published on Friday, Sep 25, 2026 by kong
published on Friday, Sep 25, 2026 by kong
GatewayPluginEntitlementEnforcement Resource
Example Usage
import * as pulumi from "@pulumi/pulumi";
import * as konnect from "@pulumi/konnect";
const myGatewaypluginentitlementenforcement = new konnect.GatewayPluginEntitlementEnforcement("my_gatewaypluginentitlementenforcement", {
condition: "...my_condition...",
config: {
apiToken: "...my_api_token...",
creditBalanceRequired: true,
customer: {
field: "...my_field...",
lookUpValueIn: "consumer",
},
denyUnknownCustomers: true,
entitlementAccessEndpoint: "...my_entitlement_access_endpoint...",
failPolicy: "allow",
feature: {
key: "...my_key...",
},
keepalive: 60000,
l1CacheTtlSeconds: 5,
l2CacheTtlSeconds: 120,
maxStaleSeconds: 60,
redis: {
cloudAuthentication: {
authProvider: "oauth",
awsAccessKeyId: "...my_aws_access_key_id...",
awsAssumeRoleArn: "...my_aws_assume_role_arn...",
awsCacheName: "...my_aws_cache_name...",
awsIsServerless: true,
awsRegion: "...my_aws_region...",
awsRoleSessionName: "...my_aws_role_session_name...",
awsSecretAccessKey: "...my_aws_secret_access_key...",
azureClientId: "...my_azure_client_id...",
azureClientSecret: "...my_azure_client_secret...",
azureTenantId: "...my_azure_tenant_id...",
gcpServiceAccountJson: "...my_gcp_service_account_json...",
oauth: {
authMethod: "client_secret_post",
clientId: "...my_client_id...",
clientSecret: "...my_client_secret...",
clientSecretJwtAlg: "HS512",
grantType: "client_credentials",
password: "...my_password...",
redisUsername: "...my_redis_username...",
redisUsernameClaim: "...my_redis_username_claim...",
scopes: ["..."],
sslVerify: true,
timeout: 10000,
tokenEndpoint: "...my_token_endpoint...",
tokenHeaders: {
key: "value",
},
tokenPostArgs: {
key: "value",
},
username: "...my_username...",
},
},
clusterMaxRedirections: 5,
clusterNodes: [{
ip: "127.0.0.1",
port: 6379,
}],
connectTimeout: 2000,
connectionIsProxied: false,
database: 0,
host: "127.0.0.1",
keepaliveBacklog: 2020228349,
keepalivePoolSize: 256,
password: "...my_password...",
port: "6379",
readTimeout: 2000,
sendTimeout: 2000,
sentinelMaster: "...my_sentinel_master...",
sentinelNodes: [{
host: "127.0.0.1",
port: 6379,
}],
sentinelPassword: "...my_sentinel_password...",
sentinelRole: "master",
sentinelUsername: "...my_sentinel_username...",
serverName: "...my_server_name...",
ssl: false,
sslVerify: true,
username: "...my_username...",
},
refreshInterval: 30,
responseCodes: {
customerNotFound: {
httpStatus: 403,
message: "Customer is not found by subject.",
},
featureNotFound: {
httpStatus: 403,
message: "Feature not found.",
},
featureUnavailable: {
httpStatus: 403,
message: "Feature is not available for the customer.",
},
noCreditAvailable: {
httpStatus: 402,
message: "Customer has no credit available.",
},
usageLimitReached: {
httpStatus: 429,
message: "Customer has reached usage limit for feature.",
},
},
sslVerify: true,
syncRate: 2,
timeout: 10000,
},
consumer: {
id: "...my_id...",
},
controlPlaneId: "9524ec7d-36d9-465d-a8c5-83a3c9390458",
createdAt: 6,
enabled: true,
gatewayPluginEntitlementEnforcementId: "...my_id...",
instanceName: "...my_instance_name...",
ordering: {
after: {
accesses: ["..."],
},
before: {
accesses: ["..."],
},
},
partials: [{
id: "...my_id...",
name: "...my_name...",
path: "...my_path...",
}],
protocols: ["http"],
route: {
id: "...my_id...",
},
service: {
id: "...my_id...",
},
tags: ["..."],
updatedAt: 9,
});
import pulumi
import pulumi_konnect as konnect
my_gatewaypluginentitlementenforcement = konnect.GatewayPluginEntitlementEnforcement("my_gatewaypluginentitlementenforcement",
condition="...my_condition...",
config={
"api_token": "...my_api_token...",
"credit_balance_required": True,
"customer": {
"field": "...my_field...",
"look_up_value_in": "consumer",
},
"deny_unknown_customers": True,
"entitlement_access_endpoint": "...my_entitlement_access_endpoint...",
"fail_policy": "allow",
"feature": {
"key": "...my_key...",
},
"keepalive": 60000,
"l1_cache_ttl_seconds": 5,
"l2_cache_ttl_seconds": 120,
"max_stale_seconds": 60,
"redis": {
"cloud_authentication": {
"auth_provider": "oauth",
"aws_access_key_id": "...my_aws_access_key_id...",
"aws_assume_role_arn": "...my_aws_assume_role_arn...",
"aws_cache_name": "...my_aws_cache_name...",
"aws_is_serverless": True,
"aws_region": "...my_aws_region...",
"aws_role_session_name": "...my_aws_role_session_name...",
"aws_secret_access_key": "...my_aws_secret_access_key...",
"azure_client_id": "...my_azure_client_id...",
"azure_client_secret": "...my_azure_client_secret...",
"azure_tenant_id": "...my_azure_tenant_id...",
"gcp_service_account_json": "...my_gcp_service_account_json...",
"oauth": {
"auth_method": "client_secret_post",
"client_id": "...my_client_id...",
"client_secret": "...my_client_secret...",
"client_secret_jwt_alg": "HS512",
"grant_type": "client_credentials",
"password": "...my_password...",
"redis_username": "...my_redis_username...",
"redis_username_claim": "...my_redis_username_claim...",
"scopes": ["..."],
"ssl_verify": True,
"timeout": 10000,
"token_endpoint": "...my_token_endpoint...",
"token_headers": {
"key": "value",
},
"token_post_args": {
"key": "value",
},
"username": "...my_username...",
},
},
"cluster_max_redirections": 5,
"cluster_nodes": [{
"ip": "127.0.0.1",
"port": 6379,
}],
"connect_timeout": 2000,
"connection_is_proxied": False,
"database": 0,
"host": "127.0.0.1",
"keepalive_backlog": 2020228349,
"keepalive_pool_size": 256,
"password": "...my_password...",
"port": "6379",
"read_timeout": 2000,
"send_timeout": 2000,
"sentinel_master": "...my_sentinel_master...",
"sentinel_nodes": [{
"host": "127.0.0.1",
"port": 6379,
}],
"sentinel_password": "...my_sentinel_password...",
"sentinel_role": "master",
"sentinel_username": "...my_sentinel_username...",
"server_name": "...my_server_name...",
"ssl": False,
"ssl_verify": True,
"username": "...my_username...",
},
"refresh_interval": 30,
"response_codes": {
"customer_not_found": {
"http_status": 403,
"message": "Customer is not found by subject.",
},
"feature_not_found": {
"http_status": 403,
"message": "Feature not found.",
},
"feature_unavailable": {
"http_status": 403,
"message": "Feature is not available for the customer.",
},
"no_credit_available": {
"http_status": 402,
"message": "Customer has no credit available.",
},
"usage_limit_reached": {
"http_status": 429,
"message": "Customer has reached usage limit for feature.",
},
},
"ssl_verify": True,
"sync_rate": 2,
"timeout": 10000,
},
consumer={
"id": "...my_id...",
},
control_plane_id="9524ec7d-36d9-465d-a8c5-83a3c9390458",
created_at=6,
enabled=True,
gateway_plugin_entitlement_enforcement_id="...my_id...",
instance_name="...my_instance_name...",
ordering={
"after": {
"accesses": ["..."],
},
"before": {
"accesses": ["..."],
},
},
partials=[{
"id": "...my_id...",
"name": "...my_name...",
"path": "...my_path...",
}],
protocols=["http"],
route={
"id": "...my_id...",
},
service={
"id": "...my_id...",
},
tags=["..."],
updated_at=9)
package main
import (
"github.com/pulumi/pulumi-terraform-provider/sdks/go/konnect/v3/konnect"
"github.com/pulumi/pulumi/sdk/v3/go/pulumi"
)
func main() {
pulumi.Run(func(ctx *pulumi.Context) error {
_, err := konnect.NewGatewayPluginEntitlementEnforcement(ctx, "my_gatewaypluginentitlementenforcement", &konnect.GatewayPluginEntitlementEnforcementArgs{
Condition: pulumi.String("...my_condition..."),
Config: &konnect.GatewayPluginEntitlementEnforcementConfigArgs{
ApiToken: pulumi.String("...my_api_token..."),
CreditBalanceRequired: pulumi.Bool(true),
Customer: &konnect.GatewayPluginEntitlementEnforcementConfigCustomerArgs{
Field: pulumi.String("...my_field..."),
LookUpValueIn: pulumi.String("consumer"),
},
DenyUnknownCustomers: pulumi.Bool(true),
EntitlementAccessEndpoint: pulumi.String("...my_entitlement_access_endpoint..."),
FailPolicy: pulumi.String("allow"),
Feature: &konnect.GatewayPluginEntitlementEnforcementConfigFeatureArgs{
Key: pulumi.String("...my_key..."),
},
Keepalive: pulumi.Float64(60000),
L1CacheTtlSeconds: pulumi.Float64(5),
L2CacheTtlSeconds: pulumi.Float64(120),
MaxStaleSeconds: pulumi.Float64(60),
Redis: &konnect.GatewayPluginEntitlementEnforcementConfigRedisArgs{
CloudAuthentication: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs{
AuthProvider: pulumi.String("oauth"),
AwsAccessKeyId: pulumi.String("...my_aws_access_key_id..."),
AwsAssumeRoleArn: pulumi.String("...my_aws_assume_role_arn..."),
AwsCacheName: pulumi.String("...my_aws_cache_name..."),
AwsIsServerless: pulumi.Bool(true),
AwsRegion: pulumi.String("...my_aws_region..."),
AwsRoleSessionName: pulumi.String("...my_aws_role_session_name..."),
AwsSecretAccessKey: pulumi.String("...my_aws_secret_access_key..."),
AzureClientId: pulumi.String("...my_azure_client_id..."),
AzureClientSecret: pulumi.String("...my_azure_client_secret..."),
AzureTenantId: pulumi.String("...my_azure_tenant_id..."),
GcpServiceAccountJson: pulumi.String("...my_gcp_service_account_json..."),
Oauth: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs{
AuthMethod: pulumi.String("client_secret_post"),
ClientId: pulumi.String("...my_client_id..."),
ClientSecret: pulumi.String("...my_client_secret..."),
ClientSecretJwtAlg: pulumi.String("HS512"),
GrantType: pulumi.String("client_credentials"),
Password: pulumi.String("...my_password..."),
RedisUsername: pulumi.String("...my_redis_username..."),
RedisUsernameClaim: pulumi.String("...my_redis_username_claim..."),
Scopes: pulumi.StringArray{
pulumi.String("..."),
},
SslVerify: pulumi.Bool(true),
Timeout: pulumi.Float64(10000),
TokenEndpoint: pulumi.String("...my_token_endpoint..."),
TokenHeaders: pulumi.StringMap{
"key": pulumi.String("value"),
},
TokenPostArgs: pulumi.StringMap{
"key": pulumi.String("value"),
},
Username: pulumi.String("...my_username..."),
},
},
ClusterMaxRedirections: pulumi.Float64(5),
ClusterNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArray{
&konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs{
Ip: pulumi.String("127.0.0.1"),
Port: pulumi.Float64(6379),
},
},
ConnectTimeout: pulumi.Float64(2000),
ConnectionIsProxied: pulumi.Bool(false),
Database: pulumi.Float64(0),
Host: pulumi.String("127.0.0.1"),
KeepaliveBacklog: pulumi.Float64(2020228349),
KeepalivePoolSize: pulumi.Float64(256),
Password: pulumi.String("...my_password..."),
Port: pulumi.String("6379"),
ReadTimeout: pulumi.Float64(2000),
SendTimeout: pulumi.Float64(2000),
SentinelMaster: pulumi.String("...my_sentinel_master..."),
SentinelNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArray{
&konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs{
Host: pulumi.String("127.0.0.1"),
Port: pulumi.Float64(6379),
},
},
SentinelPassword: pulumi.String("...my_sentinel_password..."),
SentinelRole: pulumi.String("master"),
SentinelUsername: pulumi.String("...my_sentinel_username..."),
ServerName: pulumi.String("...my_server_name..."),
Ssl: pulumi.Bool(false),
SslVerify: pulumi.Bool(true),
Username: pulumi.String("...my_username..."),
},
RefreshInterval: pulumi.Float64(30),
ResponseCodes: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs{
CustomerNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs{
HttpStatus: pulumi.Float64(403),
Message: pulumi.String("Customer is not found by subject."),
},
FeatureNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs{
HttpStatus: pulumi.Float64(403),
Message: pulumi.String("Feature not found."),
},
FeatureUnavailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs{
HttpStatus: pulumi.Float64(403),
Message: pulumi.String("Feature is not available for the customer."),
},
NoCreditAvailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs{
HttpStatus: pulumi.Float64(402),
Message: pulumi.String("Customer has no credit available."),
},
UsageLimitReached: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs{
HttpStatus: pulumi.Float64(429),
Message: pulumi.String("Customer has reached usage limit for feature."),
},
},
SslVerify: pulumi.Bool(true),
SyncRate: pulumi.Float64(2),
Timeout: pulumi.Float64(10000),
},
Consumer: &konnect.GatewayPluginEntitlementEnforcementConsumerArgs{
Id: pulumi.String("...my_id..."),
},
ControlPlaneId: pulumi.String("9524ec7d-36d9-465d-a8c5-83a3c9390458"),
CreatedAt: pulumi.Float64(6),
Enabled: pulumi.Bool(true),
GatewayPluginEntitlementEnforcementId: pulumi.String("...my_id..."),
InstanceName: pulumi.String("...my_instance_name..."),
Ordering: &konnect.GatewayPluginEntitlementEnforcementOrderingArgs{
After: &konnect.GatewayPluginEntitlementEnforcementOrderingAfterArgs{
Accesses: pulumi.StringArray{
pulumi.String("..."),
},
},
Before: &konnect.GatewayPluginEntitlementEnforcementOrderingBeforeArgs{
Accesses: pulumi.StringArray{
pulumi.String("..."),
},
},
},
Partials: konnect.GatewayPluginEntitlementEnforcementPartialArray{
&konnect.GatewayPluginEntitlementEnforcementPartialArgs{
Id: pulumi.String("...my_id..."),
Name: pulumi.String("...my_name..."),
Path: pulumi.String("...my_path..."),
},
},
Protocols: pulumi.StringArray{
pulumi.String("http"),
},
Route: &konnect.GatewayPluginEntitlementEnforcementRouteArgs{
Id: pulumi.String("...my_id..."),
},
Service: &konnect.GatewayPluginEntitlementEnforcementServiceArgs{
Id: pulumi.String("...my_id..."),
},
Tags: pulumi.StringArray{
pulumi.String("..."),
},
UpdatedAt: pulumi.Float64(9),
})
if err != nil {
return err
}
return nil
})
}
using System.Collections.Generic;
using System.Linq;
using Pulumi;
using Konnect = Pulumi.Konnect;
return await Deployment.RunAsync(() =>
{
var myGatewaypluginentitlementenforcement = new Konnect.GatewayPluginEntitlementEnforcement("my_gatewaypluginentitlementenforcement", new()
{
Condition = "...my_condition...",
Config = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigArgs
{
ApiToken = "...my_api_token...",
CreditBalanceRequired = true,
Customer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigCustomerArgs
{
Field = "...my_field...",
LookUpValueIn = "consumer",
},
DenyUnknownCustomers = true,
EntitlementAccessEndpoint = "...my_entitlement_access_endpoint...",
FailPolicy = "allow",
Feature = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigFeatureArgs
{
Key = "...my_key...",
},
Keepalive = 60000,
L1CacheTtlSeconds = 5,
L2CacheTtlSeconds = 120,
MaxStaleSeconds = 60,
Redis = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisArgs
{
CloudAuthentication = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs
{
AuthProvider = "oauth",
AwsAccessKeyId = "...my_aws_access_key_id...",
AwsAssumeRoleArn = "...my_aws_assume_role_arn...",
AwsCacheName = "...my_aws_cache_name...",
AwsIsServerless = true,
AwsRegion = "...my_aws_region...",
AwsRoleSessionName = "...my_aws_role_session_name...",
AwsSecretAccessKey = "...my_aws_secret_access_key...",
AzureClientId = "...my_azure_client_id...",
AzureClientSecret = "...my_azure_client_secret...",
AzureTenantId = "...my_azure_tenant_id...",
GcpServiceAccountJson = "...my_gcp_service_account_json...",
Oauth = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs
{
AuthMethod = "client_secret_post",
ClientId = "...my_client_id...",
ClientSecret = "...my_client_secret...",
ClientSecretJwtAlg = "HS512",
GrantType = "client_credentials",
Password = "...my_password...",
RedisUsername = "...my_redis_username...",
RedisUsernameClaim = "...my_redis_username_claim...",
Scopes = new[]
{
"...",
},
SslVerify = true,
Timeout = 10000,
TokenEndpoint = "...my_token_endpoint...",
TokenHeaders =
{
{ "key", "value" },
},
TokenPostArgs =
{
{ "key", "value" },
},
Username = "...my_username...",
},
},
ClusterMaxRedirections = 5,
ClusterNodes = new[]
{
new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs
{
Ip = "127.0.0.1",
Port = 6379,
},
},
ConnectTimeout = 2000,
ConnectionIsProxied = false,
Database = 0,
Host = "127.0.0.1",
KeepaliveBacklog = 2020228349,
KeepalivePoolSize = 256,
Password = "...my_password...",
Port = "6379",
ReadTimeout = 2000,
SendTimeout = 2000,
SentinelMaster = "...my_sentinel_master...",
SentinelNodes = new[]
{
new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs
{
Host = "127.0.0.1",
Port = 6379,
},
},
SentinelPassword = "...my_sentinel_password...",
SentinelRole = "master",
SentinelUsername = "...my_sentinel_username...",
ServerName = "...my_server_name...",
Ssl = false,
SslVerify = true,
Username = "...my_username...",
},
RefreshInterval = 30,
ResponseCodes = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs
{
CustomerNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs
{
HttpStatus = 403,
Message = "Customer is not found by subject.",
},
FeatureNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs
{
HttpStatus = 403,
Message = "Feature not found.",
},
FeatureUnavailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs
{
HttpStatus = 403,
Message = "Feature is not available for the customer.",
},
NoCreditAvailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs
{
HttpStatus = 402,
Message = "Customer has no credit available.",
},
UsageLimitReached = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs
{
HttpStatus = 429,
Message = "Customer has reached usage limit for feature.",
},
},
SslVerify = true,
SyncRate = 2,
Timeout = 10000,
},
Consumer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConsumerArgs
{
Id = "...my_id...",
},
ControlPlaneId = "9524ec7d-36d9-465d-a8c5-83a3c9390458",
CreatedAt = 6,
Enabled = true,
GatewayPluginEntitlementEnforcementId = "...my_id...",
InstanceName = "...my_instance_name...",
Ordering = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingArgs
{
After = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingAfterArgs
{
Accesses = new[]
{
"...",
},
},
Before = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingBeforeArgs
{
Accesses = new[]
{
"...",
},
},
},
Partials = new[]
{
new Konnect.Inputs.GatewayPluginEntitlementEnforcementPartialArgs
{
Id = "...my_id...",
Name = "...my_name...",
Path = "...my_path...",
},
},
Protocols = new[]
{
"http",
},
Route = new Konnect.Inputs.GatewayPluginEntitlementEnforcementRouteArgs
{
Id = "...my_id...",
},
Service = new Konnect.Inputs.GatewayPluginEntitlementEnforcementServiceArgs
{
Id = "...my_id...",
},
Tags = new[]
{
"...",
},
UpdatedAt = 9,
});
});
package generated_program;
import com.pulumi.Context;
import com.pulumi.Pulumi;
import com.pulumi.core.Output;
import com.pulumi.konnect.GatewayPluginEntitlementEnforcement;
import com.pulumi.konnect.GatewayPluginEntitlementEnforcementArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigCustomerArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigFeatureArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigRedisArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementConsumerArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementOrderingArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementOrderingAfterArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementOrderingBeforeArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementPartialArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementRouteArgs;
import com.pulumi.konnect.inputs.GatewayPluginEntitlementEnforcementServiceArgs;
import java.util.List;
import java.util.ArrayList;
import java.util.Map;
import java.io.File;
import java.nio.file.Files;
import java.nio.file.Paths;
public class App {
public static void main(String[] args) {
Pulumi.run(App::stack);
}
public static void stack(Context ctx) {
var myGatewaypluginentitlementenforcement = new GatewayPluginEntitlementEnforcement("myGatewaypluginentitlementenforcement", GatewayPluginEntitlementEnforcementArgs.builder()
.condition("...my_condition...")
.config(GatewayPluginEntitlementEnforcementConfigArgs.builder()
.apiToken("...my_api_token...")
.creditBalanceRequired(true)
.customer(GatewayPluginEntitlementEnforcementConfigCustomerArgs.builder()
.field("...my_field...")
.lookUpValueIn("consumer")
.build())
.denyUnknownCustomers(true)
.entitlementAccessEndpoint("...my_entitlement_access_endpoint...")
.failPolicy("allow")
.feature(GatewayPluginEntitlementEnforcementConfigFeatureArgs.builder()
.key("...my_key...")
.build())
.keepalive(60000.0)
.l1CacheTtlSeconds(5.0)
.l2CacheTtlSeconds(120.0)
.maxStaleSeconds(60.0)
.redis(GatewayPluginEntitlementEnforcementConfigRedisArgs.builder()
.cloudAuthentication(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs.builder()
.authProvider("oauth")
.awsAccessKeyId("...my_aws_access_key_id...")
.awsAssumeRoleArn("...my_aws_assume_role_arn...")
.awsCacheName("...my_aws_cache_name...")
.awsIsServerless(true)
.awsRegion("...my_aws_region...")
.awsRoleSessionName("...my_aws_role_session_name...")
.awsSecretAccessKey("...my_aws_secret_access_key...")
.azureClientId("...my_azure_client_id...")
.azureClientSecret("...my_azure_client_secret...")
.azureTenantId("...my_azure_tenant_id...")
.gcpServiceAccountJson("...my_gcp_service_account_json...")
.oauth(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs.builder()
.authMethod("client_secret_post")
.clientId("...my_client_id...")
.clientSecret("...my_client_secret...")
.clientSecretJwtAlg("HS512")
.grantType("client_credentials")
.password("...my_password...")
.redisUsername("...my_redis_username...")
.redisUsernameClaim("...my_redis_username_claim...")
.scopes("...")
.sslVerify(true)
.timeout(10000.0)
.tokenEndpoint("...my_token_endpoint...")
.tokenHeaders(Map.of("key", "value"))
.tokenPostArgs(Map.of("key", "value"))
.username("...my_username...")
.build())
.build())
.clusterMaxRedirections(5.0)
.clusterNodes(GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs.builder()
.ip("127.0.0.1")
.port(6379.0)
.build())
.connectTimeout(2000.0)
.connectionIsProxied(false)
.database(0.0)
.host("127.0.0.1")
.keepaliveBacklog(2020228349.0)
.keepalivePoolSize(256.0)
.password("...my_password...")
.port("6379")
.readTimeout(2000.0)
.sendTimeout(2000.0)
.sentinelMaster("...my_sentinel_master...")
.sentinelNodes(GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs.builder()
.host("127.0.0.1")
.port(6379.0)
.build())
.sentinelPassword("...my_sentinel_password...")
.sentinelRole("master")
.sentinelUsername("...my_sentinel_username...")
.serverName("...my_server_name...")
.ssl(false)
.sslVerify(true)
.username("...my_username...")
.build())
.refreshInterval(30.0)
.responseCodes(GatewayPluginEntitlementEnforcementConfigResponseCodesArgs.builder()
.customerNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs.builder()
.httpStatus(403.0)
.message("Customer is not found by subject.")
.build())
.featureNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs.builder()
.httpStatus(403.0)
.message("Feature not found.")
.build())
.featureUnavailable(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs.builder()
.httpStatus(403.0)
.message("Feature is not available for the customer.")
.build())
.noCreditAvailable(GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs.builder()
.httpStatus(402.0)
.message("Customer has no credit available.")
.build())
.usageLimitReached(GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs.builder()
.httpStatus(429.0)
.message("Customer has reached usage limit for feature.")
.build())
.build())
.sslVerify(true)
.syncRate(2.0)
.timeout(10000.0)
.build())
.consumer(GatewayPluginEntitlementEnforcementConsumerArgs.builder()
.id("...my_id...")
.build())
.controlPlaneId("9524ec7d-36d9-465d-a8c5-83a3c9390458")
.createdAt(6.0)
.enabled(true)
.gatewayPluginEntitlementEnforcementId("...my_id...")
.instanceName("...my_instance_name...")
.ordering(GatewayPluginEntitlementEnforcementOrderingArgs.builder()
.after(GatewayPluginEntitlementEnforcementOrderingAfterArgs.builder()
.accesses("...")
.build())
.before(GatewayPluginEntitlementEnforcementOrderingBeforeArgs.builder()
.accesses("...")
.build())
.build())
.partials(GatewayPluginEntitlementEnforcementPartialArgs.builder()
.id("...my_id...")
.name("...my_name...")
.path("...my_path...")
.build())
.protocols("http")
.route(GatewayPluginEntitlementEnforcementRouteArgs.builder()
.id("...my_id...")
.build())
.service(GatewayPluginEntitlementEnforcementServiceArgs.builder()
.id("...my_id...")
.build())
.tags("...")
.updatedAt(9.0)
.build());
}
}
resources:
myGatewaypluginentitlementenforcement:
type: konnect:GatewayPluginEntitlementEnforcement
name: my_gatewaypluginentitlementenforcement
properties:
condition: '...my_condition...'
config:
apiToken: '...my_api_token...'
creditBalanceRequired: true
customer:
field: '...my_field...'
lookUpValueIn: consumer
denyUnknownCustomers: true
entitlementAccessEndpoint: '...my_entitlement_access_endpoint...'
failPolicy: allow
feature:
key: '...my_key...'
keepalive: 60000
l1CacheTtlSeconds: 5
l2CacheTtlSeconds: 120
maxStaleSeconds: 60
redis:
cloudAuthentication:
authProvider: oauth
awsAccessKeyId: '...my_aws_access_key_id...'
awsAssumeRoleArn: '...my_aws_assume_role_arn...'
awsCacheName: '...my_aws_cache_name...'
awsIsServerless: true
awsRegion: '...my_aws_region...'
awsRoleSessionName: '...my_aws_role_session_name...'
awsSecretAccessKey: '...my_aws_secret_access_key...'
azureClientId: '...my_azure_client_id...'
azureClientSecret: '...my_azure_client_secret...'
azureTenantId: '...my_azure_tenant_id...'
gcpServiceAccountJson: '...my_gcp_service_account_json...'
oauth:
authMethod: client_secret_post
clientId: '...my_client_id...'
clientSecret: '...my_client_secret...'
clientSecretJwtAlg: HS512
grantType: client_credentials
password: '...my_password...'
redisUsername: '...my_redis_username...'
redisUsernameClaim: '...my_redis_username_claim...'
scopes:
- '...'
sslVerify: true
timeout: 10000
tokenEndpoint: '...my_token_endpoint...'
tokenHeaders:
key: value
tokenPostArgs:
key: value
username: '...my_username...'
clusterMaxRedirections: 5
clusterNodes:
- ip: 127.0.0.1
port: 6379
connectTimeout: 2000
connectionIsProxied: false
database: 0
host: 127.0.0.1
keepaliveBacklog: 2.020228349e+09
keepalivePoolSize: 256
password: '...my_password...'
port: '6379'
readTimeout: 2000
sendTimeout: 2000
sentinelMaster: '...my_sentinel_master...'
sentinelNodes:
- host: 127.0.0.1
port: 6379
sentinelPassword: '...my_sentinel_password...'
sentinelRole: master
sentinelUsername: '...my_sentinel_username...'
serverName: '...my_server_name...'
ssl: false
sslVerify: true
username: '...my_username...'
refreshInterval: 30
responseCodes:
customerNotFound:
httpStatus: 403
message: Customer is not found by subject.
featureNotFound:
httpStatus: 403
message: Feature not found.
featureUnavailable:
httpStatus: 403
message: Feature is not available for the customer.
noCreditAvailable:
httpStatus: 402
message: Customer has no credit available.
usageLimitReached:
httpStatus: 429
message: Customer has reached usage limit for feature.
sslVerify: true
syncRate: 2
timeout: 10000
consumer:
id: '...my_id...'
controlPlaneId: 9524ec7d-36d9-465d-a8c5-83a3c9390458
createdAt: 6
enabled: true
gatewayPluginEntitlementEnforcementId: '...my_id...'
instanceName: '...my_instance_name...'
ordering:
after:
accesses:
- '...'
before:
accesses:
- '...'
partials:
- id: '...my_id...'
name: '...my_name...'
path: '...my_path...'
protocols:
- http
route:
id: '...my_id...'
service:
id: '...my_id...'
tags:
- '...'
updatedAt: 9
Example coming soon!
Create GatewayPluginEntitlementEnforcement Resource
Resources are created with functions called constructors. To learn more about declaring and configuring resources, see Resources.
Constructor syntax
new GatewayPluginEntitlementEnforcement(name: string, args: GatewayPluginEntitlementEnforcementArgs, opts?: CustomResourceOptions);@overload
def GatewayPluginEntitlementEnforcement(resource_name: str,
args: GatewayPluginEntitlementEnforcementArgs,
opts: Optional[ResourceOptions] = None)
@overload
def GatewayPluginEntitlementEnforcement(resource_name: str,
opts: Optional[ResourceOptions] = None,
control_plane_id: Optional[str] = None,
config: Optional[GatewayPluginEntitlementEnforcementConfigArgs] = None,
gateway_plugin_entitlement_enforcement_id: Optional[str] = None,
consumer: Optional[GatewayPluginEntitlementEnforcementConsumerArgs] = None,
created_at: Optional[float] = None,
enabled: Optional[bool] = None,
condition: Optional[str] = None,
instance_name: Optional[str] = None,
ordering: Optional[GatewayPluginEntitlementEnforcementOrderingArgs] = None,
partials: Optional[Sequence[GatewayPluginEntitlementEnforcementPartialArgs]] = None,
protocols: Optional[Sequence[str]] = None,
route: Optional[GatewayPluginEntitlementEnforcementRouteArgs] = None,
service: Optional[GatewayPluginEntitlementEnforcementServiceArgs] = None,
tags: Optional[Sequence[str]] = None,
updated_at: Optional[float] = None)func NewGatewayPluginEntitlementEnforcement(ctx *Context, name string, args GatewayPluginEntitlementEnforcementArgs, opts ...ResourceOption) (*GatewayPluginEntitlementEnforcement, error)public GatewayPluginEntitlementEnforcement(string name, GatewayPluginEntitlementEnforcementArgs args, CustomResourceOptions? opts = null)
public GatewayPluginEntitlementEnforcement(String name, GatewayPluginEntitlementEnforcementArgs args)
public GatewayPluginEntitlementEnforcement(String name, GatewayPluginEntitlementEnforcementArgs args, CustomResourceOptions options)
type: konnect:GatewayPluginEntitlementEnforcement
properties: # The arguments to resource properties.
options: # Bag of options to control resource's behavior.
resource "konnect_gateway_plugin_entitlement_enforcement" "name" {
# resource properties
}Parameters
- name string
- The unique name of the resource.
- args GatewayPluginEntitlementEnforcementArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- resource_name str
- The unique name of the resource.
- args GatewayPluginEntitlementEnforcementArgs
- The arguments to resource properties.
- opts ResourceOptions
- Bag of options to control resource's behavior.
- ctx Context
- Context object for the current deployment.
- name string
- The unique name of the resource.
- args GatewayPluginEntitlementEnforcementArgs
- The arguments to resource properties.
- opts ResourceOption
- Bag of options to control resource's behavior.
- name string
- The unique name of the resource.
- args GatewayPluginEntitlementEnforcementArgs
- The arguments to resource properties.
- opts CustomResourceOptions
- Bag of options to control resource's behavior.
- name String
- The unique name of the resource.
- args GatewayPluginEntitlementEnforcementArgs
- The arguments to resource properties.
- options CustomResourceOptions
- Bag of options to control resource's behavior.
Constructor example
The following reference example uses placeholder values for all input properties.
var gatewayPluginEntitlementEnforcementResource = new Konnect.GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource", new()
{
ControlPlaneId = "string",
Config = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigArgs
{
EntitlementAccessEndpoint = "string",
ApiToken = "string",
Feature = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigFeatureArgs
{
Key = "string",
},
L1CacheTtlSeconds = 0.0,
MaxStaleSeconds = 0.0,
FailPolicy = "string",
Customer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigCustomerArgs
{
Field = "string",
LookUpValueIn = "string",
},
Keepalive = 0.0,
CreditBalanceRequired = false,
L2CacheTtlSeconds = 0.0,
DenyUnknownCustomers = false,
Redis = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisArgs
{
CloudAuthentication = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs
{
AuthProvider = "string",
AwsAccessKeyId = "string",
AwsAssumeRoleArn = "string",
AwsCacheName = "string",
AwsIsServerless = false,
AwsRegion = "string",
AwsRoleSessionName = "string",
AwsSecretAccessKey = "string",
AzureClientId = "string",
AzureClientSecret = "string",
AzureTenantId = "string",
GcpServiceAccountJson = "string",
Oauth = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs
{
AuthMethod = "string",
ClientId = "string",
ClientSecret = "string",
ClientSecretJwtAlg = "string",
GrantType = "string",
Password = "string",
RedisUsername = "string",
RedisUsernameClaim = "string",
Scopes = new[]
{
"string",
},
SslVerify = false,
Timeout = 0.0,
TokenEndpoint = "string",
TokenHeaders =
{
{ "string", "string" },
},
TokenPostArgs =
{
{ "string", "string" },
},
Username = "string",
},
},
ClusterMaxRedirections = 0.0,
ClusterNodes = new[]
{
new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs
{
Ip = "string",
Port = 0.0,
},
},
ConnectTimeout = 0.0,
ConnectionIsProxied = false,
Database = 0.0,
Host = "string",
KeepaliveBacklog = 0.0,
KeepalivePoolSize = 0.0,
Password = "string",
Port = "string",
ReadTimeout = 0.0,
SendTimeout = 0.0,
SentinelMaster = "string",
SentinelNodes = new[]
{
new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs
{
Host = "string",
Port = 0.0,
},
},
SentinelPassword = "string",
SentinelRole = "string",
SentinelUsername = "string",
ServerName = "string",
Ssl = false,
SslVerify = false,
Username = "string",
},
RefreshInterval = 0.0,
ResponseCodes = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs
{
CustomerNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs
{
HttpStatus = 0.0,
Message = "string",
},
FeatureNotFound = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs
{
HttpStatus = 0.0,
Message = "string",
},
FeatureUnavailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs
{
HttpStatus = 0.0,
Message = "string",
},
NoCreditAvailable = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs
{
HttpStatus = 0.0,
Message = "string",
},
UsageLimitReached = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs
{
HttpStatus = 0.0,
Message = "string",
},
},
SslVerify = false,
SyncRate = 0.0,
Timeout = 0.0,
},
GatewayPluginEntitlementEnforcementId = "string",
Consumer = new Konnect.Inputs.GatewayPluginEntitlementEnforcementConsumerArgs
{
Id = "string",
},
CreatedAt = 0.0,
Enabled = false,
Condition = "string",
InstanceName = "string",
Ordering = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingArgs
{
After = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingAfterArgs
{
Accesses = new[]
{
"string",
},
},
Before = new Konnect.Inputs.GatewayPluginEntitlementEnforcementOrderingBeforeArgs
{
Accesses = new[]
{
"string",
},
},
},
Partials = new[]
{
new Konnect.Inputs.GatewayPluginEntitlementEnforcementPartialArgs
{
Id = "string",
Name = "string",
Path = "string",
},
},
Protocols = new[]
{
"string",
},
Route = new Konnect.Inputs.GatewayPluginEntitlementEnforcementRouteArgs
{
Id = "string",
},
Service = new Konnect.Inputs.GatewayPluginEntitlementEnforcementServiceArgs
{
Id = "string",
},
Tags = new[]
{
"string",
},
UpdatedAt = 0.0,
});
example, err := konnect.NewGatewayPluginEntitlementEnforcement(ctx, "gatewayPluginEntitlementEnforcementResource", &konnect.GatewayPluginEntitlementEnforcementArgs{
ControlPlaneId: pulumi.String("string"),
Config: &konnect.GatewayPluginEntitlementEnforcementConfigArgs{
EntitlementAccessEndpoint: pulumi.String("string"),
ApiToken: pulumi.String("string"),
Feature: &konnect.GatewayPluginEntitlementEnforcementConfigFeatureArgs{
Key: pulumi.String("string"),
},
L1CacheTtlSeconds: pulumi.Float64(0),
MaxStaleSeconds: pulumi.Float64(0),
FailPolicy: pulumi.String("string"),
Customer: &konnect.GatewayPluginEntitlementEnforcementConfigCustomerArgs{
Field: pulumi.String("string"),
LookUpValueIn: pulumi.String("string"),
},
Keepalive: pulumi.Float64(0),
CreditBalanceRequired: pulumi.Bool(false),
L2CacheTtlSeconds: pulumi.Float64(0),
DenyUnknownCustomers: pulumi.Bool(false),
Redis: &konnect.GatewayPluginEntitlementEnforcementConfigRedisArgs{
CloudAuthentication: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs{
AuthProvider: pulumi.String("string"),
AwsAccessKeyId: pulumi.String("string"),
AwsAssumeRoleArn: pulumi.String("string"),
AwsCacheName: pulumi.String("string"),
AwsIsServerless: pulumi.Bool(false),
AwsRegion: pulumi.String("string"),
AwsRoleSessionName: pulumi.String("string"),
AwsSecretAccessKey: pulumi.String("string"),
AzureClientId: pulumi.String("string"),
AzureClientSecret: pulumi.String("string"),
AzureTenantId: pulumi.String("string"),
GcpServiceAccountJson: pulumi.String("string"),
Oauth: &konnect.GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs{
AuthMethod: pulumi.String("string"),
ClientId: pulumi.String("string"),
ClientSecret: pulumi.String("string"),
ClientSecretJwtAlg: pulumi.String("string"),
GrantType: pulumi.String("string"),
Password: pulumi.String("string"),
RedisUsername: pulumi.String("string"),
RedisUsernameClaim: pulumi.String("string"),
Scopes: pulumi.StringArray{
pulumi.String("string"),
},
SslVerify: pulumi.Bool(false),
Timeout: pulumi.Float64(0),
TokenEndpoint: pulumi.String("string"),
TokenHeaders: pulumi.StringMap{
"string": pulumi.String("string"),
},
TokenPostArgs: pulumi.StringMap{
"string": pulumi.String("string"),
},
Username: pulumi.String("string"),
},
},
ClusterMaxRedirections: pulumi.Float64(0),
ClusterNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArray{
&konnect.GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs{
Ip: pulumi.String("string"),
Port: pulumi.Float64(0),
},
},
ConnectTimeout: pulumi.Float64(0),
ConnectionIsProxied: pulumi.Bool(false),
Database: pulumi.Float64(0),
Host: pulumi.String("string"),
KeepaliveBacklog: pulumi.Float64(0),
KeepalivePoolSize: pulumi.Float64(0),
Password: pulumi.String("string"),
Port: pulumi.String("string"),
ReadTimeout: pulumi.Float64(0),
SendTimeout: pulumi.Float64(0),
SentinelMaster: pulumi.String("string"),
SentinelNodes: konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArray{
&konnect.GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs{
Host: pulumi.String("string"),
Port: pulumi.Float64(0),
},
},
SentinelPassword: pulumi.String("string"),
SentinelRole: pulumi.String("string"),
SentinelUsername: pulumi.String("string"),
ServerName: pulumi.String("string"),
Ssl: pulumi.Bool(false),
SslVerify: pulumi.Bool(false),
Username: pulumi.String("string"),
},
RefreshInterval: pulumi.Float64(0),
ResponseCodes: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesArgs{
CustomerNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs{
HttpStatus: pulumi.Float64(0),
Message: pulumi.String("string"),
},
FeatureNotFound: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs{
HttpStatus: pulumi.Float64(0),
Message: pulumi.String("string"),
},
FeatureUnavailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs{
HttpStatus: pulumi.Float64(0),
Message: pulumi.String("string"),
},
NoCreditAvailable: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs{
HttpStatus: pulumi.Float64(0),
Message: pulumi.String("string"),
},
UsageLimitReached: &konnect.GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs{
HttpStatus: pulumi.Float64(0),
Message: pulumi.String("string"),
},
},
SslVerify: pulumi.Bool(false),
SyncRate: pulumi.Float64(0),
Timeout: pulumi.Float64(0),
},
GatewayPluginEntitlementEnforcementId: pulumi.String("string"),
Consumer: &konnect.GatewayPluginEntitlementEnforcementConsumerArgs{
Id: pulumi.String("string"),
},
CreatedAt: pulumi.Float64(0),
Enabled: pulumi.Bool(false),
Condition: pulumi.String("string"),
InstanceName: pulumi.String("string"),
Ordering: &konnect.GatewayPluginEntitlementEnforcementOrderingArgs{
After: &konnect.GatewayPluginEntitlementEnforcementOrderingAfterArgs{
Accesses: pulumi.StringArray{
pulumi.String("string"),
},
},
Before: &konnect.GatewayPluginEntitlementEnforcementOrderingBeforeArgs{
Accesses: pulumi.StringArray{
pulumi.String("string"),
},
},
},
Partials: konnect.GatewayPluginEntitlementEnforcementPartialArray{
&konnect.GatewayPluginEntitlementEnforcementPartialArgs{
Id: pulumi.String("string"),
Name: pulumi.String("string"),
Path: pulumi.String("string"),
},
},
Protocols: pulumi.StringArray{
pulumi.String("string"),
},
Route: &konnect.GatewayPluginEntitlementEnforcementRouteArgs{
Id: pulumi.String("string"),
},
Service: &konnect.GatewayPluginEntitlementEnforcementServiceArgs{
Id: pulumi.String("string"),
},
Tags: pulumi.StringArray{
pulumi.String("string"),
},
UpdatedAt: pulumi.Float64(0),
})
resource "konnect_gateway_plugin_entitlement_enforcement" "gatewayPluginEntitlementEnforcementResource" {
lifecycle {
create_before_destroy = true
}
control_plane_id = "string"
config = {
entitlement_access_endpoint = "string"
api_token = "string"
feature = {
key = "string"
}
l1_cache_ttl_seconds = 0
max_stale_seconds = 0
fail_policy = "string"
customer = {
field = "string"
look_up_value_in = "string"
}
keepalive = 0
credit_balance_required = false
l2_cache_ttl_seconds = 0
deny_unknown_customers = false
redis = {
cloud_authentication = {
auth_provider = "string"
aws_access_key_id = "string"
aws_assume_role_arn = "string"
aws_cache_name = "string"
aws_is_serverless = false
aws_region = "string"
aws_role_session_name = "string"
aws_secret_access_key = "string"
azure_client_id = "string"
azure_client_secret = "string"
azure_tenant_id = "string"
gcp_service_account_json = "string"
oauth = {
auth_method = "string"
client_id = "string"
client_secret = "string"
client_secret_jwt_alg = "string"
grant_type = "string"
password = "string"
redis_username = "string"
redis_username_claim = "string"
scopes = ["string"]
ssl_verify = false
timeout = 0
token_endpoint = "string"
token_headers = {
"string" = "string"
}
token_post_args = {
"string" = "string"
}
username = "string"
}
}
cluster_max_redirections = 0
cluster_nodes = [{
ip = "string"
port = 0
}]
connect_timeout = 0
connection_is_proxied = false
database = 0
host = "string"
keepalive_backlog = 0
keepalive_pool_size = 0
password = "string"
port = "string"
read_timeout = 0
send_timeout = 0
sentinel_master = "string"
sentinel_nodes = [{
host = "string"
port = 0
}]
sentinel_password = "string"
sentinel_role = "string"
sentinel_username = "string"
server_name = "string"
ssl = false
ssl_verify = false
username = "string"
}
refresh_interval = 0
response_codes = {
customer_not_found = {
http_status = 0
message = "string"
}
feature_not_found = {
http_status = 0
message = "string"
}
feature_unavailable = {
http_status = 0
message = "string"
}
no_credit_available = {
http_status = 0
message = "string"
}
usage_limit_reached = {
http_status = 0
message = "string"
}
}
ssl_verify = false
sync_rate = 0
timeout = 0
}
gateway_plugin_entitlement_enforcement_id = "string"
consumer = {
id = "string"
}
created_at = 0
enabled = false
condition = "string"
instance_name = "string"
ordering = {
after = {
accesses = ["string"]
}
before = {
accesses = ["string"]
}
}
partials {
id = "string"
name = "string"
path = "string"
}
protocols = ["string"]
route = {
id = "string"
}
service = {
id = "string"
}
tags = ["string"]
updated_at = 0
}
var gatewayPluginEntitlementEnforcementResource = new GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource", GatewayPluginEntitlementEnforcementArgs.builder()
.controlPlaneId("string")
.config(GatewayPluginEntitlementEnforcementConfigArgs.builder()
.entitlementAccessEndpoint("string")
.apiToken("string")
.feature(GatewayPluginEntitlementEnforcementConfigFeatureArgs.builder()
.key("string")
.build())
.l1CacheTtlSeconds(0.0)
.maxStaleSeconds(0.0)
.failPolicy("string")
.customer(GatewayPluginEntitlementEnforcementConfigCustomerArgs.builder()
.field("string")
.lookUpValueIn("string")
.build())
.keepalive(0.0)
.creditBalanceRequired(false)
.l2CacheTtlSeconds(0.0)
.denyUnknownCustomers(false)
.redis(GatewayPluginEntitlementEnforcementConfigRedisArgs.builder()
.cloudAuthentication(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs.builder()
.authProvider("string")
.awsAccessKeyId("string")
.awsAssumeRoleArn("string")
.awsCacheName("string")
.awsIsServerless(false)
.awsRegion("string")
.awsRoleSessionName("string")
.awsSecretAccessKey("string")
.azureClientId("string")
.azureClientSecret("string")
.azureTenantId("string")
.gcpServiceAccountJson("string")
.oauth(GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs.builder()
.authMethod("string")
.clientId("string")
.clientSecret("string")
.clientSecretJwtAlg("string")
.grantType("string")
.password("string")
.redisUsername("string")
.redisUsernameClaim("string")
.scopes("string")
.sslVerify(false)
.timeout(0.0)
.tokenEndpoint("string")
.tokenHeaders(Map.of("string", "string"))
.tokenPostArgs(Map.of("string", "string"))
.username("string")
.build())
.build())
.clusterMaxRedirections(0.0)
.clusterNodes(GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs.builder()
.ip("string")
.port(0.0)
.build())
.connectTimeout(0.0)
.connectionIsProxied(false)
.database(0.0)
.host("string")
.keepaliveBacklog(0.0)
.keepalivePoolSize(0.0)
.password("string")
.port("string")
.readTimeout(0.0)
.sendTimeout(0.0)
.sentinelMaster("string")
.sentinelNodes(GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs.builder()
.host("string")
.port(0.0)
.build())
.sentinelPassword("string")
.sentinelRole("string")
.sentinelUsername("string")
.serverName("string")
.ssl(false)
.sslVerify(false)
.username("string")
.build())
.refreshInterval(0.0)
.responseCodes(GatewayPluginEntitlementEnforcementConfigResponseCodesArgs.builder()
.customerNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs.builder()
.httpStatus(0.0)
.message("string")
.build())
.featureNotFound(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs.builder()
.httpStatus(0.0)
.message("string")
.build())
.featureUnavailable(GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs.builder()
.httpStatus(0.0)
.message("string")
.build())
.noCreditAvailable(GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs.builder()
.httpStatus(0.0)
.message("string")
.build())
.usageLimitReached(GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs.builder()
.httpStatus(0.0)
.message("string")
.build())
.build())
.sslVerify(false)
.syncRate(0.0)
.timeout(0.0)
.build())
.gatewayPluginEntitlementEnforcementId("string")
.consumer(GatewayPluginEntitlementEnforcementConsumerArgs.builder()
.id("string")
.build())
.createdAt(0.0)
.enabled(false)
.condition("string")
.instanceName("string")
.ordering(GatewayPluginEntitlementEnforcementOrderingArgs.builder()
.after(GatewayPluginEntitlementEnforcementOrderingAfterArgs.builder()
.accesses("string")
.build())
.before(GatewayPluginEntitlementEnforcementOrderingBeforeArgs.builder()
.accesses("string")
.build())
.build())
.partials(GatewayPluginEntitlementEnforcementPartialArgs.builder()
.id("string")
.name("string")
.path("string")
.build())
.protocols("string")
.route(GatewayPluginEntitlementEnforcementRouteArgs.builder()
.id("string")
.build())
.service(GatewayPluginEntitlementEnforcementServiceArgs.builder()
.id("string")
.build())
.tags("string")
.updatedAt(0.0)
.build());
gateway_plugin_entitlement_enforcement_resource = konnect.GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource",
control_plane_id="string",
config={
"entitlement_access_endpoint": "string",
"api_token": "string",
"feature": {
"key": "string",
},
"l1_cache_ttl_seconds": float(0),
"max_stale_seconds": float(0),
"fail_policy": "string",
"customer": {
"field": "string",
"look_up_value_in": "string",
},
"keepalive": float(0),
"credit_balance_required": False,
"l2_cache_ttl_seconds": float(0),
"deny_unknown_customers": False,
"redis": {
"cloud_authentication": {
"auth_provider": "string",
"aws_access_key_id": "string",
"aws_assume_role_arn": "string",
"aws_cache_name": "string",
"aws_is_serverless": False,
"aws_region": "string",
"aws_role_session_name": "string",
"aws_secret_access_key": "string",
"azure_client_id": "string",
"azure_client_secret": "string",
"azure_tenant_id": "string",
"gcp_service_account_json": "string",
"oauth": {
"auth_method": "string",
"client_id": "string",
"client_secret": "string",
"client_secret_jwt_alg": "string",
"grant_type": "string",
"password": "string",
"redis_username": "string",
"redis_username_claim": "string",
"scopes": ["string"],
"ssl_verify": False,
"timeout": float(0),
"token_endpoint": "string",
"token_headers": {
"string": "string",
},
"token_post_args": {
"string": "string",
},
"username": "string",
},
},
"cluster_max_redirections": float(0),
"cluster_nodes": [{
"ip": "string",
"port": float(0),
}],
"connect_timeout": float(0),
"connection_is_proxied": False,
"database": float(0),
"host": "string",
"keepalive_backlog": float(0),
"keepalive_pool_size": float(0),
"password": "string",
"port": "string",
"read_timeout": float(0),
"send_timeout": float(0),
"sentinel_master": "string",
"sentinel_nodes": [{
"host": "string",
"port": float(0),
}],
"sentinel_password": "string",
"sentinel_role": "string",
"sentinel_username": "string",
"server_name": "string",
"ssl": False,
"ssl_verify": False,
"username": "string",
},
"refresh_interval": float(0),
"response_codes": {
"customer_not_found": {
"http_status": float(0),
"message": "string",
},
"feature_not_found": {
"http_status": float(0),
"message": "string",
},
"feature_unavailable": {
"http_status": float(0),
"message": "string",
},
"no_credit_available": {
"http_status": float(0),
"message": "string",
},
"usage_limit_reached": {
"http_status": float(0),
"message": "string",
},
},
"ssl_verify": False,
"sync_rate": float(0),
"timeout": float(0),
},
gateway_plugin_entitlement_enforcement_id="string",
consumer={
"id": "string",
},
created_at=float(0),
enabled=False,
condition="string",
instance_name="string",
ordering={
"after": {
"accesses": ["string"],
},
"before": {
"accesses": ["string"],
},
},
partials=[{
"id": "string",
"name": "string",
"path": "string",
}],
protocols=["string"],
route={
"id": "string",
},
service={
"id": "string",
},
tags=["string"],
updated_at=float(0))
const gatewayPluginEntitlementEnforcementResource = new konnect.GatewayPluginEntitlementEnforcement("gatewayPluginEntitlementEnforcementResource", {
controlPlaneId: "string",
config: {
entitlementAccessEndpoint: "string",
apiToken: "string",
feature: {
key: "string",
},
l1CacheTtlSeconds: 0,
maxStaleSeconds: 0,
failPolicy: "string",
customer: {
field: "string",
lookUpValueIn: "string",
},
keepalive: 0,
creditBalanceRequired: false,
l2CacheTtlSeconds: 0,
denyUnknownCustomers: false,
redis: {
cloudAuthentication: {
authProvider: "string",
awsAccessKeyId: "string",
awsAssumeRoleArn: "string",
awsCacheName: "string",
awsIsServerless: false,
awsRegion: "string",
awsRoleSessionName: "string",
awsSecretAccessKey: "string",
azureClientId: "string",
azureClientSecret: "string",
azureTenantId: "string",
gcpServiceAccountJson: "string",
oauth: {
authMethod: "string",
clientId: "string",
clientSecret: "string",
clientSecretJwtAlg: "string",
grantType: "string",
password: "string",
redisUsername: "string",
redisUsernameClaim: "string",
scopes: ["string"],
sslVerify: false,
timeout: 0,
tokenEndpoint: "string",
tokenHeaders: {
string: "string",
},
tokenPostArgs: {
string: "string",
},
username: "string",
},
},
clusterMaxRedirections: 0,
clusterNodes: [{
ip: "string",
port: 0,
}],
connectTimeout: 0,
connectionIsProxied: false,
database: 0,
host: "string",
keepaliveBacklog: 0,
keepalivePoolSize: 0,
password: "string",
port: "string",
readTimeout: 0,
sendTimeout: 0,
sentinelMaster: "string",
sentinelNodes: [{
host: "string",
port: 0,
}],
sentinelPassword: "string",
sentinelRole: "string",
sentinelUsername: "string",
serverName: "string",
ssl: false,
sslVerify: false,
username: "string",
},
refreshInterval: 0,
responseCodes: {
customerNotFound: {
httpStatus: 0,
message: "string",
},
featureNotFound: {
httpStatus: 0,
message: "string",
},
featureUnavailable: {
httpStatus: 0,
message: "string",
},
noCreditAvailable: {
httpStatus: 0,
message: "string",
},
usageLimitReached: {
httpStatus: 0,
message: "string",
},
},
sslVerify: false,
syncRate: 0,
timeout: 0,
},
gatewayPluginEntitlementEnforcementId: "string",
consumer: {
id: "string",
},
createdAt: 0,
enabled: false,
condition: "string",
instanceName: "string",
ordering: {
after: {
accesses: ["string"],
},
before: {
accesses: ["string"],
},
},
partials: [{
id: "string",
name: "string",
path: "string",
}],
protocols: ["string"],
route: {
id: "string",
},
service: {
id: "string",
},
tags: ["string"],
updatedAt: 0,
});
type: konnect:GatewayPluginEntitlementEnforcement
properties:
condition: string
config:
apiToken: string
creditBalanceRequired: false
customer:
field: string
lookUpValueIn: string
denyUnknownCustomers: false
entitlementAccessEndpoint: string
failPolicy: string
feature:
key: string
keepalive: 0
l1CacheTtlSeconds: 0
l2CacheTtlSeconds: 0
maxStaleSeconds: 0
redis:
cloudAuthentication:
authProvider: string
awsAccessKeyId: string
awsAssumeRoleArn: string
awsCacheName: string
awsIsServerless: false
awsRegion: string
awsRoleSessionName: string
awsSecretAccessKey: string
azureClientId: string
azureClientSecret: string
azureTenantId: string
gcpServiceAccountJson: string
oauth:
authMethod: string
clientId: string
clientSecret: string
clientSecretJwtAlg: string
grantType: string
password: string
redisUsername: string
redisUsernameClaim: string
scopes:
- string
sslVerify: false
timeout: 0
tokenEndpoint: string
tokenHeaders:
string: string
tokenPostArgs:
string: string
username: string
clusterMaxRedirections: 0
clusterNodes:
- ip: string
port: 0
connectTimeout: 0
connectionIsProxied: false
database: 0
host: string
keepaliveBacklog: 0
keepalivePoolSize: 0
password: string
port: string
readTimeout: 0
sendTimeout: 0
sentinelMaster: string
sentinelNodes:
- host: string
port: 0
sentinelPassword: string
sentinelRole: string
sentinelUsername: string
serverName: string
ssl: false
sslVerify: false
username: string
refreshInterval: 0
responseCodes:
customerNotFound:
httpStatus: 0
message: string
featureNotFound:
httpStatus: 0
message: string
featureUnavailable:
httpStatus: 0
message: string
noCreditAvailable:
httpStatus: 0
message: string
usageLimitReached:
httpStatus: 0
message: string
sslVerify: false
syncRate: 0
timeout: 0
consumer:
id: string
controlPlaneId: string
createdAt: 0
enabled: false
gatewayPluginEntitlementEnforcementId: string
instanceName: string
ordering:
after:
accesses:
- string
before:
accesses:
- string
partials:
- id: string
name: string
path: string
protocols:
- string
route:
id: string
service:
id: string
tags:
- string
updatedAt: 0
GatewayPluginEntitlementEnforcement Resource Properties
To learn more about resource properties and how to use them, see Inputs and Outputs in the Architecture and Concepts docs.
Inputs
In Python, inputs that are objects can be passed either as argument classes or as dictionary literals.
The GatewayPluginEntitlementEnforcement resource accepts the following input properties:
- Config
Gateway
Plugin Entitlement Enforcement Config - Control
Plane stringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- Condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - Consumer
Gateway
Plugin Entitlement Enforcement Consumer - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- Created
At double - Unix epoch when the resource was created.
- Enabled bool
- Whether the plugin is applied. Default: true
- Gateway
Plugin stringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- Instance
Name string - A unique string representing a UTF-8 encoded name.
- Ordering
Gateway
Plugin Entitlement Enforcement Ordering - Partials
List<Gateway
Plugin Entitlement Enforcement Partial> - A list of partials to be used by the plugin.
- Protocols List<string>
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- Route
Gateway
Plugin Entitlement Enforcement Route - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- Service
Gateway
Plugin Entitlement Enforcement Service - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- List<string>
- An optional set of strings associated with the Plugin for grouping and filtering.
- Updated
At double - Unix epoch when the resource was last updated.
- Config
Gateway
Plugin Entitlement Enforcement Config Args - Control
Plane stringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- Condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - Consumer
Gateway
Plugin Entitlement Enforcement Consumer Args - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- Created
At float64 - Unix epoch when the resource was created.
- Enabled bool
- Whether the plugin is applied. Default: true
- Gateway
Plugin stringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- Instance
Name string - A unique string representing a UTF-8 encoded name.
- Ordering
Gateway
Plugin Entitlement Enforcement Ordering Args - Partials
[]Gateway
Plugin Entitlement Enforcement Partial Args - A list of partials to be used by the plugin.
- Protocols []string
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- Route
Gateway
Plugin Entitlement Enforcement Route Args - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- Service
Gateway
Plugin Entitlement Enforcement Service Args - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- []string
- An optional set of strings associated with the Plugin for grouping and filtering.
- Updated
At float64 - Unix epoch when the resource was last updated.
- config object
- control_
plane_ stringid - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - consumer object
- If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- created_
at number - Unix epoch when the resource was created.
- enabled bool
- Whether the plugin is applied. Default: true
- gateway_
plugin_ stringentitlement_ enforcement_ id - A string representing a UUID (universally unique identifier).
- instance_
name string - A unique string representing a UTF-8 encoded name.
- ordering object
- partials list(object)
- A list of partials to be used by the plugin.
- protocols list(string)
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route object
- If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service object
- If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- list(string)
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated_
at number - Unix epoch when the resource was last updated.
- config
Gateway
Plugin Entitlement Enforcement Config - control
Plane StringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- condition String
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - consumer
Gateway
Plugin Entitlement Enforcement Consumer - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- created
At Double - Unix epoch when the resource was created.
- enabled Boolean
- Whether the plugin is applied. Default: true
- gateway
Plugin StringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- instance
Name String - A unique string representing a UTF-8 encoded name.
- ordering
Gateway
Plugin Entitlement Enforcement Ordering - partials
List<Gateway
Plugin Entitlement Enforcement Partial> - A list of partials to be used by the plugin.
- protocols List<String>
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route
Gateway
Plugin Entitlement Enforcement Route - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service
Gateway
Plugin Entitlement Enforcement Service - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- List<String>
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated
At Double - Unix epoch when the resource was last updated.
- config
Gateway
Plugin Entitlement Enforcement Config - control
Plane stringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - consumer
Gateway
Plugin Entitlement Enforcement Consumer - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- created
At number - Unix epoch when the resource was created.
- enabled boolean
- Whether the plugin is applied. Default: true
- gateway
Plugin stringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- instance
Name string - A unique string representing a UTF-8 encoded name.
- ordering
Gateway
Plugin Entitlement Enforcement Ordering - partials
Gateway
Plugin Entitlement Enforcement Partial[] - A list of partials to be used by the plugin.
- protocols string[]
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route
Gateway
Plugin Entitlement Enforcement Route - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service
Gateway
Plugin Entitlement Enforcement Service - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- string[]
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated
At number - Unix epoch when the resource was last updated.
- config
Gateway
Plugin Entitlement Enforcement Config Args - control_
plane_ strid - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- condition str
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - consumer
Gateway
Plugin Entitlement Enforcement Consumer Args - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- created_
at float - Unix epoch when the resource was created.
- enabled bool
- Whether the plugin is applied. Default: true
- gateway_
plugin_ strentitlement_ enforcement_ id - A string representing a UUID (universally unique identifier).
- instance_
name str - A unique string representing a UTF-8 encoded name.
- ordering
Gateway
Plugin Entitlement Enforcement Ordering Args - partials
Sequence[Gateway
Plugin Entitlement Enforcement Partial Args] - A list of partials to be used by the plugin.
- protocols Sequence[str]
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route
Gateway
Plugin Entitlement Enforcement Route Args - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service
Gateway
Plugin Entitlement Enforcement Service Args - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- Sequence[str]
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated_
at float - Unix epoch when the resource was last updated.
- config Property Map
- control
Plane StringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- condition String
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - consumer Property Map
- If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- created
At Number - Unix epoch when the resource was created.
- enabled Boolean
- Whether the plugin is applied. Default: true
- gateway
Plugin StringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- instance
Name String - A unique string representing a UTF-8 encoded name.
- ordering Property Map
- partials List<Property Map>
- A list of partials to be used by the plugin.
- protocols List<String>
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route Property Map
- If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service Property Map
- If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- List<String>
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated
At Number - Unix epoch when the resource was last updated.
Outputs
All input properties are implicitly available as output properties. Additionally, the GatewayPluginEntitlementEnforcement resource produces the following output properties:
- Id string
- The provider-assigned unique ID for this managed resource.
- Id string
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
- id string
- The provider-assigned unique ID for this managed resource.
- id str
- The provider-assigned unique ID for this managed resource.
- id String
- The provider-assigned unique ID for this managed resource.
Look up Existing GatewayPluginEntitlementEnforcement Resource
Get an existing GatewayPluginEntitlementEnforcement resource’s state with the given name, ID, and optional extra properties used to qualify the lookup.
public static get(name: string, id: Input<ID>, state?: GatewayPluginEntitlementEnforcementState, opts?: CustomResourceOptions): GatewayPluginEntitlementEnforcement@staticmethod
def get(resource_name: str,
id: str,
opts: Optional[ResourceOptions] = None,
condition: Optional[str] = None,
config: Optional[GatewayPluginEntitlementEnforcementConfigArgs] = None,
consumer: Optional[GatewayPluginEntitlementEnforcementConsumerArgs] = None,
control_plane_id: Optional[str] = None,
created_at: Optional[float] = None,
enabled: Optional[bool] = None,
gateway_plugin_entitlement_enforcement_id: Optional[str] = None,
instance_name: Optional[str] = None,
ordering: Optional[GatewayPluginEntitlementEnforcementOrderingArgs] = None,
partials: Optional[Sequence[GatewayPluginEntitlementEnforcementPartialArgs]] = None,
protocols: Optional[Sequence[str]] = None,
route: Optional[GatewayPluginEntitlementEnforcementRouteArgs] = None,
service: Optional[GatewayPluginEntitlementEnforcementServiceArgs] = None,
tags: Optional[Sequence[str]] = None,
updated_at: Optional[float] = None) -> GatewayPluginEntitlementEnforcementfunc GetGatewayPluginEntitlementEnforcement(ctx *Context, name string, id IDInput, state *GatewayPluginEntitlementEnforcementState, opts ...ResourceOption) (*GatewayPluginEntitlementEnforcement, error)public static GatewayPluginEntitlementEnforcement Get(string name, Input<string> id, GatewayPluginEntitlementEnforcementState? state, CustomResourceOptions? opts = null)public static GatewayPluginEntitlementEnforcement get(String name, Output<String> id, GatewayPluginEntitlementEnforcementState state, CustomResourceOptions options)resources: _: type: konnect:GatewayPluginEntitlementEnforcement get: id: ${id}import {
to = konnect_gateway_plugin_entitlement_enforcement.example
id = "${id}"
}
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- resource_name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- name
- The unique name of the resulting resource.
- id
- The unique provider ID of the resource to lookup.
- state
- Any extra arguments used during the lookup.
- opts
- A bag of options that control this resource's behavior.
- Condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - Config
Gateway
Plugin Entitlement Enforcement Config - Consumer
Gateway
Plugin Entitlement Enforcement Consumer - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- Control
Plane stringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- Created
At double - Unix epoch when the resource was created.
- Enabled bool
- Whether the plugin is applied. Default: true
- Gateway
Plugin stringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- Instance
Name string - A unique string representing a UTF-8 encoded name.
- Ordering
Gateway
Plugin Entitlement Enforcement Ordering - Partials
List<Gateway
Plugin Entitlement Enforcement Partial> - A list of partials to be used by the plugin.
- Protocols List<string>
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- Route
Gateway
Plugin Entitlement Enforcement Route - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- Service
Gateway
Plugin Entitlement Enforcement Service - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- List<string>
- An optional set of strings associated with the Plugin for grouping and filtering.
- Updated
At double - Unix epoch when the resource was last updated.
- Condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - Config
Gateway
Plugin Entitlement Enforcement Config Args - Consumer
Gateway
Plugin Entitlement Enforcement Consumer Args - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- Control
Plane stringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- Created
At float64 - Unix epoch when the resource was created.
- Enabled bool
- Whether the plugin is applied. Default: true
- Gateway
Plugin stringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- Instance
Name string - A unique string representing a UTF-8 encoded name.
- Ordering
Gateway
Plugin Entitlement Enforcement Ordering Args - Partials
[]Gateway
Plugin Entitlement Enforcement Partial Args - A list of partials to be used by the plugin.
- Protocols []string
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- Route
Gateway
Plugin Entitlement Enforcement Route Args - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- Service
Gateway
Plugin Entitlement Enforcement Service Args - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- []string
- An optional set of strings associated with the Plugin for grouping and filtering.
- Updated
At float64 - Unix epoch when the resource was last updated.
- condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - config object
- consumer object
- If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- control_
plane_ stringid - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- created_
at number - Unix epoch when the resource was created.
- enabled bool
- Whether the plugin is applied. Default: true
- gateway_
plugin_ stringentitlement_ enforcement_ id - A string representing a UUID (universally unique identifier).
- instance_
name string - A unique string representing a UTF-8 encoded name.
- ordering object
- partials list(object)
- A list of partials to be used by the plugin.
- protocols list(string)
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route object
- If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service object
- If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- list(string)
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated_
at number - Unix epoch when the resource was last updated.
- condition String
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - config
Gateway
Plugin Entitlement Enforcement Config - consumer
Gateway
Plugin Entitlement Enforcement Consumer - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- control
Plane StringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- created
At Double - Unix epoch when the resource was created.
- enabled Boolean
- Whether the plugin is applied. Default: true
- gateway
Plugin StringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- instance
Name String - A unique string representing a UTF-8 encoded name.
- ordering
Gateway
Plugin Entitlement Enforcement Ordering - partials
List<Gateway
Plugin Entitlement Enforcement Partial> - A list of partials to be used by the plugin.
- protocols List<String>
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route
Gateway
Plugin Entitlement Enforcement Route - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service
Gateway
Plugin Entitlement Enforcement Service - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- List<String>
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated
At Double - Unix epoch when the resource was last updated.
- condition string
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - config
Gateway
Plugin Entitlement Enforcement Config - consumer
Gateway
Plugin Entitlement Enforcement Consumer - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- control
Plane stringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- created
At number - Unix epoch when the resource was created.
- enabled boolean
- Whether the plugin is applied. Default: true
- gateway
Plugin stringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- instance
Name string - A unique string representing a UTF-8 encoded name.
- ordering
Gateway
Plugin Entitlement Enforcement Ordering - partials
Gateway
Plugin Entitlement Enforcement Partial[] - A list of partials to be used by the plugin.
- protocols string[]
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route
Gateway
Plugin Entitlement Enforcement Route - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service
Gateway
Plugin Entitlement Enforcement Service - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- string[]
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated
At number - Unix epoch when the resource was last updated.
- condition str
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - config
Gateway
Plugin Entitlement Enforcement Config Args - consumer
Gateway
Plugin Entitlement Enforcement Consumer Args - If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- control_
plane_ strid - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- created_
at float - Unix epoch when the resource was created.
- enabled bool
- Whether the plugin is applied. Default: true
- gateway_
plugin_ strentitlement_ enforcement_ id - A string representing a UUID (universally unique identifier).
- instance_
name str - A unique string representing a UTF-8 encoded name.
- ordering
Gateway
Plugin Entitlement Enforcement Ordering Args - partials
Sequence[Gateway
Plugin Entitlement Enforcement Partial Args] - A list of partials to be used by the plugin.
- protocols Sequence[str]
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route
Gateway
Plugin Entitlement Enforcement Route Args - If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service
Gateway
Plugin Entitlement Enforcement Service Args - If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- Sequence[str]
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated_
at float - Unix epoch when the resource was last updated.
- condition String
- An expression used for conditional control over plugin execution. If the expression evaluates to
trueduring the request flow, the plugin is executed; otherwise, it is skipped. - config Property Map
- consumer Property Map
- If set, the plugin will activate only for requests where the specified has been authenticated. (Note that some plugins can not be restricted to consumers this way.). Leave unset for the plugin to activate regardless of the authenticated Consumer.
- control
Plane StringId - The UUID of your control plane. This variable is available in the Konnect manager. Requires replacement if changed.
- created
At Number - Unix epoch when the resource was created.
- enabled Boolean
- Whether the plugin is applied. Default: true
- gateway
Plugin StringEntitlement Enforcement Id - A string representing a UUID (universally unique identifier).
- instance
Name String - A unique string representing a UTF-8 encoded name.
- ordering Property Map
- partials List<Property Map>
- A list of partials to be used by the plugin.
- protocols List<String>
- A set of strings representing HTTP protocols. Default: ["grpc","grpcs","http","https"]
- route Property Map
- If set, the plugin will only activate when receiving requests via the specified route. Leave unset for the plugin to activate regardless of the route being used.
- service Property Map
- If set, the plugin will only activate when receiving requests via one of the routes belonging to the specified Service. Leave unset for the plugin to activate regardless of the Service being matched.
- List<String>
- An optional set of strings associated with the Plugin for grouping and filtering.
- updated
At Number - Unix epoch when the resource was last updated.
Supporting Types
GatewayPluginEntitlementEnforcementConfig, GatewayPluginEntitlementEnforcementConfigArgs
- Api
Token string - Bearer token for authenticating with the entitlement access endpoint.
- Entitlement
Access stringEndpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- Feature
Gateway
Plugin Entitlement Enforcement Config Feature - The feature identifies what capability is being accessed and enforced.
- Credit
Balance boolRequired - If set to true, gateway will fetch credit balance for subject. Default: true
- Customer
Gateway
Plugin Entitlement Enforcement Config Customer - The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- Deny
Unknown boolCustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- Fail
Policy string - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- Keepalive double
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- L1Cache
Ttl doubleSeconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- L2Cache
Ttl doubleSeconds - Time in seconds to keep enforcement state in Redis. Default: 120
- Max
Stale doubleSeconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- Redis
Gateway
Plugin Entitlement Enforcement Config Redis - Refresh
Interval double - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- Response
Codes GatewayPlugin Entitlement Enforcement Config Response Codes - Ssl
Verify bool - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- Sync
Rate double - How often in seconds to sync enforcement state from redis. Default: 2
- Timeout double
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
- Api
Token string - Bearer token for authenticating with the entitlement access endpoint.
- Entitlement
Access stringEndpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- Feature
Gateway
Plugin Entitlement Enforcement Config Feature - The feature identifies what capability is being accessed and enforced.
- Credit
Balance boolRequired - If set to true, gateway will fetch credit balance for subject. Default: true
- Customer
Gateway
Plugin Entitlement Enforcement Config Customer - The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- Deny
Unknown boolCustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- Fail
Policy string - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- Keepalive float64
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- L1Cache
Ttl float64Seconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- L2Cache
Ttl float64Seconds - Time in seconds to keep enforcement state in Redis. Default: 120
- Max
Stale float64Seconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- Redis
Gateway
Plugin Entitlement Enforcement Config Redis - Refresh
Interval float64 - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- Response
Codes GatewayPlugin Entitlement Enforcement Config Response Codes - Ssl
Verify bool - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- Sync
Rate float64 - How often in seconds to sync enforcement state from redis. Default: 2
- Timeout float64
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
- api_
token string - Bearer token for authenticating with the entitlement access endpoint.
- entitlement_
access_ stringendpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- feature object
- The feature identifies what capability is being accessed and enforced.
- credit_
balance_ boolrequired - If set to true, gateway will fetch credit balance for subject. Default: true
- customer object
- The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- deny_
unknown_ boolcustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- fail_
policy string - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- keepalive number
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- l1_
cache_ numberttl_ seconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- l2_
cache_ numberttl_ seconds - Time in seconds to keep enforcement state in Redis. Default: 120
- max_
stale_ numberseconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- redis object
- refresh_
interval number - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- response_
codes object - ssl_
verify bool - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- sync_
rate number - How often in seconds to sync enforcement state from redis. Default: 2
- timeout number
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
- api
Token String - Bearer token for authenticating with the entitlement access endpoint.
- entitlement
Access StringEndpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- feature
Gateway
Plugin Entitlement Enforcement Config Feature - The feature identifies what capability is being accessed and enforced.
- credit
Balance BooleanRequired - If set to true, gateway will fetch credit balance for subject. Default: true
- customer
Gateway
Plugin Entitlement Enforcement Config Customer - The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- deny
Unknown BooleanCustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- fail
Policy String - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- keepalive Double
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- l1Cache
Ttl DoubleSeconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- l2Cache
Ttl DoubleSeconds - Time in seconds to keep enforcement state in Redis. Default: 120
- max
Stale DoubleSeconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- redis
Gateway
Plugin Entitlement Enforcement Config Redis - refresh
Interval Double - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- response
Codes GatewayPlugin Entitlement Enforcement Config Response Codes - ssl
Verify Boolean - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- sync
Rate Double - How often in seconds to sync enforcement state from redis. Default: 2
- timeout Double
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
- api
Token string - Bearer token for authenticating with the entitlement access endpoint.
- entitlement
Access stringEndpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- feature
Gateway
Plugin Entitlement Enforcement Config Feature - The feature identifies what capability is being accessed and enforced.
- credit
Balance booleanRequired - If set to true, gateway will fetch credit balance for subject. Default: true
- customer
Gateway
Plugin Entitlement Enforcement Config Customer - The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- deny
Unknown booleanCustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- fail
Policy string - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- keepalive number
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- l1Cache
Ttl numberSeconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- l2Cache
Ttl numberSeconds - Time in seconds to keep enforcement state in Redis. Default: 120
- max
Stale numberSeconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- redis
Gateway
Plugin Entitlement Enforcement Config Redis - refresh
Interval number - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- response
Codes GatewayPlugin Entitlement Enforcement Config Response Codes - ssl
Verify boolean - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- sync
Rate number - How often in seconds to sync enforcement state from redis. Default: 2
- timeout number
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
- api_
token str - Bearer token for authenticating with the entitlement access endpoint.
- entitlement_
access_ strendpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- feature
Gateway
Plugin Entitlement Enforcement Config Feature - The feature identifies what capability is being accessed and enforced.
- credit_
balance_ boolrequired - If set to true, gateway will fetch credit balance for subject. Default: true
- customer
Gateway
Plugin Entitlement Enforcement Config Customer - The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- deny_
unknown_ boolcustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- fail_
policy str - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- keepalive float
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- l1_
cache_ floatttl_ seconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- l2_
cache_ floatttl_ seconds - Time in seconds to keep enforcement state in Redis. Default: 120
- max_
stale_ floatseconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- redis
Gateway
Plugin Entitlement Enforcement Config Redis - refresh_
interval float - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- response_
codes GatewayPlugin Entitlement Enforcement Config Response Codes - ssl_
verify bool - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- sync_
rate float - How often in seconds to sync enforcement state from redis. Default: 2
- timeout float
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
- api
Token String - Bearer token for authenticating with the entitlement access endpoint.
- entitlement
Access StringEndpoint - A string representing a URL, such as https://example.com/path/to/resource?q=search.
- feature Property Map
- The feature identifies what capability is being accessed and enforced.
- credit
Balance BooleanRequired - If set to true, gateway will fetch credit balance for subject. Default: true
- customer Property Map
- The customer identifies who gets billed for each request. Choose where the plugin should look for the customer identifier.
- deny
Unknown BooleanCustomers - If set to true, gateway will deny access to any unknown subjects. Default: true
- fail
Policy String - Policy to apply when enforcement state cannot be retrieved. possible known values include one of ["allow", "block"]; Default: "allow"
- keepalive Number
- How long in milliseconds an idle connection to the entitlement access endpoint is kept open before being closed. Default: 60000
- l1Cache
Ttl NumberSeconds - Time in seconds to keep enforcement state in Kong's local L1 cache. Default: 5
- l2Cache
Ttl NumberSeconds - Time in seconds to keep enforcement state in Redis. Default: 120
- max
Stale NumberSeconds - Maximum age in seconds of cached enforcement state before it is considered stale and must be refreshed from Redis. Default: 60
- redis Property Map
- refresh
Interval Number - How often in seconds to poll enforcement state from the entitlement access endpoint. Default: 30
- response
Codes Property Map - ssl
Verify Boolean - Verify the TLS certificate presented by the entitlement access endpoint. Default: true
- sync
Rate Number - How often in seconds to sync enforcement state from redis. Default: 2
- timeout Number
- Maximum time in milliseconds to wait for a response from the entitlement access endpoint. Default: 10000
GatewayPluginEntitlementEnforcementConfigCustomer, GatewayPluginEntitlementEnforcementConfigCustomerArgs
- Field string
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- Look
Up stringValue In - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
- Field string
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- Look
Up stringValue In - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
- field string
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- look_
up_ stringvalue_ in - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
- field String
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- look
Up StringValue In - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
- field string
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- look
Up stringValue In - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
- field str
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- look_
up_ strvalue_ in - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
- field String
- The header name, query parameter, consumer field, or application field that contains the customer identifier, e.g. 'x-customer-id'
- look
Up StringValue In - Where to find the customer identifier in the request. possible known values include one of ["application", "consumer", "header", "query"]; Default: "consumer"
GatewayPluginEntitlementEnforcementConfigFeature, GatewayPluginEntitlementEnforcementConfigFeatureArgs
- Key string
- The feature key
- Key string
- The feature key
- key string
- The feature key
- key String
- The feature key
- key string
- The feature key
- key str
- The feature key
- key String
- The feature key
GatewayPluginEntitlementEnforcementConfigRedis, GatewayPluginEntitlementEnforcementConfigRedisArgs
- Cloud
Authentication GatewayPlugin Entitlement Enforcement Config Redis Cloud Authentication - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- Cluster
Max doubleRedirections - Maximum retry attempts for redirection. Default: 5
- Cluster
Nodes List<GatewayPlugin Entitlement Enforcement Config Redis Cluster Node> - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - Connect
Timeout double - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- Connection
Is boolProxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - Database double
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - Host string
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- Keepalive
Backlog double - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - Keepalive
Pool doubleSize - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - Password string
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- Port string
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- Read
Timeout double - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- Send
Timeout double - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- Sentinel
Master string - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- Sentinel
Nodes List<GatewayPlugin Entitlement Enforcement Config Redis Sentinel Node> - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - Sentinel
Password string - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- Sentinel
Role string - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - Sentinel
Username string - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- Server
Name string - A string representing an SNI (server name indication) value for TLS.
- Ssl bool
- If set to true, uses SSL to connect to Redis. Default: false
- Ssl
Verify bool - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - Username string
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
- Cloud
Authentication GatewayPlugin Entitlement Enforcement Config Redis Cloud Authentication - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- Cluster
Max float64Redirections - Maximum retry attempts for redirection. Default: 5
- Cluster
Nodes []GatewayPlugin Entitlement Enforcement Config Redis Cluster Node - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - Connect
Timeout float64 - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- Connection
Is boolProxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - Database float64
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - Host string
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- Keepalive
Backlog float64 - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - Keepalive
Pool float64Size - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - Password string
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- Port string
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- Read
Timeout float64 - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- Send
Timeout float64 - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- Sentinel
Master string - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- Sentinel
Nodes []GatewayPlugin Entitlement Enforcement Config Redis Sentinel Node - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - Sentinel
Password string - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- Sentinel
Role string - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - Sentinel
Username string - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- Server
Name string - A string representing an SNI (server name indication) value for TLS.
- Ssl bool
- If set to true, uses SSL to connect to Redis. Default: false
- Ssl
Verify bool - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - Username string
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
- cloud_
authentication object - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- cluster_
max_ numberredirections - Maximum retry attempts for redirection. Default: 5
- cluster_
nodes list(object) - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - connect_
timeout number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- connection_
is_ boolproxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - database number
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - host string
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- keepalive_
backlog number - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - keepalive_
pool_ numbersize - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - password string
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- port string
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- read_
timeout number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- send_
timeout number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- sentinel_
master string - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- sentinel_
nodes list(object) - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - sentinel_
password string - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- sentinel_
role string - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - sentinel_
username string - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- server_
name string - A string representing an SNI (server name indication) value for TLS.
- ssl bool
- If set to true, uses SSL to connect to Redis. Default: false
- ssl_
verify bool - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - username string
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
- cloud
Authentication GatewayPlugin Entitlement Enforcement Config Redis Cloud Authentication - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- cluster
Max DoubleRedirections - Maximum retry attempts for redirection. Default: 5
- cluster
Nodes List<GatewayPlugin Entitlement Enforcement Config Redis Cluster Node> - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - connect
Timeout Double - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- connection
Is BooleanProxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - database Double
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - host String
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- keepalive
Backlog Double - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - keepalive
Pool DoubleSize - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - password String
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- port String
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- read
Timeout Double - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- send
Timeout Double - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- sentinel
Master String - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- sentinel
Nodes List<GatewayPlugin Entitlement Enforcement Config Redis Sentinel Node> - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - sentinel
Password String - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- sentinel
Role String - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - sentinel
Username String - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- server
Name String - A string representing an SNI (server name indication) value for TLS.
- ssl Boolean
- If set to true, uses SSL to connect to Redis. Default: false
- ssl
Verify Boolean - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - username String
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
- cloud
Authentication GatewayPlugin Entitlement Enforcement Config Redis Cloud Authentication - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- cluster
Max numberRedirections - Maximum retry attempts for redirection. Default: 5
- cluster
Nodes GatewayPlugin Entitlement Enforcement Config Redis Cluster Node[] - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - connect
Timeout number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- connection
Is booleanProxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - database number
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - host string
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- keepalive
Backlog number - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - keepalive
Pool numberSize - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - password string
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- port string
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- read
Timeout number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- send
Timeout number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- sentinel
Master string - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- sentinel
Nodes GatewayPlugin Entitlement Enforcement Config Redis Sentinel Node[] - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - sentinel
Password string - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- sentinel
Role string - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - sentinel
Username string - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- server
Name string - A string representing an SNI (server name indication) value for TLS.
- ssl boolean
- If set to true, uses SSL to connect to Redis. Default: false
- ssl
Verify boolean - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - username string
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
- cloud_
authentication GatewayPlugin Entitlement Enforcement Config Redis Cloud Authentication - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- cluster_
max_ floatredirections - Maximum retry attempts for redirection. Default: 5
- cluster_
nodes Sequence[GatewayPlugin Entitlement Enforcement Config Redis Cluster Node] - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - connect_
timeout float - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- connection_
is_ boolproxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - database float
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - host str
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- keepalive_
backlog float - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - keepalive_
pool_ floatsize - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - password str
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- port str
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- read_
timeout float - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- send_
timeout float - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- sentinel_
master str - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- sentinel_
nodes Sequence[GatewayPlugin Entitlement Enforcement Config Redis Sentinel Node] - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - sentinel_
password str - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- sentinel_
role str - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - sentinel_
username str - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- server_
name str - A string representing an SNI (server name indication) value for TLS.
- ssl bool
- If set to true, uses SSL to connect to Redis. Default: false
- ssl_
verify bool - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - username str
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
- cloud
Authentication Property Map - Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
- cluster
Max NumberRedirections - Maximum retry attempts for redirection. Default: 5
- cluster
Nodes List<Property Map> - Cluster addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element. - connect
Timeout Number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- connection
Is BooleanProxied - If the connection to Redis is proxied (e.g. Envoy), set it
true. Set thehostandportto point to the proxy address. Default: false - database Number
- Database to use for the Redis connection when using the
redisstrategy. Default: 0 - host String
- A string representing a host name, such as example.com. Default: "127.0.0.1"
- keepalive
Backlog Number - Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return
nil. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less thankeepalive_pool_size. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger thankeepalive_pool_size. - keepalive
Pool NumberSize - The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither
keepalive_pool_sizenorkeepalive_backlogis specified, no pool is created. Ifkeepalive_pool_sizeisn't specified butkeepalive_backlogis specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low. Default: 256 - password String
- Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
- port String
- An integer representing a port number between 0 and 65535, inclusive. Default: "6379"
- read
Timeout Number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- send
Timeout Number - An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2. Default: 2000
- sentinel
Master String - Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
- sentinel
Nodes List<Property Map> - Sentinel node addresses to use for Redis connections when the
redisstrategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element. - sentinel
Password String - Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
- sentinel
Role String - Sentinel role to use for Redis connections when the
redisstrategy is defined. Defining this value implies using Redis Sentinel. possible known values include one of ["any", "master", "slave"] - sentinel
Username String - Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
- server
Name String - A string representing an SNI (server name indication) value for TLS.
- ssl Boolean
- If set to true, uses SSL to connect to Redis. Default: false
- ssl
Verify Boolean - If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure
lua_ssl_trusted_certificateinkong.confto specify the CA (or server) certificate used by your Redis server. You may also need to configurelua_ssl_verify_depthaccordingly. Default: true - username String
- Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to
default.
GatewayPluginEntitlementEnforcementConfigRedisCloudAuthentication, GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationArgs
- Auth
Provider string - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- Aws
Access stringKey Id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - Aws
Assume stringRole Arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- Aws
Cache stringName - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - Aws
Is boolServerless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - Aws
Region string - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - Aws
Role stringSession Name - The session name for the temporary credentials when assuming the IAM role.
- Aws
Secret stringAccess Key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - Azure
Client stringId - Azure Client ID to be used for authentication when
auth_provideris set toazure. - Azure
Client stringSecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - Azure
Tenant stringId - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - Gcp
Service stringAccount Json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - Oauth
Gateway
Plugin Entitlement Enforcement Config Redis Cloud Authentication Oauth - OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
- Auth
Provider string - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- Aws
Access stringKey Id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - Aws
Assume stringRole Arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- Aws
Cache stringName - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - Aws
Is boolServerless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - Aws
Region string - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - Aws
Role stringSession Name - The session name for the temporary credentials when assuming the IAM role.
- Aws
Secret stringAccess Key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - Azure
Client stringId - Azure Client ID to be used for authentication when
auth_provideris set toazure. - Azure
Client stringSecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - Azure
Tenant stringId - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - Gcp
Service stringAccount Json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - Oauth
Gateway
Plugin Entitlement Enforcement Config Redis Cloud Authentication Oauth - OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
- auth_
provider string - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- aws_
access_ stringkey_ id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - aws_
assume_ stringrole_ arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- aws_
cache_ stringname - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - aws_
is_ boolserverless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - aws_
region string - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - aws_
role_ stringsession_ name - The session name for the temporary credentials when assuming the IAM role.
- aws_
secret_ stringaccess_ key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - azure_
client_ stringid - Azure Client ID to be used for authentication when
auth_provideris set toazure. - azure_
client_ stringsecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - azure_
tenant_ stringid - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - gcp_
service_ stringaccount_ json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - oauth object
- OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
- auth
Provider String - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- aws
Access StringKey Id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - aws
Assume StringRole Arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- aws
Cache StringName - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - aws
Is BooleanServerless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - aws
Region String - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - aws
Role StringSession Name - The session name for the temporary credentials when assuming the IAM role.
- aws
Secret StringAccess Key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - azure
Client StringId - Azure Client ID to be used for authentication when
auth_provideris set toazure. - azure
Client StringSecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - azure
Tenant StringId - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - gcp
Service StringAccount Json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - oauth
Gateway
Plugin Entitlement Enforcement Config Redis Cloud Authentication Oauth - OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
- auth
Provider string - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- aws
Access stringKey Id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - aws
Assume stringRole Arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- aws
Cache stringName - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - aws
Is booleanServerless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - aws
Region string - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - aws
Role stringSession Name - The session name for the temporary credentials when assuming the IAM role.
- aws
Secret stringAccess Key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - azure
Client stringId - Azure Client ID to be used for authentication when
auth_provideris set toazure. - azure
Client stringSecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - azure
Tenant stringId - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - gcp
Service stringAccount Json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - oauth
Gateway
Plugin Entitlement Enforcement Config Redis Cloud Authentication Oauth - OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
- auth_
provider str - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- aws_
access_ strkey_ id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - aws_
assume_ strrole_ arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- aws_
cache_ strname - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - aws_
is_ boolserverless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - aws_
region str - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - aws_
role_ strsession_ name - The session name for the temporary credentials when assuming the IAM role.
- aws_
secret_ straccess_ key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - azure_
client_ strid - Azure Client ID to be used for authentication when
auth_provideris set toazure. - azure_
client_ strsecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - azure_
tenant_ strid - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - gcp_
service_ straccount_ json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - oauth
Gateway
Plugin Entitlement Enforcement Config Redis Cloud Authentication Oauth - OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
- auth
Provider String - Auth providers to be used to authenticate to a Cloud Provider's Redis instance. possible known values include one of ["aws", "azure", "gcp", "oauth"]
- aws
Access StringKey Id - AWS Access Key ID to be used for authentication when
auth_provideris set toaws. - aws
Assume StringRole Arn - The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
- aws
Cache StringName - The name of the AWS Elasticache cluster when
auth_provideris set toaws. - aws
Is BooleanServerless - This flag specifies whether the cluster is serverless when auth_provider is set to
aws. Default: true - aws
Region String - The region of the AWS ElastiCache cluster when
auth_provideris set toaws. - aws
Role StringSession Name - The session name for the temporary credentials when assuming the IAM role.
- aws
Secret StringAccess Key - AWS Secret Access Key to be used for authentication when
auth_provideris set toaws. - azure
Client StringId - Azure Client ID to be used for authentication when
auth_provideris set toazure. - azure
Client StringSecret - Azure Client Secret to be used for authentication when
auth_provideris set toazure. - azure
Tenant StringId - Azure Tenant ID to be used for authentication when
auth_provideris set toazure. - gcp
Service StringAccount Json - GCP Service Account JSON to be used for authentication when
auth_provideris set togcp. - oauth Property Map
- OAuth 2.0 client configuration used to authenticate to Redis when
auth_provideris set tooauth.
GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauth, GatewayPluginEntitlementEnforcementConfigRedisCloudAuthenticationOauthArgs
- Auth
Method string - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- Client
Id string - OAuth 2.0 client ID.
- Client
Secret string - OAuth 2.0 client secret.
- Client
Secret stringJwt Alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - Grant
Type string - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- Password string
- Resource owner password, used with the
passwordgrant type. - Redis
Username string - Static Redis ACL username sent with
AUTH <username> <token>. - Redis
Username stringClaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - Scopes List<string>
- OAuth 2.0 scopes to request. Default: []
- Ssl
Verify bool - Whether to verify the TLS certificate of the token endpoint. Default: true
- Timeout double
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- Token
Endpoint string - OAuth 2.0 token endpoint URL used to request access tokens.
- Token
Headers Dictionary<string, string> - Additional HTTP headers to send with the token request.
- Token
Post Dictionary<string, string>Args - Additional POST body arguments to send with the token request.
- Username string
- Resource owner username, used with the
passwordgrant type.
- Auth
Method string - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- Client
Id string - OAuth 2.0 client ID.
- Client
Secret string - OAuth 2.0 client secret.
- Client
Secret stringJwt Alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - Grant
Type string - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- Password string
- Resource owner password, used with the
passwordgrant type. - Redis
Username string - Static Redis ACL username sent with
AUTH <username> <token>. - Redis
Username stringClaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - Scopes []string
- OAuth 2.0 scopes to request. Default: []
- Ssl
Verify bool - Whether to verify the TLS certificate of the token endpoint. Default: true
- Timeout float64
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- Token
Endpoint string - OAuth 2.0 token endpoint URL used to request access tokens.
- Token
Headers map[string]string - Additional HTTP headers to send with the token request.
- Token
Post map[string]stringArgs - Additional POST body arguments to send with the token request.
- Username string
- Resource owner username, used with the
passwordgrant type.
- auth_
method string - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- client_
id string - OAuth 2.0 client ID.
- client_
secret string - OAuth 2.0 client secret.
- client_
secret_ stringjwt_ alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - grant_
type string - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- password string
- Resource owner password, used with the
passwordgrant type. - redis_
username string - Static Redis ACL username sent with
AUTH <username> <token>. - redis_
username_ stringclaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - scopes list(string)
- OAuth 2.0 scopes to request. Default: []
- ssl_
verify bool - Whether to verify the TLS certificate of the token endpoint. Default: true
- timeout number
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- token_
endpoint string - OAuth 2.0 token endpoint URL used to request access tokens.
- token_
headers map(string) - Additional HTTP headers to send with the token request.
- token_
post_ map(string)args - Additional POST body arguments to send with the token request.
- username string
- Resource owner username, used with the
passwordgrant type.
- auth
Method String - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- client
Id String - OAuth 2.0 client ID.
- client
Secret String - OAuth 2.0 client secret.
- client
Secret StringJwt Alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - grant
Type String - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- password String
- Resource owner password, used with the
passwordgrant type. - redis
Username String - Static Redis ACL username sent with
AUTH <username> <token>. - redis
Username StringClaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - scopes List<String>
- OAuth 2.0 scopes to request. Default: []
- ssl
Verify Boolean - Whether to verify the TLS certificate of the token endpoint. Default: true
- timeout Double
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- token
Endpoint String - OAuth 2.0 token endpoint URL used to request access tokens.
- token
Headers Map<String,String> - Additional HTTP headers to send with the token request.
- token
Post Map<String,String>Args - Additional POST body arguments to send with the token request.
- username String
- Resource owner username, used with the
passwordgrant type.
- auth
Method string - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- client
Id string - OAuth 2.0 client ID.
- client
Secret string - OAuth 2.0 client secret.
- client
Secret stringJwt Alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - grant
Type string - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- password string
- Resource owner password, used with the
passwordgrant type. - redis
Username string - Static Redis ACL username sent with
AUTH <username> <token>. - redis
Username stringClaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - scopes string[]
- OAuth 2.0 scopes to request. Default: []
- ssl
Verify boolean - Whether to verify the TLS certificate of the token endpoint. Default: true
- timeout number
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- token
Endpoint string - OAuth 2.0 token endpoint URL used to request access tokens.
- token
Headers {[key: string]: string} - Additional HTTP headers to send with the token request.
- token
Post {[key: string]: string}Args - Additional POST body arguments to send with the token request.
- username string
- Resource owner username, used with the
passwordgrant type.
- auth_
method str - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- client_
id str - OAuth 2.0 client ID.
- client_
secret str - OAuth 2.0 client secret.
- client_
secret_ strjwt_ alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - grant_
type str - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- password str
- Resource owner password, used with the
passwordgrant type. - redis_
username str - Static Redis ACL username sent with
AUTH <username> <token>. - redis_
username_ strclaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - scopes Sequence[str]
- OAuth 2.0 scopes to request. Default: []
- ssl_
verify bool - Whether to verify the TLS certificate of the token endpoint. Default: true
- timeout float
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- token_
endpoint str - OAuth 2.0 token endpoint URL used to request access tokens.
- token_
headers Mapping[str, str] - Additional HTTP headers to send with the token request.
- token_
post_ Mapping[str, str]args - Additional POST body arguments to send with the token request.
- username str
- Resource owner username, used with the
passwordgrant type.
- auth
Method String - Client authentication method used against the token endpoint. possible known values include one of ["clientsecretbasic", "clientsecretjwt", "clientsecretpost"]; Default: "clientsecretpost"
- client
Id String - OAuth 2.0 client ID.
- client
Secret String - OAuth 2.0 client secret.
- client
Secret StringJwt Alg - Signing algorithm used for
client_secret_jwtclient authentication. possible known values include one of ["HS256", "HS512"]; Default: "HS512" - grant
Type String - OAuth 2.0 grant type used to request access tokens. possible known values include one of ["clientcredentials", "password"]; Default: "clientcredentials"
- password String
- Resource owner password, used with the
passwordgrant type. - redis
Username String - Static Redis ACL username sent with
AUTH <username> <token>. - redis
Username StringClaim - JWT claim in the access token used to derive the Redis ACL username (for example,
oidfor Microsoft Entra ID). - scopes List<String>
- OAuth 2.0 scopes to request. Default: []
- ssl
Verify Boolean - Whether to verify the TLS certificate of the token endpoint. Default: true
- timeout Number
- Timeout, in milliseconds, for requests to the token endpoint. Default: 10000
- token
Endpoint String - OAuth 2.0 token endpoint URL used to request access tokens.
- token
Headers Map<String> - Additional HTTP headers to send with the token request.
- token
Post Map<String>Args - Additional POST body arguments to send with the token request.
- username String
- Resource owner username, used with the
passwordgrant type.
GatewayPluginEntitlementEnforcementConfigRedisClusterNode, GatewayPluginEntitlementEnforcementConfigRedisClusterNodeArgs
GatewayPluginEntitlementEnforcementConfigRedisSentinelNode, GatewayPluginEntitlementEnforcementConfigRedisSentinelNodeArgs
GatewayPluginEntitlementEnforcementConfigResponseCodes, GatewayPluginEntitlementEnforcementConfigResponseCodesArgs
- Customer
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Customer Not Found - Feature
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Feature Not Found -
Gateway
Plugin Entitlement Enforcement Config Response Codes Feature Unavailable - No
Credit GatewayAvailable Plugin Entitlement Enforcement Config Response Codes No Credit Available - Usage
Limit GatewayReached Plugin Entitlement Enforcement Config Response Codes Usage Limit Reached
- Customer
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Customer Not Found - Feature
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Feature Not Found -
Gateway
Plugin Entitlement Enforcement Config Response Codes Feature Unavailable - No
Credit GatewayAvailable Plugin Entitlement Enforcement Config Response Codes No Credit Available - Usage
Limit GatewayReached Plugin Entitlement Enforcement Config Response Codes Usage Limit Reached
- customer
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Customer Not Found - feature
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Feature Not Found -
Gateway
Plugin Entitlement Enforcement Config Response Codes Feature Unavailable - no
Credit GatewayAvailable Plugin Entitlement Enforcement Config Response Codes No Credit Available - usage
Limit GatewayReached Plugin Entitlement Enforcement Config Response Codes Usage Limit Reached
- customer
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Customer Not Found - feature
Not GatewayFound Plugin Entitlement Enforcement Config Response Codes Feature Not Found -
Gateway
Plugin Entitlement Enforcement Config Response Codes Feature Unavailable - no
Credit GatewayAvailable Plugin Entitlement Enforcement Config Response Codes No Credit Available - usage
Limit GatewayReached Plugin Entitlement Enforcement Config Response Codes Usage Limit Reached
- customer_
not_ Gatewayfound Plugin Entitlement Enforcement Config Response Codes Customer Not Found - feature_
not_ Gatewayfound Plugin Entitlement Enforcement Config Response Codes Feature Not Found -
Gateway
Plugin Entitlement Enforcement Config Response Codes Feature Unavailable - no_
credit_ Gatewayavailable Plugin Entitlement Enforcement Config Response Codes No Credit Available - usage_
limit_ Gatewayreached Plugin Entitlement Enforcement Config Response Codes Usage Limit Reached
GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFound, GatewayPluginEntitlementEnforcementConfigResponseCodesCustomerNotFoundArgs
- Http
Status double - Status code to return when enforcement is triggered. Default: 403
- Message string
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
- Http
Status float64 - Status code to return when enforcement is triggered. Default: 403
- Message string
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
- http_
status number - Status code to return when enforcement is triggered. Default: 403
- message string
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
- http
Status Double - Status code to return when enforcement is triggered. Default: 403
- message String
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
- http
Status number - Status code to return when enforcement is triggered. Default: 403
- message string
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
- http_
status float - Status code to return when enforcement is triggered. Default: 403
- message str
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
- http
Status Number - Status code to return when enforcement is triggered. Default: 403
- message String
- Message to return when enforcement is triggered. Default: "Customer is not found by subject."
GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFound, GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureNotFoundArgs
- Http
Status double - Status code to return when enforcement is triggered. Default: 403
- Message string
- Message to return when enforcement is triggered. Default: "Feature not found."
- Http
Status float64 - Status code to return when enforcement is triggered. Default: 403
- Message string
- Message to return when enforcement is triggered. Default: "Feature not found."
- http_
status number - Status code to return when enforcement is triggered. Default: 403
- message string
- Message to return when enforcement is triggered. Default: "Feature not found."
- http
Status Double - Status code to return when enforcement is triggered. Default: 403
- message String
- Message to return when enforcement is triggered. Default: "Feature not found."
- http
Status number - Status code to return when enforcement is triggered. Default: 403
- message string
- Message to return when enforcement is triggered. Default: "Feature not found."
- http_
status float - Status code to return when enforcement is triggered. Default: 403
- message str
- Message to return when enforcement is triggered. Default: "Feature not found."
- http
Status Number - Status code to return when enforcement is triggered. Default: 403
- message String
- Message to return when enforcement is triggered. Default: "Feature not found."
GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailable, GatewayPluginEntitlementEnforcementConfigResponseCodesFeatureUnavailableArgs
- Http
Status double - Status code to return when enforcement is triggered. Default: 403
- Message string
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
- Http
Status float64 - Status code to return when enforcement is triggered. Default: 403
- Message string
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
- http_
status number - Status code to return when enforcement is triggered. Default: 403
- message string
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
- http
Status Double - Status code to return when enforcement is triggered. Default: 403
- message String
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
- http
Status number - Status code to return when enforcement is triggered. Default: 403
- message string
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
- http_
status float - Status code to return when enforcement is triggered. Default: 403
- message str
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
- http
Status Number - Status code to return when enforcement is triggered. Default: 403
- message String
- Message to return when enforcement is triggered. Default: "Feature is not available for the customer."
GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailable, GatewayPluginEntitlementEnforcementConfigResponseCodesNoCreditAvailableArgs
- Http
Status double - Status code to return when enforcement is triggered. Default: 402
- Message string
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
- Http
Status float64 - Status code to return when enforcement is triggered. Default: 402
- Message string
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
- http_
status number - Status code to return when enforcement is triggered. Default: 402
- message string
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
- http
Status Double - Status code to return when enforcement is triggered. Default: 402
- message String
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
- http
Status number - Status code to return when enforcement is triggered. Default: 402
- message string
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
- http_
status float - Status code to return when enforcement is triggered. Default: 402
- message str
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
- http
Status Number - Status code to return when enforcement is triggered. Default: 402
- message String
- Message to return when enforcement is triggered. Default: "Customer has no credit available."
GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReached, GatewayPluginEntitlementEnforcementConfigResponseCodesUsageLimitReachedArgs
- Http
Status double - Status code to return when enforcement is triggered. Default: 429
- Message string
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
- Http
Status float64 - Status code to return when enforcement is triggered. Default: 429
- Message string
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
- http_
status number - Status code to return when enforcement is triggered. Default: 429
- message string
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
- http
Status Double - Status code to return when enforcement is triggered. Default: 429
- message String
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
- http
Status number - Status code to return when enforcement is triggered. Default: 429
- message string
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
- http_
status float - Status code to return when enforcement is triggered. Default: 429
- message str
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
- http
Status Number - Status code to return when enforcement is triggered. Default: 429
- message String
- Message to return when enforcement is triggered. Default: "Customer has reached usage limit for feature."
GatewayPluginEntitlementEnforcementConsumer, GatewayPluginEntitlementEnforcementConsumerArgs
- Id string
- Id string
- id string
- id String
- id string
- id str
- id String
GatewayPluginEntitlementEnforcementOrdering, GatewayPluginEntitlementEnforcementOrderingArgs
GatewayPluginEntitlementEnforcementOrderingAfter, GatewayPluginEntitlementEnforcementOrderingAfterArgs
- Accesses List<string>
- Accesses []string
- accesses list(string)
- accesses List<String>
- accesses string[]
- accesses Sequence[str]
- accesses List<String>
GatewayPluginEntitlementEnforcementOrderingBefore, GatewayPluginEntitlementEnforcementOrderingBeforeArgs
- Accesses List<string>
- Accesses []string
- accesses list(string)
- accesses List<String>
- accesses string[]
- accesses Sequence[str]
- accesses List<String>
GatewayPluginEntitlementEnforcementPartial, GatewayPluginEntitlementEnforcementPartialArgs
GatewayPluginEntitlementEnforcementRoute, GatewayPluginEntitlementEnforcementRouteArgs
- Id string
- Id string
- id string
- id String
- id string
- id str
- id String
GatewayPluginEntitlementEnforcementService, GatewayPluginEntitlementEnforcementServiceArgs
- Id string
- Id string
- id string
- id String
- id string
- id str
- id String
Import
In Terraform v1.5.0 and later, the import block can be used with the id attribute, for example:
terraform
import {
to = konnect_gateway_plugin_entitlement_enforcement.my_konnect_gateway_plugin_entitlement_enforcement
id = jsonencode({
control_plane_id = "9524ec7d-36d9-465d-a8c5-83a3c9390458"
id = "3473c251-5b6c-4f45-b1ff-7ede735a366d"
})
}
The pulumi import command can be used, for example:
$ pulumi import konnect:index/gatewayPluginEntitlementEnforcement:GatewayPluginEntitlementEnforcement my_konnect_gateway_plugin_entitlement_enforcement '{"control_plane_id": "9524ec7d-36d9-465d-a8c5-83a3c9390458", "id": "3473c251-5b6c-4f45-b1ff-7ede735a366d"}'
To learn more about importing existing cloud resources, see Importing resources.
Package Details
- Repository
- konnect kong/terraform-provider-konnect
- License
- Notes
- This Pulumi package is based on the
konnectTerraform Provider.
published on Friday, Sep 25, 2026 by kong