Verify TLS connection using a custom CAv3.16+
Verify a call node’s outbound TLS connection against a private CA using the plugin’s ca_certificates field, instead of relying on Kong Gateway’s global trusted CA store.
This is useful when a call node contacts an internal service whose certificate is signed by a private CA that can’t be added to a global trust store,
for example on Konnect Dedicated Cloud Gateways.
This example contains the following nodes:
- The node
AUTHORcalls an internal HTTPS endpoint. Its certificate is verified against the CA Certificate object referenced inca_certificates, instead of the global trusted CA store. - The node
EXITreturns the call’s response body directly to the client.
If the internal endpoint’s certificate isn’t signed by a CA in ca_certificates,
the AUTHOR node fails with a TLS verification error, and Datakit returns a 500 response instead of reaching EXIT.
Note:
ca_certificatesis set at the root of the plugin’s config. Allcallnodes in the plugin instance share the same trust store. When set, it replaces the global trusted CA store for verifying outbound calls, so include any public CAs you still need to trust alongside your private CA. The field has no effect if a node’sssl_verifyisfalse.
Prerequisites
- You have added your private CA to Kong Gateway as a CA Certificate object.
Environment variables
-
CA_CERT_ID: The ID of your CA Certificate object in Kong Gateway. -
SERVICE_URL: The URL of the internal service theAUTHORnode will call.
Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: datakit
config:
ca_certificates:
- ${{ env "DECK_CA_CERT_ID" }}
nodes:
- name: AUTHOR
type: call
url: ${{ env "DECK_SERVICE_URL" }}
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200Make the following request:
curl -i -X POST http://localhost:8001/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongClusterPlugin
metadata:
name: datakit
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
labels:
global: 'true'
config:
ca_certificates:
- '$CA_CERT_ID'
nodes:
- name: AUTHOR
type: call
url: '$SERVICE_URL'
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200
plugin: datakit
" | kubectl apply -f -Prerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_datakit" "my_datakit" {
enabled = true
config = {
ca_certificates = [var.ca_cert_id]
nodes = [
{
name = "AUTHOR"
type = "call"
url = var.service_url
ssl_verify = true
},
{
name = "EXIT"
type = "exit"
inputs = {
body = "AUTHOR.body"
}
status = 200
} ]
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "ca_cert_id" {
type = string
}
variable "service_url" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: datakit
service: serviceName|Id
config:
ca_certificates:
- ${{ env "DECK_CA_CERT_ID" }}
nodes:
- name: AUTHOR
type: call
url: ${{ env "DECK_SERVICE_URL" }}
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200Make sure to replace the following placeholders with your own values:
serviceName|Id: Theidornameof the service the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/services/{serviceName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
serviceName|Id: Theidornameof the service the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/services/{serviceId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
serviceId: Theidof the service the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: datakit
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
ca_certificates:
- '$CA_CERT_ID'
nodes:
- name: AUTHOR
type: call
url: '$SERVICE_URL'
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200
plugin: datakit
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the service resource:
kubectl annotate -n kong service SERVICE_NAME konghq.com/plugins=datakitPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_datakit" "my_datakit" {
enabled = true
config = {
ca_certificates = [var.ca_cert_id]
nodes = [
{
name = "AUTHOR"
type = "call"
url = var.service_url
ssl_verify = true
},
{
name = "EXIT"
type = "exit"
inputs = {
body = "AUTHOR.body"
}
status = 200
} ]
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
service = {
id = konnect_gateway_service.my_service.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "ca_cert_id" {
type = string
}
variable "service_url" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: datakit
route: routeName|Id
config:
ca_certificates:
- ${{ env "DECK_CA_CERT_ID" }}
nodes:
- name: AUTHOR
type: call
url: ${{ env "DECK_SERVICE_URL" }}
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200Make sure to replace the following placeholders with your own values:
routeName|Id: Theidornameof the route the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/routes/{routeName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
routeName|Id: Theidornameof the route the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/routes/{routeId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
routeId: Theidof the route the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: datakit
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
ca_certificates:
- '$CA_CERT_ID'
nodes:
- name: AUTHOR
type: call
url: '$SERVICE_URL'
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200
plugin: datakit
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the httproute or ingress resource:
kubectl annotate -n kong httproute konghq.com/plugins=datakitkubectl annotate -n kong ingress konghq.com/plugins=datakitPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_datakit" "my_datakit" {
enabled = true
config = {
ca_certificates = [var.ca_cert_id]
nodes = [
{
name = "AUTHOR"
type = "call"
url = var.service_url
ssl_verify = true
},
{
name = "EXIT"
type = "exit"
inputs = {
body = "AUTHOR.body"
}
status = 200
} ]
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
route = {
id = konnect_gateway_route.my_route.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "ca_cert_id" {
type = string
}
variable "service_url" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: datakit
consumer: consumerName|Id
config:
ca_certificates:
- ${{ env "DECK_CA_CERT_ID" }}
nodes:
- name: AUTHOR
type: call
url: ${{ env "DECK_SERVICE_URL" }}
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200Make sure to replace the following placeholders with your own values:
consumerName|Id: Theidornameof the consumer the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/consumers/{consumerName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
consumerName|Id: Theidornameof the consumer the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/consumers/{consumerId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
consumerId: Theidof the consumer the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: datakit
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
ca_certificates:
- '$CA_CERT_ID'
nodes:
- name: AUTHOR
type: call
url: '$SERVICE_URL'
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200
plugin: datakit
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the KongConsumer resource:
kubectl annotate -n kong kongconsumer CONSUMER_NAME konghq.com/plugins=datakitPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_datakit" "my_datakit" {
enabled = true
config = {
ca_certificates = [var.ca_cert_id]
nodes = [
{
name = "AUTHOR"
type = "call"
url = var.service_url
ssl_verify = true
},
{
name = "EXIT"
type = "exit"
inputs = {
body = "AUTHOR.body"
}
status = 200
} ]
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
consumer = {
id = konnect_gateway_consumer.my_consumer.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "ca_cert_id" {
type = string
}
variable "service_url" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: datakit
consumer_group: consumerGroupName|Id
config:
ca_certificates:
- ${{ env "DECK_CA_CERT_ID" }}
nodes:
- name: AUTHOR
type: call
url: ${{ env "DECK_SERVICE_URL" }}
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200Make sure to replace the following placeholders with your own values:
consumerGroupName|Id: Theidornameof the consumer group the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/consumer_groups/{consumerGroupName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
consumerGroupName|Id: Theidornameof the consumer group the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/consumer_groups/{consumerGroupId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "datakit",
"config": {
"ca_certificates": [
"'$CA_CERT_ID'"
],
"nodes": [
{
"name": "AUTHOR",
"type": "call",
"url": "'$SERVICE_URL'",
"ssl_verify": true
},
{
"name": "EXIT",
"type": "exit",
"inputs": {
"body": "AUTHOR.body"
},
"status": 200
}
]
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
consumerGroupId: Theidof the consumer group the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: datakit
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
ca_certificates:
- '$CA_CERT_ID'
nodes:
- name: AUTHOR
type: call
url: '$SERVICE_URL'
ssl_verify: true
- name: EXIT
type: exit
inputs:
body: AUTHOR.body
status: 200
plugin: datakit
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the KongConsumerGroup resource:
kubectl annotate -n kong kongconsumergroup CONSUMERGROUP_NAME konghq.com/plugins=datakitPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_datakit" "my_datakit" {
enabled = true
config = {
ca_certificates = [var.ca_cert_id]
nodes = [
{
name = "AUTHOR"
type = "call"
url = var.service_url
ssl_verify = true
},
{
name = "EXIT"
type = "exit"
inputs = {
body = "AUTHOR.body"
}
status = 200
} ]
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
consumer_group = {
id = konnect_gateway_consumer_group.my_consumer_group.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "ca_cert_id" {
type = string
}
variable "service_url" {
type = string
}