To try the examples, export a sample schema and handler:
export LUA_SCHEMA="return{name='my-streaming-custom-policy',fields={{config={type='record',fields={}}}}}"
export LUA_HANDLER="return{PRIORITY=1000,VERSION='0.1.0',access=function(self,conf)kong.response.set_header('X-Custom-Policy','enabled')end}"
This handler adds an X-Custom-Policy: enabled header to responses for requests the policy runs on.
When you pass Lua through environment variables to the Konnect API, keep it on one line with no spaces or double quotes. Line breaks, spaces, and double quotes break the request body.
curl -X POST https://{region}.api.konghq.com/v1/ai-gateways/{AIGatewayId}/custom-policies \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "my-streaming-custom-policy",
"type": "streaming",
"display_name": "Custom Policy - Streaming plugin",
"schema": "'$LUA_SCHEMA'",
"handler": "'$LUA_HANDLER'"
}
'
Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates.
-
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account.
-
AIGatewayId: The id of the AI Gateway.
See the Konnect AI Gateway API reference to learn about region-specific URLs and personal access tokens.
ai_gateway_custom_policies:
- ref: my-streaming-custom-policy
ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
name: my-streaming-custom-policy
type: streaming
display_name: Custom Policy - Streaming plugin
schema: !env LUA_SCHEMA
handler: !env LUA_HANDLER
Make sure to replace the following placeholders with your own values:
-
AI_GATEWAY_ID: The id of your AI Gateway.
-
!env LUA_SCHEMA: Your Lua schema
-
!env LUA_HANDLER: Your plugin handler.
Install the plugin on each data plane first. See Installed mode.
The schema you upload must be the installed plugin’s schema.lua, so the name declared in it matches both the installed plugin and the AI Custom Policy’s name.
For a plugin named my-installed-custom-policy, set LUA_SCHEMA like this:
export LUA_SCHEMA="return{name='my-installed-custom-policy',fields={{config={type='record',fields={}}}}}"
This sample only works if a plugin named my-installed-custom-policy with this schema is installed on your data planes. In installed mode, Konnect doesn’t send any plugin code to data planes, so the AI Custom Policy only runs if the plugin is already installed.
curl -X POST https://{region}.api.konghq.com/v1/ai-gateways/{AIGatewayId}/custom-policies \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "my-installed-custom-policy",
"type": "installed",
"display_name": "Custom Policy - Installed plugin",
"schema": "'$LUA_SCHEMA'"
}
'
Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates.
-
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account.
-
AIGatewayId: The id of the AI Gateway.
See the Konnect AI Gateway API reference to learn about region-specific URLs and personal access tokens.
ai_gateway_custom_policies:
- ref: my-installed-custom-policy
ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
name: my-installed-custom-policy
type: installed
display_name: Custom Policy - Installed plugin
schema: !env LUA_SCHEMA
Make sure to replace the following placeholders with your own values:
Create an AI Policy with type set to the AI Custom Policy’s name. The following example applies the streaming AI Custom Policy globally:
curl -X POST https://{region}.api.konghq.com/v1/ai-gateways/{AIGatewayId}/policies \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"display_name": "Custom header - Global",
"name": "custom-header-global",
"type": "my-streaming-custom-policy",
"enabled": true,
"global": true,
"config": {}
}
'
Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates.
-
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account.
-
AIGatewayId: The id of the AI Gateway.
See the Konnect AI Gateway API reference to learn about region-specific URLs and personal access tokens.
ai_gateway_policies:
- ref: custom-header-global
ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
display_name: Custom header - Global
name: custom-header-global
type: my-streaming-custom-policy
enabled: true
global: true
config: {}
Make sure to replace the following placeholders with your own values:
AI_GATEWAY_ID: The id of your AI Gateway.
Updates replace the whole definition, so send every required field:
Send a PUT request to the /v1/ai-gateways/{aiGatewayId}/custom-policies/{name|id} endpoint:
curl -X PUT "https://us.api.konghq.com/v1/ai-gateways/$AI_GATEWAY_ID/custom-policies/my-streaming-custom-policy" \
--no-progress-meter --fail-with-body \
-H "Authorization: Bearer $KONNECT_TOKEN"\
-H "Content-Type: application/json"\
-H "Accept: application/json, application/problem+json" \
--json '{
"name": "my-streaming-custom-policy",
"type": "streaming",
"display_name": "Custom Policy - Streaming plugin (updated)",
"schema": "'$LUA_SCHEMA'",
"handler": "'$LUA_HANDLER'"
}'
Edit the AI Custom Policy in your declarative configuration and apply it:
ai_gateway_custom_policies:
- ref: my-streaming-custom-policy
ai_gateway: !lookup {id: !env AI_GATEWAY_ID}
name: my-streaming-custom-policy
type: streaming
display_name: Custom Policy - Streaming plugin (updated)
schema: !env LUA_SCHEMA
handler: !env LUA_HANDLER
Make sure to replace the following placeholders with your own values:
-
AI_GATEWAY_ID: The id of your AI Gateway.
-
!env LUA_SCHEMA: Your Lua schema
-
!env LUA_HANDLER: Your plugin handler.