AI Custom Policies

Related Documentation
Minimum Version
AI Gateway - 2.2
Incompatible with
on-prem

What is an AI Custom Policy?

Create an AI Custom Policy when you need behavior that the built-in AI Policies don’t provide. An AI Custom Policy registers your own plugin as a new AI Policy type.

An AI Custom Policy has two parts:

  • A Lua schema that defines the configuration your policy accepts
  • A Lua handler that implements the behavior, using the Plugin Development Kit (PDK)

Plugin development works the same way for AI Gateway and Kong Gateway, so you can reuse custom plugins you’ve already written.

Once registered, the AI Custom Policy’s name becomes a valid AI Policy type. You then attach it like any other AI Policy. Built-in policies each support a fixed set of scopes, but an AI Custom Policy has no scope restriction, so you can attach it at any scope, including to AI Consumers and AI Consumer Groups.

Manage AI Custom Policies

AI Custom Policies are managed through:

  • Konnect UI
  • AI Gateway API: /v1/ai-gateways/{aiGatewayId}/custom-policies
  • kongctl 1.20.0 or later

For configuration examples and step-by-step setup instructions, see Set up an AI Custom Policy.

Deployment modes

Each AI Custom Policy uses one of two modes, set by its type field:

  • streaming: You upload both the schema and the handler. Konnect sends the handler to your data planes as part of their configuration.
  • installed: You install the plugin on each data plane yourself and upload only its schema. Konnect doesn’t send any plugin code to data planes.

Streaming mode

Use streaming mode when you want Konnect to distribute your plugin, with no changes to data plane images or file systems.

Data planes must be started with KONG_CUSTOM_PLUGIN_STREAMING_ENABLED=on to accept streamed policies. The same limitations as streaming Kong Gateway plugins apply. For more information, see Streaming custom plugins.

Installed mode

Use installed mode for plugins that need more than a single schema and handler module, or that you already ship with your data planes.

First install the plugin on each data plane by following the installation guide. Then create the AI Custom Policy with the plugin’s schema.

Validation rules

Konnect applies the following rules when you create or update an AI Custom Policy:

Field

Rule

Error

name Must match the name declared in the Lua schema. For example, if your schema returns { name = "my-streaming-custom-policy", ... }, set name: my-streaming-custom-policy. 400
handler Required in streaming mode. Not allowed in installed mode. 400
schema Can’t contain custom_validator or custom_entity_check, in either mode. 400

You can’t delete an AI Custom Policy while any AI Policy uses it as its type. The request returns a 400 error until you delete or change those AI Policies.

Set up an AI Custom Policy

To try the examples, export a sample schema and handler:

export LUA_SCHEMA="return{name='my-streaming-custom-policy',fields={{config={type='record',fields={}}}}}"
export LUA_HANDLER="return{PRIORITY=1000,VERSION='0.1.0',access=function(self,conf)kong.response.set_header('X-Custom-Policy','enabled')end}"

This handler adds an X-Custom-Policy: enabled header to responses for requests the policy runs on.

When you pass Lua through environment variables to the Konnect API, keep it on one line with no spaces or double quotes. Line breaks, spaces, and double quotes break the request body.

Create a streaming AI Custom Policy

Create an installed AI Custom Policy

Install the plugin on each data plane first. See Installed mode. The schema you upload must be the installed plugin’s schema.lua, so the name declared in it matches both the installed plugin and the AI Custom Policy’s name.

For a plugin named my-installed-custom-policy, set LUA_SCHEMA like this:

export LUA_SCHEMA="return{name='my-installed-custom-policy',fields={{config={type='record',fields={}}}}}"

This sample only works if a plugin named my-installed-custom-policy with this schema is installed on your data planes. In installed mode, Konnect doesn’t send any plugin code to data planes, so the AI Custom Policy only runs if the plugin is already installed.

Use the AI Custom Policy in an AI Policy

Create an AI Policy with type set to the AI Custom Policy’s name. The following example applies the streaming AI Custom Policy globally:

Update an AI Custom Policy

Updates replace the whole definition, so send every required field:

Schema

FAQs

Create an AI Policy as normal and set its type to the name of the AI Custom Policy.

Lua. The schema and handler fields take Lua source, equivalent to a plugin’s schema.lua and handler.lua.

No. Konnect validates the schema itself when you create or update the AI Custom Policy, but it accepts any config on an AI Policy that uses it. Make sure your AI Policy config matches your schema.

No. name and type are immutable. To change either, create a new AI Custom Policy, point your AI Policies at it, then delete the old one.

Help us make these docs great!

Kong Developer docs are open source. If you find these useful and want to make them better, contribute today!