Enable Straiker Coding Agent Bufferedv3.14+
Enable the Straiker Coding Agent Buffered plugin on a Route that proxies Anthropic Messages traffic, for example from Claude Code.
This configuration fails open if Straiker Defend is unreachable, covering both the request and response phase, so a Straiker outage doesn’t return a 503 for a response the model already generated.
Because the response is held until it’s scored, this is the only Straiker plugin that can stop a tool_use before the client runs it, at the cost of added time to first token.
Don’t attach AI Proxy to the same Route. See How it works.
This plugin requires nginx_http_client_body_buffer_size raised to at least 32m. See Body buffer.
Prerequisites
-
The Straiker Coding Agent Buffered plugin is installed, with
nginx_http_client_body_buffer_sizeraised. -
A Straiker Defend API key. Contact your Straiker team for enterprise API keys and sandbox access.
-
A Service pointing at the Anthropic Messages API, for example
https://api.anthropic.com, without AI Proxy attached. Set a generousread_timeout, for example600000. It’s an inter-read timeout, not a total one, but a buffered response is only delivered once generation finishes.
Environment variables
STRAIKER_API_KEY: Your Straiker Defend API key.
Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: straiker-coding-agent-buffered
config:
api_key: ${{ env "DECK_STRAIKER_API_KEY" }}
fail_open: trueMake the following request:
curl -i -X POST http://localhost:8001/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongClusterPlugin
metadata:
name: straiker-coding-agent-buffered
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
labels:
global: 'true'
config:
api_key: '$STRAIKER_API_KEY'
fail_open: true
plugin: straiker-coding-agent-buffered
" | kubectl apply -f -Prerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_straiker_coding_agent_buffered" "my_straiker_coding_agent_buffered" {
enabled = true
config = {
api_key = var.straiker_api_key
fail_open = true
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "straiker_api_key" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: straiker-coding-agent-buffered
service: serviceName|Id
config:
api_key: ${{ env "DECK_STRAIKER_API_KEY" }}
fail_open: trueMake sure to replace the following placeholders with your own values:
serviceName|Id: Theidornameof the service the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/services/{serviceName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
serviceName|Id: Theidornameof the service the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/services/{serviceId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
serviceId: Theidof the service the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: straiker-coding-agent-buffered
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
api_key: '$STRAIKER_API_KEY'
fail_open: true
plugin: straiker-coding-agent-buffered
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the service resource:
kubectl annotate -n kong service SERVICE_NAME konghq.com/plugins=straiker-coding-agent-bufferedPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_straiker_coding_agent_buffered" "my_straiker_coding_agent_buffered" {
enabled = true
config = {
api_key = var.straiker_api_key
fail_open = true
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
service = {
id = konnect_gateway_service.my_service.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "straiker_api_key" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: straiker-coding-agent-buffered
route: routeName|Id
config:
api_key: ${{ env "DECK_STRAIKER_API_KEY" }}
fail_open: trueMake sure to replace the following placeholders with your own values:
routeName|Id: Theidornameof the route the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/routes/{routeName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
routeName|Id: Theidornameof the route the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/routes/{routeId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
routeId: Theidof the route the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: straiker-coding-agent-buffered
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
api_key: '$STRAIKER_API_KEY'
fail_open: true
plugin: straiker-coding-agent-buffered
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the httproute or ingress resource:
kubectl annotate -n kong httproute konghq.com/plugins=straiker-coding-agent-bufferedkubectl annotate -n kong ingress konghq.com/plugins=straiker-coding-agent-bufferedPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_straiker_coding_agent_buffered" "my_straiker_coding_agent_buffered" {
enabled = true
config = {
api_key = var.straiker_api_key
fail_open = true
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
route = {
id = konnect_gateway_route.my_route.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "straiker_api_key" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: straiker-coding-agent-buffered
consumer: consumerName|Id
config:
api_key: ${{ env "DECK_STRAIKER_API_KEY" }}
fail_open: trueMake sure to replace the following placeholders with your own values:
consumerName|Id: Theidornameof the consumer the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/consumers/{consumerName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
consumerName|Id: Theidornameof the consumer the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/consumers/{consumerId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
consumerId: Theidof the consumer the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: straiker-coding-agent-buffered
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
api_key: '$STRAIKER_API_KEY'
fail_open: true
plugin: straiker-coding-agent-buffered
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the KongConsumer resource:
kubectl annotate -n kong kongconsumer CONSUMER_NAME konghq.com/plugins=straiker-coding-agent-bufferedPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_straiker_coding_agent_buffered" "my_straiker_coding_agent_buffered" {
enabled = true
config = {
api_key = var.straiker_api_key
fail_open = true
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
consumer = {
id = konnect_gateway_consumer.my_consumer.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "straiker_api_key" {
type = string
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: straiker-coding-agent-buffered
consumer_group: consumerGroupName|Id
config:
api_key: ${{ env "DECK_STRAIKER_API_KEY" }}
fail_open: trueMake sure to replace the following placeholders with your own values:
consumerGroupName|Id: Theidornameof the consumer group the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/consumer_groups/{consumerGroupName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
consumerGroupName|Id: Theidornameof the consumer group the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/consumer_groups/{consumerGroupId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "straiker-coding-agent-buffered",
"config": {
"api_key": "'$STRAIKER_API_KEY'",
"fail_open": true
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
consumerGroupId: Theidof the consumer group the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: straiker-coding-agent-buffered
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
api_key: '$STRAIKER_API_KEY'
fail_open: true
plugin: straiker-coding-agent-buffered
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the KongConsumerGroup resource:
kubectl annotate -n kong kongconsumergroup CONSUMERGROUP_NAME konghq.com/plugins=straiker-coding-agent-bufferedPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_straiker_coding_agent_buffered" "my_straiker_coding_agent_buffered" {
enabled = true
config = {
api_key = var.straiker_api_key
fail_open = true
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
consumer_group = {
id = konnect_gateway_consumer_group.my_consumer_group.id
}
}This example requires the following variables to be added to your manifest. You can specify values at runtime by setting TF_VAR_name=value.
variable "straiker_api_key" {
type = string
}