{
  "meta": {
    "version": "v1",
    "pricing": {
      "public": {
        "label": "Public",
        "description": "Read-only API access for lightweight status checks and public integrations."
      },
      "premium": {
        "label": "Premium",
        "description": "API keys with higher hourly quotas, plus Slack, Discord, webhook, and email outage alerts across your vendor stack."
      }
    },
    "generatedAt": "2026-07-24T10:20:15.133Z"
  },
  "data": {
    "id": "incident_statuspage_kong_908w4gk08ytq",
    "slug": "kong-konnect-control-plane-default-changes-due-to-3-14-release-and-secure-by-2026-04-08-4gk08ytq",
    "title": "Konnect Control Plane Default Changes due to 3.14 Release and Secure by Default",
    "summary": "Konnect Control Plane Default Changes due to 3.14 Release and Secure by Default",
    "status": "resolved",
    "severity": "major",
    "startedAt": "2026-04-08T16:20:16+00:00",
    "updatedAt": "2026-04-08T21:33:19.2+00:00",
    "resolvedAt": "2026-04-08T21:33:19.181+00:00",
    "provider": {
      "slug": "kong",
      "name": "Kong"
    },
    "affectedServices": [
      {
        "slug": "kong-konnect",
        "name": "Konnect Cloud"
      }
    ],
    "links": {
      "html": "/incidents/kong-konnect-control-plane-default-changes-due-to-3-14-release-and-secure-by-2026-04-08-4gk08ytq",
      "api": "/api/v1/incidents/kong-konnect-control-plane-default-changes-due-to-3-14-release-and-secure-by-2026-04-08-4gk08ytq",
      "providerHtml": "/providers/kong"
    },
    "impactSummary": "Kong reported a major event for the affected tracked services.",
    "source": {
      "id": "source_kong_status",
      "kind": "official_status_page",
      "name": "Kong Status",
      "checkedAt": "2026-07-23T12:00:00Z",
      "officialUrl": "https://status.konghq.com",
      "statusPageUrl": "https://status.konghq.com"
    },
    "updates": [
      {
        "id": "update_statuspage_kong_908w4gk08ytq_j7x43077rmdk",
        "status": "investigating",
        "body": "With the release of 3.14 and changes to default security settings for Kong’s secure by default initiatives, Konnect customers running dataplanes less than 3.14 and updating certain plugins without providing overrides to the new defaults began experiencing the following issues:\n\n\nKonnect would begin reporting that a default had been overridden that did not apply to the connected dataplane. This is a warning that Konnect gives when the configuration on Konnect control plane appears to have user-defined changes that do not apply to the dataplane version the customer is using. This message is provided to avoid a user configuring properties on a plugin that their dataplane would not utilize, to make it clear to users why a new field isn’t taking effect.  Since our defaults changed, this caused the reporting in some cases to see this as an ‘override’ if the configuration didn’t match the new default, causing the message.  This had no impact on dataplane configurations or behavior, but it was a confusing message, and we have removed it. \n\n\n\nThe second and more impactful issue is the updating of default values in 3.14. After the 3.14 release, some fields like ssl_verify and hide_credentials in various entities started defaulting to true instead of false . This is causing customers who run a deck sync without these fields defined, will see their config values change from false to true which is an issue. Konnect is working on rolling back to the old default values. Once the default values are restored on the API, the next time the config is updated without the default values, the previous values will be applied. \n\nPlugins using ssl_verify:\nace\nacme\nai-aws-guardrail\nai-azure-content-safety\nai-llm-as-judge\nai-proxy-advanced\nai-rag-injector\nai-rate-limiting-advanced\nai-request-transformer\nai-response-transformer\nai-semantic-cache\nai-semantic-prompt-guard\nai-semantic-response-guard\naws-lambda\nazure-functions\nbasic-auth\nconfluent\nconfluent-consume\ndatakit\nforward-proxy\ngraphql-proxy-cache-advanced\ngraphql-rate-limiting-advanced\nheader-cert-auth\nhttp-log\njwt-signer\nkafka-consume\nkafka-log\nkafka-upstream\nldap-auth\nldap-auth-advanced\nmtls-auth\nopa\nopenid-connect\nproxy-cache-advanced\nrate-limiting\nrate-limiting-advanced\nrequest-callout\nresponse-ratelimiting\nsaml\nservice-protection\ntcp-log\nupstream-oauth\n\nPlugins using hide_credentials:\nKey-auth\nKey-auth-enc\nBasic-auth\nHmac-authldap-auth\nOauth2\nOauth2-introspection\nvault-auth (EE)\nldap-auth-advanced (EE)",
        "createdAt": "2026-04-08T16:20:16.171+00:00"
      },
      {
        "id": "update_statuspage_kong_908w4gk08ytq_znzpt8n4744v",
        "status": "identified",
        "body": "The issue has been identified and a fix is being implemented.",
        "createdAt": "2026-04-08T16:20:29.562+00:00"
      },
      {
        "id": "update_statuspage_kong_908w4gk08ytq_pth709ntf86f",
        "status": "resolved",
        "body": "We have completed the rollback to the original default values. Customers applying their configurations without explicitly defining ssl_verify and hide_credentials will default to `false` again.",
        "createdAt": "2026-04-08T21:33:19.181+00:00"
      }
    ],
    "access": {
      "plan": "public",
      "keyed": false
    }
  }
}