugin is applied. Default: true
    gateway_plugin_entitlement_enforcement_id str
    A string representing a UUID (universally unique identifier).
    instance_name str
    A unique string representing a UTF-8 encoded name.
    ordering GatewayPluginEntitlementEnforcementOrderingArgs
    partials Sequence[GatewayPluginEntitlementEnforcementPartialArgs]
    A list of partials to be used by the plugin.
    protocols Sequence[str]
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route GatewayPluginEntitlementEnforcementRouteArgs
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service GatewayPluginEntitlementEnforcementServiceArgs
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags Sequence[str]
    An optional set of strings associated with the Plugin for grouping and filtering.
    updated_at float
    Unix epoch when the resource was last updated.
    condition String
    An expression used for conditional control over plugin execution. If the expression evaluates to true during the request flow, the plugin is executed; otherwise, it is skipped.
    config Property Map
    consumer Property Map
    If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
    controlPlaneId String
    The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
    createdAt Number
    Unix epoch when the resource was created.
    enabled Boolean
    Whether the plugin is applied. Default: true
    gatewayPluginEntitlementEnforcementId String
    A string representing a UUID (universally unique identifier).
    instanceName String
    A unique string representing a UTF-8 encoded name.
    ordering Property Map
    partials List<Property Map>
    A list of partials to be used by the plugin.
    protocols List<String>
    A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
    route Property Map
    If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
    service Property Map
    If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
    tags List<String>
    An optional set of strings associated with the Plugin for grouping and filtering.
    updatedAt Number
    Unix epoch when the resource was last updated.

    Supporting Types

    GatewayPluginEntitlementEnforcementConfig, GatewayPluginEntitlementEnforcementConfigArgs

    ApiToken string
    Bearer token for authenticating with the entitlement access endpoint.
    EntitlementAccessEndpoint string
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    Feature GatewayPluginEntitlementEnforcementConfigFeature
    The feature identifies what capability is being accessed and enforced.
    CreditBalanceRequired bool
    If set to true, gateway will fetch credit balance for subject. Default: true
    Customer GatewayPluginEntitlementEnforcementConfigCustomer
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    DenyUnknownCustomers bool
    If set to true, gateway will deny access to any unknown subjects. Default: true
    FailPolicy string
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    Keepalive double
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    L1CacheTtlSeconds double
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    L2CacheTtlSeconds double
    Time in seconds to keep enforcement state in Redis. Default: 120
    MaxStaleSeconds double
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    Redis GatewayPluginEntitlementEnforcementConfigRedis
    RefreshInterval double
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    ResponseCodes GatewayPluginEntitlementEnforcementConfigResponseCodes
    SslVerify bool
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    SyncRate double
    How often in seconds to sync enforcement state from redis. Default: 2
    Timeout double
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
    ApiToken string
    Bearer token for authenticating with the entitlement access endpoint.
    EntitlementAccessEndpoint string
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    Feature GatewayPluginEntitlementEnforcementConfigFeature
    The feature identifies what capability is being accessed and enforced.
    CreditBalanceRequired bool
    If set to true, gateway will fetch credit balance for subject. Default: true
    Customer GatewayPluginEntitlementEnforcementConfigCustomer
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    DenyUnknownCustomers bool
    If set to true, gateway will deny access to any unknown subjects. Default: true
    FailPolicy string
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    Keepalive float64
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    L1CacheTtlSeconds float64
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    L2CacheTtlSeconds float64
    Time in seconds to keep enforcement state in Redis. Default: 120
    MaxStaleSeconds float64
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    Redis GatewayPluginEntitlementEnforcementConfigRedis
    RefreshInterval float64
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    ResponseCodes GatewayPluginEntitlementEnforcementConfigResponseCodes
    SslVerify bool
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    SyncRate float64
    How often in seconds to sync enforcement state from redis. Default: 2
    Timeout float64
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
    api_token string
    Bearer token for authenticating with the entitlement access endpoint.
    entitlement_access_endpoint string
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    feature object
    The feature identifies what capability is being accessed and enforced.
    credit_balance_required bool
    If set to true, gateway will fetch credit balance for subject. Default: true
    customer object
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    deny_unknown_customers bool
    If set to true, gateway will deny access to any unknown subjects. Default: true
    fail_policy string
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    keepalive number
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    l1_cache_ttl_seconds number
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    l2_cache_ttl_seconds number
    Time in seconds to keep enforcement state in Redis. Default: 120
    max_stale_seconds number
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    redis object
    refresh_interval number
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    response_codes object
    ssl_verify bool
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    sync_rate number
    How often in seconds to sync enforcement state from redis. Default: 2
    timeout number
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
    apiToken String
    Bearer token for authenticating with the entitlement access endpoint.
    entitlementAccessEndpoint String
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    feature GatewayPluginEntitlementEnforcementConfigFeature
    The feature identifies what capability is being accessed and enforced.
    creditBalanceRequired Boolean
    If set to true, gateway will fetch credit balance for subject. Default: true
    customer GatewayPluginEntitlementEnforcementConfigCustomer
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    denyUnknownCustomers Boolean
    If set to true, gateway will deny access to any unknown subjects. Default: true
    failPolicy String
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    keepalive Double
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    l1CacheTtlSeconds Double
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    l2CacheTtlSeconds Double
    Time in seconds to keep enforcement state in Redis. Default: 120
    maxStaleSeconds Double
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    redis GatewayPluginEntitlementEnforcementConfigRedis
    refreshInterval Double
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    responseCodes GatewayPluginEntitlementEnforcementConfigResponseCodes
    sslVerify Boolean
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    syncRate Double
    How often in seconds to sync enforcement state from redis. Default: 2
    timeout Double
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
    apiToken string
    Bearer token for authenticating with the entitlement access endpoint.
    entitlementAccessEndpoint string
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    feature GatewayPluginEntitlementEnforcementConfigFeature
    The feature identifies what capability is being accessed and enforced.
    creditBalanceRequired boolean
    If set to true, gateway will fetch credit balance for subject. Default: true
    customer GatewayPluginEntitlementEnforcementConfigCustomer
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    denyUnknownCustomers boolean
    If set to true, gateway will deny access to any unknown subjects. Default: true
    failPolicy string
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    keepalive number
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    l1CacheTtlSeconds number
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    l2CacheTtlSeconds number
    Time in seconds to keep enforcement state in Redis. Default: 120
    maxStaleSeconds number
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    redis GatewayPluginEntitlementEnforcementConfigRedis
    refreshInterval number
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    responseCodes GatewayPluginEntitlementEnforcementConfigResponseCodes
    sslVerify boolean
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    syncRate number
    How often in seconds to sync enforcement state from redis. Default: 2
    timeout number
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
    api_token str
    Bearer token for authenticating with the entitlement access endpoint.
    entitlement_access_endpoint str
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    feature GatewayPluginEntitlementEnforcementConfigFeature
    The feature identifies what capability is being accessed and enforced.
    credit_balance_required bool
    If set to true, gateway will fetch credit balance for subject. Default: true
    customer GatewayPluginEntitlementEnforcementConfigCustomer
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    deny_unknown_customers bool
    If set to true, gateway will deny access to any unknown subjects. Default: true
    fail_policy str
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    keepalive float
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    l1_cache_ttl_seconds float
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    l2_cache_ttl_seconds float
    Time in seconds to keep enforcement state in Redis. Default: 120
    max_stale_seconds float
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    redis GatewayPluginEntitlementEnforcementConfigRedis
    refresh_interval float
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    response_codes GatewayPluginEntitlementEnforcementConfigResponseCodes
    ssl_verify bool
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    sync_rate float
    How often in seconds to sync enforcement state from redis. Default: 2
    timeout float
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
    apiToken String
    Bearer token for authenticating with the entitlement access endpoint.
    entitlementAccessEndpoint String
    A string representing a URL, such as https://example.com/path/to/resource?q=search.
    feature Property Map
    The feature identifies what capability is being accessed and enforced.
    creditBalanceRequired Boolean
    If set to true, gateway will fetch credit balance for subject. Default: true
    customer Property Map
    The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
    denyUnknownCustomers Boolean
    If set to true, gateway will deny access to any unknown subjects. Default: true
    failPolicy String
    Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
    keepalive Number
    How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
    l1CacheTtlSeconds Number
    Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
    l2CacheTtlSeconds Number
    Time in seconds to keep enforcement state in Redis. Default: 120
    maxStaleSeconds Number
    Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
    redis Property Map
    refreshInterval Number
    How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
    responseCodes Property Map
    sslVerify Boolean
    Verify the TLS certificate presented by the entitlement access endpoint. Default: true
    syncRate Number
    How often in seconds to sync enforcement state from redis. Default: 2
    timeout Number
    Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000

    GatewayPluginEntitlementEnforcementConfigCustomer, GatewayPluginEntitlementEnforcementConfigCustomerArgs

    Field string
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    LookUpValueIn string
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
    Field string
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    LookUpValueIn string
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
    field string
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    look_up_value_in string
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
    field String
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    lookUpValueIn String
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
    field string
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    lookUpValueIn string
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
    field str
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    look_up_value_in str
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
    field String
    The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
    lookUpValueIn String
    Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"

    GatewayPluginEntitlementEnforcementConfigFeature, GatewayPluginEntitlementEnforcementConfigFeatureArgs

    Key string
    The feature key
    Key string
    The feature key
    key string
    The feature key
    key String
    The feature key
    key string
    The feature key
    key str
    The feature key
    key String
    The feature key

    GatewayPluginEntitlementEnforcementConfigRedis, GatewayPluginEntitlementEnforcementConfigRedisArgs

    CloudAuthentication GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    ClusterMaxRedirections double
    Maximum retry attempts for redirection. Default: 5
    ClusterNodes List<GatewayPluginEntitlementEnforcementConfigRedisClusterNode>
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    ConnectTimeout double
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    ConnectionIsProxied bool
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    Database double
    Database to use for the Redis connection when using the redis strategy. Default: 0
    Host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    KeepaliveBacklog double
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    KeepalivePoolSize double
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    Password string
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    Port string
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    ReadTimeout double
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    SendTimeout double
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    SentinelMaster string
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    SentinelNodes List<GatewayPluginEntitlementEnforcementConfigRedisSentinelNode>
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    SentinelPassword string
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    SentinelRole string
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    SentinelUsername string
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    ServerName string
    A string representing an SNI (server name indication) value for TLS.
    Ssl bool
    If set to true, uses SSL to connect to Redis. Default: false
    SslVerify bool
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    Username string
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.
    CloudAuthentication GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    ClusterMaxRedirections float64
    Maximum retry attempts for redirection. Default: 5
    ClusterNodes []GatewayPluginEntitlementEnforcementConfigRedisClusterNode
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    ConnectTimeout float64
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    ConnectionIsProxied bool
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    Database float64
    Database to use for the Redis connection when using the redis strategy. Default: 0
    Host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    KeepaliveBacklog float64
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    KeepalivePoolSize float64
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    Password string
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    Port string
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    ReadTimeout float64
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    SendTimeout float64
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    SentinelMaster string
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    SentinelNodes []GatewayPluginEntitlementEnforcementConfigRedisSentinelNode
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    SentinelPassword string
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    SentinelRole string
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    SentinelUsername string
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    ServerName string
    A string representing an SNI (server name indication) value for TLS.
    Ssl bool
    If set to true, uses SSL to connect to Redis. Default: false
    SslVerify bool
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    Username string
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.
    cloud_authentication object
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    cluster_max_redirections number
    Maximum retry attempts for redirection. Default: 5
    cluster_nodes list(object)
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    connect_timeout number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    connection_is_proxied bool
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    database number
    Database to use for the Redis connection when using the redis strategy. Default: 0
    host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    keepalive_backlog number
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    keepalive_pool_size number
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    password string
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    port string
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    read_timeout number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    send_timeout number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sentinel_master string
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    sentinel_nodes list(object)
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    sentinel_password string
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    sentinel_role string
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    sentinel_username string
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    server_name string
    A string representing an SNI (server name indication) value for TLS.
    ssl bool
    If set to true, uses SSL to connect to Redis. Default: false
    ssl_verify bool
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    username string
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.
    cloudAuthentication GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    clusterMaxRedirections Double
    Maximum retry attempts for redirection. Default: 5
    clusterNodes List<GatewayPluginEntitlementEnforcementConfigRedisClusterNode>
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    connectTimeout Double
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    connectionIsProxied Boolean
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    database Double
    Database to use for the Redis connection when using the redis strategy. Default: 0
    host String
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    keepaliveBacklog Double
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    keepalivePoolSize Double
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    password String
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    port String
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    readTimeout Double
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sendTimeout Double
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sentinelMaster String
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    sentinelNodes List<GatewayPluginEntitlementEnforcementConfigRedisSentinelNode>
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    sentinelPassword String
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    sentinelRole String
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    sentinelUsername String
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    serverName String
    A string representing an SNI (server name indication) value for TLS.
    ssl Boolean
    If set to true, uses SSL to connect to Redis. Default: false
    sslVerify Boolean
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    username String
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.
    cloudAuthentication GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    clusterMaxRedirections number
    Maximum retry attempts for redirection. Default: 5
    clusterNodes GatewayPluginEntitlementEnforcementConfigRedisClusterNode[]
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    connectTimeout number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    connectionIsProxied boolean
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    database number
    Database to use for the Redis connection when using the redis strategy. Default: 0
    host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    keepaliveBacklog number
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    keepalivePoolSize number
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    password string
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    port string
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    readTimeout number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sendTimeout number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sentinelMaster string
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    sentinelNodes GatewayPluginEntitlementEnforcementConfigRedisSentinelNode[]
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    sentinelPassword string
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    sentinelRole string
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    sentinelUsername string
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    serverName string
    A string representing an SNI (server name indication) value for TLS.
    ssl boolean
    If set to true, uses SSL to connect to Redis. Default: false
    sslVerify boolean
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    username string
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.
    cloud_authentication GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    cluster_max_redirections float
    Maximum retry attempts for redirection. Default: 5
    cluster_nodes Sequence[GatewayPluginEntitlementEnforcementConfigRedisClusterNode]
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    connect_timeout float
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    connection_is_proxied bool
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    database float
    Database to use for the Redis connection when using the redis strategy. Default: 0
    host str
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    keepalive_backlog float
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    keepalive_pool_size float
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    password str
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    port str
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    read_timeout float
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    send_timeout float
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sentinel_master str
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    sentinel_nodes Sequence[GatewayPluginEntitlementEnforcementConfigRedisSentinelNode]
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    sentinel_password str
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    sentinel_role str
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    sentinel_username str
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    server_name str
    A string representing an SNI (server name indication) value for TLS.
    ssl bool
    If set to true, uses SSL to connect to Redis. Default: false
    ssl_verify bool
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    username str
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.
    cloudAuthentication Property Map
    Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
    clusterMaxRedirections Number
    Maximum retry attempts for redirection. Default: 5
    clusterNodes List<Property Map>
    Cluster addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
    connectTimeout Number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    connectionIsProxied Boolean
    If the connection to Redis is proxied (e.g. Envoy), set it true. Set the host and port to point to the proxy address. Default: false
    database Number
    Database to use for the Redis connection when using the redis strategy. Default: 0
    host String
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    keepaliveBacklog Number
    Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than keepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than keepalive_pool_size.
    keepalivePoolSize Number
    The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither keepalive_pool_size nor keepalive_backlog is specified, no pool is created. If keepalive_pool_size isn't specified but keepalive_backlog is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256
    password String
    Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
    port String
    An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
    readTimeout Number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sendTimeout Number
    An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
    sentinelMaster String
    Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
    sentinelNodes List<Property Map>
    Sentinel node addresses to use for Redis connections when the redis strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
    sentinelPassword String
    Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
    sentinelRole String
    Sentinel role to use for Redis connections when the redis strategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"]
    sentinelUsername String
    Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
    serverName String
    A string representing an SNI (server name indication) value for TLS.
    ssl Boolean
    If set to true, uses SSL to connect to Redis. Default: false
    sslVerify Boolean
    If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure lua_ssl_trusted_certificate in kong.conf to specify the CA (or server) certificate used by your Redis server. You may also need to configure lua_ssl_verify_depth accordingly. Default: true
    username String
    Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to default.

    GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication, GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs

    AuthProvider string
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    AwsAccessKeyId string
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    AwsAssumeRoleArn string
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    AwsCacheName string
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    AwsIsServerless bool
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    AwsRegion string
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    AwsRoleSessionName string
    The session name for the temporary credentials when assuming the IAM role.
    AwsSecretAccessKey string
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    AzureClientId string
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    AzureClientSecret string
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    AzureTenantId string
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    GcpServiceAccountJson string
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    Oauth GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.
    AuthProvider string
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    AwsAccessKeyId string
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    AwsAssumeRoleArn string
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    AwsCacheName string
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    AwsIsServerless bool
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    AwsRegion string
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    AwsRoleSessionName string
    The session name for the temporary credentials when assuming the IAM role.
    AwsSecretAccessKey string
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    AzureClientId string
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    AzureClientSecret string
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    AzureTenantId string
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    GcpServiceAccountJson string
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    Oauth GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.
    auth_provider string
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    aws_access_key_id string
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    aws_assume_role_arn string
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    aws_cache_name string
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    aws_is_serverless bool
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    aws_region string
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    aws_role_session_name string
    The session name for the temporary credentials when assuming the IAM role.
    aws_secret_access_key string
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    azure_client_id string
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    azure_client_secret string
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    azure_tenant_id string
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    gcp_service_account_json string
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    oauth object
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.
    authProvider String
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    awsAccessKeyId String
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    awsAssumeRoleArn String
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    awsCacheName String
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    awsIsServerless Boolean
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    awsRegion String
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    awsRoleSessionName String
    The session name for the temporary credentials when assuming the IAM role.
    awsSecretAccessKey String
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    azureClientId String
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    azureClientSecret String
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    azureTenantId String
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    gcpServiceAccountJson String
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    oauth GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.
    authProvider string
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    awsAccessKeyId string
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    awsAssumeRoleArn string
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    awsCacheName string
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    awsIsServerless boolean
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    awsRegion string
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    awsRoleSessionName string
    The session name for the temporary credentials when assuming the IAM role.
    awsSecretAccessKey string
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    azureClientId string
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    azureClientSecret string
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    azureTenantId string
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    gcpServiceAccountJson string
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    oauth GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.
    auth_provider str
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    aws_access_key_id str
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    aws_assume_role_arn str
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    aws_cache_name str
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    aws_is_serverless bool
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    aws_region str
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    aws_role_session_name str
    The session name for the temporary credentials when assuming the IAM role.
    aws_secret_access_key str
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    azure_client_id str
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    azure_client_secret str
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    azure_tenant_id str
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    gcp_service_account_json str
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    oauth GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.
    authProvider String
    Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
    awsAccessKeyId String
    AWS Access Key ID to be used for authentication when auth_provider is set to aws.
    awsAssumeRoleArn String
    The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
    awsCacheName String
    The name of the AWS Elasticache cluster when auth_provider is set to aws.
    awsIsServerless Boolean
    This flag specifies whether the cluster is serverless when auth_provider is set to aws. Default: true
    awsRegion String
    The region of the AWS ElastiCache cluster when auth_provider is set to aws.
    awsRoleSessionName String
    The session name for the temporary credentials when assuming the IAM role.
    awsSecretAccessKey String
    AWS Secret Access Key to be used for authentication when auth_provider is set to aws.
    azureClientId String
    Azure Client ID to be used for authentication when auth_provider is set to azure.
    azureClientSecret String
    Azure Client Secret to be used for authentication when auth_provider is set to azure.
    azureTenantId String
    Azure Tenant ID to be used for authentication when auth_provider is set to azure.
    gcpServiceAccountJson String
    GCP Service Account JSON to be used for authentication when auth_provider is set to gcp.
    oauth Property Map
    OAuth 2.0 client configuration used to authenticate to Redis when auth_provider is set to oauth.

    GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth, GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs

    AuthMethod string
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    ClientId string
    OAuth 2.0 client ID.
    ClientSecret string
    OAuth 2.0 client secret.
    ClientSecretJwtAlg string
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    GrantType string
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    Password string
    Resource owner password, used with the password grant type.
    RedisUsername string
    Static Redis ACL username sent with AUTH <username> <token>.
    RedisUsernameClaim string
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    Scopes List<string>
    OAuth 2.0 scopes to request. Default: []
    SslVerify bool
    Whether to verify the TLS certificate of the token endpoint. Default: true
    Timeout double
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    TokenEndpoint string
    OAuth 2.0 token endpoint URL used to request access tokens.
    TokenHeaders Dictionary<string, string>
    Additional HTTP headers to send with the token request.
    TokenPostArgs Dictionary<string, string>
    Additional POST body arguments to send with the token request.
    Username string
    Resource owner username, used with the password grant type.
    AuthMethod string
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    ClientId string
    OAuth 2.0 client ID.
    ClientSecret string
    OAuth 2.0 client secret.
    ClientSecretJwtAlg string
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    GrantType string
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    Password string
    Resource owner password, used with the password grant type.
    RedisUsername string
    Static Redis ACL username sent with AUTH <username> <token>.
    RedisUsernameClaim string
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    Scopes []string
    OAuth 2.0 scopes to request. Default: []
    SslVerify bool
    Whether to verify the TLS certificate of the token endpoint. Default: true
    Timeout float64
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    TokenEndpoint string
    OAuth 2.0 token endpoint URL used to request access tokens.
    TokenHeaders map[string]string
    Additional HTTP headers to send with the token request.
    TokenPostArgs map[string]string
    Additional POST body arguments to send with the token request.
    Username string
    Resource owner username, used with the password grant type.
    auth_method string
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    client_id string
    OAuth 2.0 client ID.
    client_secret string
    OAuth 2.0 client secret.
    client_secret_jwt_alg string
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    grant_type string
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    password string
    Resource owner password, used with the password grant type.
    redis_username string
    Static Redis ACL username sent with AUTH <username> <token>.
    redis_username_claim string
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    scopes list(string)
    OAuth 2.0 scopes to request. Default: []
    ssl_verify bool
    Whether to verify the TLS certificate of the token endpoint. Default: true
    timeout number
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    token_endpoint string
    OAuth 2.0 token endpoint URL used to request access tokens.
    token_headers map(string)
    Additional HTTP headers to send with the token request.
    token_post_args map(string)
    Additional POST body arguments to send with the token request.
    username string
    Resource owner username, used with the password grant type.
    authMethod String
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    clientId String
    OAuth 2.0 client ID.
    clientSecret String
    OAuth 2.0 client secret.
    clientSecretJwtAlg String
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    grantType String
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    password String
    Resource owner password, used with the password grant type.
    redisUsername String
    Static Redis ACL username sent with AUTH <username> <token>.
    redisUsernameClaim String
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    scopes List<String>
    OAuth 2.0 scopes to request. Default: []
    sslVerify Boolean
    Whether to verify the TLS certificate of the token endpoint. Default: true
    timeout Double
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    tokenEndpoint String
    OAuth 2.0 token endpoint URL used to request access tokens.
    tokenHeaders Map<String,String>
    Additional HTTP headers to send with the token request.
    tokenPostArgs Map<String,String>
    Additional POST body arguments to send with the token request.
    username String
    Resource owner username, used with the password grant type.
    authMethod string
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    clientId string
    OAuth 2.0 client ID.
    clientSecret string
    OAuth 2.0 client secret.
    clientSecretJwtAlg string
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    grantType string
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    password string
    Resource owner password, used with the password grant type.
    redisUsername string
    Static Redis ACL username sent with AUTH <username> <token>.
    redisUsernameClaim string
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    scopes string[]
    OAuth 2.0 scopes to request. Default: []
    sslVerify boolean
    Whether to verify the TLS certificate of the token endpoint. Default: true
    timeout number
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    tokenEndpoint string
    OAuth 2.0 token endpoint URL used to request access tokens.
    tokenHeaders {[key: string]: string}
    Additional HTTP headers to send with the token request.
    tokenPostArgs {[key: string]: string}
    Additional POST body arguments to send with the token request.
    username string
    Resource owner username, used with the password grant type.
    auth_method str
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    client_id str
    OAuth 2.0 client ID.
    client_secret str
    OAuth 2.0 client secret.
    client_secret_jwt_alg str
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    grant_type str
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    password str
    Resource owner password, used with the password grant type.
    redis_username str
    Static Redis ACL username sent with AUTH <username> <token>.
    redis_username_claim str
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    scopes Sequence[str]
    OAuth 2.0 scopes to request. Default: []
    ssl_verify bool
    Whether to verify the TLS certificate of the token endpoint. Default: true
    timeout float
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    token_endpoint str
    OAuth 2.0 token endpoint URL used to request access tokens.
    token_headers Mapping[str, str]
    Additional HTTP headers to send with the token request.
    token_post_args Mapping[str, str]
    Additional POST body arguments to send with the token request.
    username str
    Resource owner username, used with the password grant type.
    authMethod String
    Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
    clientId String
    OAuth 2.0 client ID.
    clientSecret String
    OAuth 2.0 client secret.
    clientSecretJwtAlg String
    Signing algorithm used for client_secret_jwt client authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512"
    grantType String
    OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
    password String
    Resource owner password, used with the password grant type.
    redisUsername String
    Static Redis ACL username sent with AUTH <username> <token>.
    redisUsernameClaim String
    JWT claim in the access token used to derive the Redis ACL username (for example, oid for Microsoft Entra ID).
    scopes List<String>
    OAuth 2.0 scopes to request. Default: []
    sslVerify Boolean
    Whether to verify the TLS certificate of the token endpoint. Default: true
    timeout Number
    Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
    tokenEndpoint String
    OAuth 2.0 token endpoint URL used to request access tokens.
    tokenHeaders Map<String>
    Additional HTTP headers to send with the token request.
    tokenPostArgs Map<String>
    Additional POST body arguments to send with the token request.
    username String
    Resource owner username, used with the password grant type.

    GatewayPluginEntitlementEnforcementConfigRedisClusterNode, GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs

    Ip string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    Port double
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    Ip string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    Port float64
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    ip string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port number
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    ip String
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port Double
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    ip string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port number
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    ip str
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port float
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    ip String
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port Number
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379

    GatewayPluginEntitlementEnforcementConfigRedisSentinelNode, GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs

    Host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    Port double
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    Host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    Port float64
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port number
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    host String
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port Double
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    host string
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port number
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    host str
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port float
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379
    host String
    A string representing a host name, such as example.com. Default: "127.0.0.1"
    port Number
    An integer representing a port number between 0 and 65535, inclusive. Default: 6379

    GatewayPluginEntitlementEnforcementConfigResponseCodes, GatewayPluginEntitlementEnforcementConfigResponseCodesArgs

    GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFound, GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs

    HttpStatus double
    Status code to return when enforcement is triggered. Default: 403
    Message string
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."
    HttpStatus float64
    Status code to return when enforcement is triggered. Default: 403
    Message string
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."
    http_status number
    Status code to return when enforcement is triggered. Default: 403
    message string
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."
    httpStatus Double
    Status code to return when enforcement is triggered. Default: 403
    message String
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."
    httpStatus number
    Status code to return when enforcement is triggered. Default: 403
    message string
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."
    http_status float
    Status code to return when enforcement is triggered. Default: 403
    message str
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."
    httpStatus Number
    Status code to return when enforcement is triggered. Default: 403
    message String
    Message to return when enforcement is triggered. Default: "Customer is not found by subject."

    GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFound, GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs

    HttpStatus double
    Status code to return when enforcement is triggered. Default: 403
    Message string
    Message to return when enforcement is triggered. Default: "Feature not found."
    HttpStatus float64
    Status code to return when enforcement is triggered. Default: 403
    Message string
    Message to return when enforcement is triggered. Default: "Feature not found."
    http_status number
    Status code to return when enforcement is triggered. Default: 403
    message string
    Message to return when enforcement is triggered. Default: "Feature not found."
    httpStatus Double
    Status code to return when enforcement is triggered. Default: 403
    message String
    Message to return when enforcement is triggered. Default: "Feature not found."
    httpStatus number
    Status code to return when enforcement is triggered. Default: 403
    message string
    Message to return when enforcement is triggered. Default: "Feature not found."
    http_status float
    Status code to return when enforcement is triggered. Default: 403
    message str
    Message to return when enforcement is triggered. Default: "Feature not found."
    httpStatus Number
    Status code to return when enforcement is triggered. Default: 403
    message String
    Message to return when enforcement is triggered. Default: "Feature not found."

    GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailable, GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs

    HttpStatus double
    Status code to return when enforcement is triggered. Default: 403
    Message string
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
    HttpStatus float64
    Status code to return when enforcement is triggered. Default: 403
    Message string
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
    http_status number
    Status code to return when enforcement is triggered. Default: 403
    message string
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
    httpStatus Double
    Status code to return when enforcement is triggered. Default: 403
    message String
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
    httpStatus number
    Status code to return when enforcement is triggered. Default: 403
    message string
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
    http_status float
    Status code to return when enforcement is triggered. Default: 403
    message str
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
    httpStatus Number
    Status code to return when enforcement is triggered. Default: 403
    message String
    Message to return when enforcement is triggered. Default: "Feature is not available for the customer."

    GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailable, GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs

    HttpStatus double
    Status code to return when enforcement is triggered. Default: 402
    Message string
    Message to return when enforcement is triggered. Default: "Customer has no credit available."
    HttpStatus float64
    Status code to return when enforcement is triggered. Default: 402
    Message string
    Message to return when enforcement is triggered. Default: "Customer has no credit available."
    http_status number
    Status code to return when enforcement is triggered. Default: 402
    message string
    Message to return when enforcement is triggered. Default: "Customer has no credit available."
    httpStatus Double
    Status code to return when enforcement is triggered. Default: 402
    message String
    Message to return when enforcement is triggered. Default: "Customer has no credit available."
    httpStatus number
    Status code to return when enforcement is triggered. Default: 402
    message string
    Message to return when enforcement is triggered. Default: "Customer has no credit available."
    http_status float
    Status code to return when enforcement is triggered. Default: 402
    message str
    Message to return when enforcement is triggered. Default: "Customer has no credit available."
    httpStatus Number
    Status code to return when enforcement is triggered. Default: 402
    message String
    Message to return when enforcement is triggered. Default: "Customer has no credit available."

    GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReached, GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs

    HttpStatus double
    Status code to return when enforcement is triggered. Default: 429
    Message string
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
    HttpStatus float64
    Status code to return when enforcement is triggered. Default: 429
    Message string
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
    http_status number
    Status code to return when enforcement is triggered. Default: 429
    message string
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
    httpStatus Double
    Status code to return when enforcement is triggered. Default: 429
    message String
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
    httpStatus number
    Status code to return when enforcement is triggered. Default: 429
    message string
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
    http_status float
    Status code to return when enforcement is triggered. Default: 429
    message str
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
    httpStatus Number
    Status code to return when enforcement is triggered. Default: 429
    message String
    Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."

    GatewayPluginEntitlementEnforcementConsumer, GatewayPluginEntitlementEnforcementConsumerArgs

    Id string
    Id string
    id string
    id String
    id string
    id str
    id String

    GatewayPluginEntitlementEnforcementOrdering, GatewayPluginEntitlementEnforcementOrderingArgs

    GatewayPluginEntitlementEnforcementOrderingAfter, GatewayPluginEntitlementEnforcementOrderingAfterArgs

    Accesses List<string>
    Accesses []string
    accesses list(string)
    accesses List<String>
    accesses string[]
    accesses Sequence[str]
    accesses List<String>

    GatewayPluginEntitlementEnforcementOrderingBefore, GatewayPluginEntitlementEnforcementOrderingBeforeArgs

    Accesses List<string>
    Accesses []string
    accesses list(string)
    accesses List<String>
    accesses string[]
    accesses Sequence[str]
    accesses List<String>

    GatewayPluginEntitlementEnforcementPartial, GatewayPluginEntitlementEnforcementPartialArgs

    Id string
    A string representing a UUID (universally unique identifier).
    Name string
    A unique string representing a UTF-8 encoded name.
    Path string
    Not Null
    Id string
    A string representing a UUID (universally unique identifier).
    Name string
    A unique string representing a UTF-8 encoded name.
    Path string
    Not Null
    id string
    A string representing a UUID (universally unique identifier).
    name string
    A unique string representing a UTF-8 encoded name.
    path string
    Not Null
    id String
    A string representing a UUID (universally unique identifier).
    name String
    A unique string representing a UTF-8 encoded name.
    path String
    Not Null
    id string
    A string representing a UUID (universally unique identifier).
    name string
    A unique string representing a UTF-8 encoded name.
    path string
    Not Null
    id str
    A string representing a UUID (universally unique identifier).
    name str
    A unique string representing a UTF-8 encoded name.
    path str
    Not Null
    id String
    A string representing a UUID (universally unique identifier).
    name String
    A unique string representing a UTF-8 encoded name.
    path String
    Not Null

    GatewayPluginEntitlementEnforcementRoute, GatewayPluginEntitlementEnforcementRouteArgs

    Id string
    Id string
    id string
    id String
    id string
    id str
    id String

    GatewayPluginEntitlementEnforcementService, GatewayPluginEntitlementEnforcementServiceArgs

    Id string
    Id string
    id string
    id String
    id string
    id str
    id String

    Import

    In Terraform v1.5.0 and later, the import block can be used with the id attribute, for example:

    terraform

    import {

    to = konnect_gateway_plugin_entitlement_enforcement.my_konnect_gateway_plugin_entitlement_enforcement

    id = jsonencode({

    control_plane_id = "9524ec7d-36d9-465d-a8c5-83a3c9390458"
    
    id               = "3473c251-5b6c-4f45-b1ff-7ede735a366d"
    

    })

    }

    The pulumi import command can be used, for example:

    $ pulumi import konnect:index/gatewayPluginEntitlementEnforcement:GatewayPluginEntitlementEnforcement my_konnect_gateway_plugin_entitlement_enforcement '{"control_plane_id": "9524ec7d-36d9-465d-a8c5-83a3c9390458", "id": "3473c251-5b6c-4f45-b1ff-7ede735a366d"}'
    

    To learn more about importing existing cloud resources, see Importing resources.

    Package Details

    Repository
    konnect kong/terraform-provider-konnect
    License
    Notes
    This Pulumi package is based on the konnect Terraform Provider.
    Viewing docs for konnect 3.24.0
    published on Friday, Sep 25, 2026 by kong

      Try Pulumi Cloud free.
      Your team will thank you.

      Start free trial