Kong Event Gateway Virtual Cluster Consume Policies API

Consume policies operate on Kafka messages as they are read from a Kafka cluster. Transformations may be applied at consume time, but they are applied once per Consumer. Where possible, transofmrations should be applied as a Produce policy

OpenAPI Specification

kong-event-gateway-virtual-cluster-consume-policies-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API.


    You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com).

    Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.'
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: Kong Enterprise Admin ACLs Event Gateway Virtual Cluster Consume Policies API
  version: 3.14.0
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
security:
- adminToken: []
tags:
- name: Event Gateway Virtual Cluster Consume Policies
  description: 'Consume policies operate on Kafka messages as they are read from a Kafka cluster.


    Transformations may be applied at consume time, but they are applied once per Consumer. Where possible, transofmrations should be applied as a Produce policy

    '
paths:
  /v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/consume-policies:
    parameters:
    - $ref: '#/components/parameters/gatewayId'
    - $ref: '#/components/parameters/virtualClusterId'
    get:
      operationId: list-event-gateway-virtual-cluster-consume-policies
      summary: List Consume Policies for Virtual Cluster
      description: Returns a list of consume policies associated with the specified Event Gateway virtual cluster.
      parameters:
      - $ref: '#/components/parameters/EventGatewayPolicyListFilter'
      responses:
        '200':
          $ref: '#/components/responses/ListConsumePoliciesResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
    post:
      x-speakeasy-entity-operation:
        terraform-resource: EventGatewayVirtualClusterConsumePolicy#create
        terraform-datasource: null
      operationId: create-event-gateway-virtual-cluster-consume-policy
      summary: Create Consume Policy for Virtual Cluster
      description: Creates a new consume policy associated with the specified Event Gateway virtual cluster.
      parameters:
      - $ref: '#/components/parameters/EventGatewayPolicyBefore'
      - $ref: '#/components/parameters/EventGatewayPolicyAfter'
      requestBody:
        $ref: '#/components/requestBodies/CreateEventGatewayConsumePolicyRequest'
      responses:
        '201':
          description: Created
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EventGatewayPolicy'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
  /v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/consume-policies/{policyId}:
    parameters:
    - $ref: '#/components/parameters/gatewayId'
    - $ref: '#/components/parameters/virtualClusterId'
    - name: policyId
      in: path
      description: The UUID of the policy.
      required: true
      schema:
        type: string
        format: uuid
        example: 9524ec7d-36d9-465d-a8c5-83a3c9390458
      x-speakeasy-match: id
    get:
      x-speakeasy-entity-operation:
        terraform-resource: EventGatewayVirtualClusterConsumePolicy#read
        terraform-datasource: null
      operationId: get-event-gateway-virtual-cluster-consume-policy
      summary: Get a Consume Policy for Virtual Cluster
      description: Returns information about a specific consume policy associated with the Event Gateway virtual cluster.
      responses:
        '200':
          description: A single consume policy object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EventGatewayPolicy'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
    put:
      x-speakeasy-entity-operation:
        terraform-resource: EventGatewayVirtualClusterConsumePolicy#update
        terraform-datasource: null
      operationId: update-event-gateway-virtual-cluster-consume-policy
      summary: Update Consume Policy for Virtual Cluster
      description: Updates an existing consume policy associated with the specified Event Gateway virtual cluster.
      requestBody:
        $ref: '#/components/requestBodies/UpdateEventGatewayConsumePolicyRequest'
      responses:
        '200':
          description: Updated consume policy object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EventGatewayPolicy'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
    patch:
      operationId: patch-event-gateway-virtual-cluster-consume-policy
      summary: Patch Consume Policy for Virtual Cluster
      description: Updates an existing consume policy associated with the specified Event Gateway virtual cluster.
      requestBody:
        $ref: '#/components/requestBodies/PatchEventGatewayPolicyRequest'
      responses:
        '200':
          description: Updated consume policy object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EventGatewayPolicy'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
    delete:
      x-speakeasy-entity-operation:
        terraform-resource: EventGatewayVirtualClusterConsumePolicy#delete
        terraform-datasource: null
      operationId: delete-event-gateway-virtual-cluster-consume-policy
      summary: Delete Consume Policy for Virtual Cluster
      description: Deletes a specific consume policy associated with the Event Gateway virtual cluster.
      responses:
        '204':
          description: No Content
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
  /v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/consume-policies/{policyId}/move:
    parameters:
    - $ref: '#/components/parameters/gatewayId'
    - $ref: '#/components/parameters/virtualClusterId'
    - $ref: '#/components/parameters/policyId'
    post:
      operationId: move-event-gateway-virtual-cluster-consume-policy
      summary: Move Consume Policy
      description: 'Moves the position of a specific consume policy relative to the chain associated with the Event Gateway virtual

        cluster.

        If a policy is defined under a parent policy, it moves the position relative to the sibling policies under the

        same parent.

        '
      requestBody:
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/MoveEventGatewayPolicy'
      responses:
        '204':
          description: No Content
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
  /v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/consume-policy-chain:
    parameters:
    - $ref: '#/components/parameters/gatewayId'
    - $ref: '#/components/parameters/virtualClusterId'
    get:
      operationId: get-event-gateway-virtual-cluster-consume-policy-chain
      summary: Get Consume Policy Chain
      description: 'Get the consume policy chain for a virtual cluster composed of all the ids of the consume policies in order of execution.

        '
      responses:
        '200':
          $ref: '#/components/responses/EventGatewayPolicyChainResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
    put:
      operationId: update-event-gateway-virtual-cluster-consume-policy-chain
      summary: Update Consume Policy Chain
      description: Update the consume policy chain for a virtual cluster by providing an ordered list of consume policy ids.
      requestBody:
        $ref: '#/components/requestBodies/UpdateEventGatewayPolicyChainRequest'
      responses:
        '200':
          $ref: '#/components/responses/EventGatewayPolicyChainResponse'
        '400':
          $ref: '#/components/responses/BadRequest'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
      tags:
      - Event Gateway Virtual Cluster Consume Policies
components:
  schemas:
    InvalidParameterMinimumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - min_length
          - min_digits
          - min_lowercase
          - min_uppercase
          - min_symbols
          - min_items
          - min
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        minimum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must have at least 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - minimum
    SchemaValidationType:
      description: 'How to validate the schema and parse the record.

        * confluent_schema_registry - validates against confluent schema registry.

        * json - simple JSON parsing without the schema.

        '
      type: string
      enum:
      - confluent_schema_registry
      - json
      x-speakeasy-unknown-values: allow
    ConsumeFailureMode:
      description: 'Describes how to handle a failure in a policy applied to consumed records.

        * `error` - the batch is not delivered to the client. Use sparingly: erroring on a batch causes clients to get stuck on the problematic offset and requires manual intervention to skip it.

        * `skip` - the record is not delivered to the client.

        * `passthrough` - passes the record to the client even though policy execution failed.

        * `mark` - passes the record to the client but marks it with a `kong/policy-failure-<id>` header whose value is the reason for the policy failure (truncated to 512 characters).

        '
      type: string
      enum:
      - error
      - skip
      - passthrough
      - mark
      x-speakeasy-unknown-values: allow
    EventGatewaySkipRecordPolicyCreate:
      description: A policy that skips processing of a record.
      type: object
      properties:
        type:
          description: The type name of the policy.
          type: string
          const: skip_record
          maxLength: 255
          minLength: 1
        name:
          description: A unique user-defined name of the policy.
          type: string
          maxLength: 255
          x-unicode-pattern: ^[\p{L}\p{N}][\p{L}\p{N} _\-\.:/+']*[\p{L}\p{N}]$
        description:
          description: A human-readable description of the policy.
          type: string
          default: ''
          maxLength: 512
        enabled:
          description: Whether the policy is enabled.
          type: boolean
          default: true
        labels:
          $ref: '#/components/schemas/Labels'
        condition:
          description: 'A string containing the boolean expression that determines whether the policy is applied.


            When the policy is applied as a child policy of schema_validation, the expression can also reference

            `record.value` fields.

            '
          type: string
          example: record.value.content.foo.bar == "a-value"
          default: ''
          maxLength: 1000
          x-expression:
            type: boolean
            fields:
            - name: context.auth.principal.name
              type: string
              description: Name of authenticated principal. Username in case of PLAIN/SCRAM, `sub` claim in case of OAUTHBEARER.
            - name: context.auth.type
              type: string
              description: 'The matched authentication type from a virtual cluster: anonymous, sasl_plain, sasl_scram_sha256, sasl_scram_sha512, sasl_oauth_bearer.

                '
            - name: context.topic.name
              type: string
              description: The name of the topic.
            - name: record.headers
              type: object
              description: An associative array of header key value pairs.
            - name: record.value.validated
              type: boolean
              description: Indicates whether the record value was successfully validated.
            - name: record.value.content
              type: object
              description: The content of the record value.
        parent_policy_id:
          description: The unique identifier of the parent schema validation policy, if any.
          type: string
          format: uuid
      required:
      - type
      title: Skip Record
    ConsumeValueValidationAction:
      description: "Defines a behavior when record value is not valid.\n* mark - marks a record with kong/server header and client ID value\n  to help to identify the clients violating schema.\n* skip - skips delivering a record.\n"
      type: string
      enum:
      - mark
      - skip
      x-speakeasy-unknown-values: allow
    EventGatewayModifyHeaderRemoveAction:
      description: An action that removes a header by key.
      type: object
      properties:
        op:
          type: string
          const: remove
        key:
          description: The key of the header to remove.
          type: string
      required:
      - op
      - key
    EventGatewayConsumePolicyCreate:
      description: The typed schema of the consume policy to modify it.
      discriminator:
        propertyName: type
        mapping:
          modify_headers: '#/components/schemas/EventGatewayModifyHeadersPolicyCreate'
          schema_validation: '#/components/schemas/EventGatewayConsumeSchemaValidationPolicy'
          decrypt: '#/components/schemas/EventGatewayDecryptPolicy'
          skip_record: '#/components/schemas/EventGatewaySkipRecordPolicyCreate'
          decrypt_fields: '#/components/schemas/EventGatewayParsedRecordDecryptFieldsPolicyCreate'
      oneOf:
      - $ref: '#/components/schemas/EventGatewayConsumeSchemaValidationPolicy'
      - $ref: '#/components/schemas/EventGatewayModifyHeadersPolicyCreate'
      - $ref: '#/components/schemas/EventGatewaySkipRecordPolicyCreate'
      - $ref: '#/components/schemas/EventGatewayDecryptPolicy'
      - $ref: '#/components/schemas/EventGatewayParsedRecordDecryptFieldsPolicyCreate'
    SchemaRegistryReference:
      description: A reference to a schema Registry.
      oneOf:
      - $ref: '#/components/schemas/SchemaRegistryReferenceById'
      - $ref: '#/components/schemas/SchemaRegistryReferenceByName'
      x-terraform-preferred: '#/components/schemas/SchemaRegistryReferenceById'
    InvalidParameterChoiceItem:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - enum
          nullable: false
          readOnly: true
        reason:
          type: string
          example: is a required field
          readOnly: true
        choices:
          type: array
          items: {}
          minItems: 1
          nullable: false
          readOnly: true
          uniqueItems: true
        source:
          type: string
          example: body
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - choices
    SchemaRegistryReferenceById:
      type: object
      properties:
        id:
          description: The unique identifier of the schema registry.
          type: string
          format: uuid
          minLength: 1
      required:
      - id
    InvalidParameterMaximumLength:
      type: object
      properties:
        field:
          type: string
          example: name
          readOnly: true
        rule:
          description: invalid parameters rules
          type: string
          enum:
          - max_length
          - max_items
          - max
          nullable: false
          readOnly: true
          x-speakeasy-unknown-values: allow
        maximum:
          type: integer
          example: 8
        source:
          type: string
          example: body
        reason:
          type: string
          example: must not have more than 8 characters
          readOnly: true
      additionalProperties: false
      required:
      - field
      - reason
      - rule
      - maximum
    UpdatedAt:
      description: An ISO-8601 timestamp representation of entity update date.
      type: string
      format: date-time
      example: '2022-11-04T20:10:06.927Z'
      readOnly: true
      x-speakeasy-param-suppress-computed-diff: true
    EventGatewayParsedRecordDecryptionSelector:
      description: Selects fields of a parsed record for decryption.
      type: object
      properties:
        paths:
          description: Selects which fields of the parsed record to decrypt. A maximum of 50 path entries are allowed.
          oneOf:
          - type: array
            maxItems: 50
            items:
              type: object
              required:
              - match
              properties:
                match:
                  description: 'A field selector. It can select nested fields and array entries.


                    Currently supported are exact matches.

                    '
                  type: string
                  example: someObject.someArray[1].fieldName
          - type: string
            x-expression:
              type: array
              items:
                type: string
              fields:
              - name: context.auth.principal.name
                type: string
                description: Name of authenticated principal. Username in case of PLAIN/SCRAM, `sub` claim in case of OAUTHBEARER.
              - name: context.auth.type
                type: string
                description: 'The matched authentication type from a virtual cluster: anonymous, sasl_plain, sasl_scram_sha256, sasl_scram_sha512, sasl_oauth_bearer.

                  '
              - name: context.auth.token.claims
                type: object
                description: All claims from the JWT token. Only populated for sasl_oauth_bearer authentication. Claims can be strings, numbers, booleans, arrays or nested JSON objects.
              - name: record.headers
                type: object
                description: An associative array of header key value pairs.
              - name: record.value.content
                type: object
                description: The content of the record value.
            description: 'This expression should evaluate to an array of exact field paths,

              equivalent to the `match` values in the array variant.

              '
            example: '${context.auth.type == ''sasl_oauth_bearer'' ? [''credentials.accessToken'', ''credentials.refreshToken''] : [''credentials.password'']}

              '
      required:
      - paths
    EventGatewayModifyHeaderSetAction:
      description: An action that sets a header key and value.
      type: object
      properties:
        op:
          type: string
          const: set
        key:
          description: The key of the header to set.
          type: string
        value:
          description: The value of the header to set.
          type: string
      required:
      - op
      - key
      - value
    EventGatewayKeySource:
      description: 'A key source that describes how to find a symmetric key for encryption or decryption.

        It can be an AWS KMS key source that uses a KMS to find a symmetric key,

        or a static key source that uses a static symmetric key provided as secrets.

        '
      discriminator:
        propertyName: type
        mapping:
          aws: '#/components/schemas/EventGatewayAWSKeySource'
          static: '#/components/schemas/EventGatewayStaticKeySource'
      oneOf:
      - $ref: '#/components/schemas/EventGatewayAWSKeySource'
      - $ref: '#/components/schemas/EventGatewayStaticKeySource'
    EventGatewayDecryptPolicy:
      description: Decrypts Kafka records or keys using AES_256_GCM. Keys are therefore 256 bits long.
      type: object
      properties:
        type:
          description: The type name of the policy.
          type: string
          const: decrypt
          maxLength: 255
          minLength: 1
        name:
          description: A unique user-defined name of the policy.
          type: string
          maxLength: 255
          x-unicode-pattern: ^[\p{L}\p{N}][\p{L}\p{N} _\-\.:/+']*[\p{L}\p{N}]$
        description:
          description: A human-readable description of the policy.
          type: string
          default: ''
          maxLength: 512
        enabled:
          description: Whether the policy is enabled.
          type: boolean
          default: true
        labels:
          $ref: '#/components/schemas/Labels'
        config:
          description: The configuration of the policy.
          type: object
          $ref: '#/components/schemas/EventGatewayDecryptPolicyConfig'
        condition:
          description: A string containing the boolean expression that determines whether the policy is applied.
          type: string
          example: context.topic.name.endsWith("my_suffix") && record.headers["x-flag"] == "a-value"
          default: ''
          maxLength: 1000
          x-expression:
            type: boolean
            fields:
            - name: context.auth.principal.name
              type: string
              description: Name of authenticated principal. Username in case of PLAIN/SCRAM, `sub` claim in case of OAUTHBEARER.
            - name: context.auth.type
              type: string
              description: 'The matched authentication type from a virtual cluster: anonymous, sasl_plain, sasl_scram_sha256, sasl_scram_sha512, sasl_oauth_bearer.

                '
            - name: context.topic.name
              type: string
              description: The name of the topic.
            - name: record.headers
              type: object
              description: An associative array of header key value pairs.
      required:
      - type
      - config
      title: Decrypt
    EventGatewayPolicyPatch:
      description: The schema of the policy to patch it.
      properties:
        name:
          description: A unique user-defined name of the policy.
          type: string
          maxLength: 255
          minLength: 1
          nullable: true
          pattern: ^[\p{L}\p{N}][\p{L}\p{N} _\-\.']*[\p{L}\p{N}]$
        description:
          description: A human-readable description of the policy.
          type: string
          maxLength: 512
          nullable: true
        enabled:
          description: Whether the policy is enabled.
          type: boolean
        condition:
          description: A string containing the boolean expression that determines whether the policy is applied.
          type: string
          example: context.topic.name.endsWith('my_suffix')
          maxLength: 1000
          nullable: true
          x-expression:
            type: boolean
        labels:
          $ref: '#/components/schemas/Labels'
    EventGatewayParsedRecordDecryptFieldsConfig:
      description: The configuration of the decrypt parsed record fields policy.
      type: object
      properties:
        failure_mode:
          $ref: '#/components/schemas/ConsumeFailureMode'
        key_sources:
          description: Describes how to find a symmetric key for decryption.
          type: array
          items:
            $ref: '#/components/schemas/EventGatewayKeySource'
          minItems: 1
        decrypt_fields:
          description: Selects which fields to decrypt.
          type: array
          items:
            $ref: '#/components/schemas/EventGatewayParsedRecordDecryptionSelector'
          minItems: 1
      required:
      - failure_mode
      - key_sources
      - decrypt_fields
    Labels:
      description: "Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. \n\nKeys must be of length 1-63 characters, and cannot start with \"kong\", \"konnect\", \"mesh\", \"kic\", or \"_\".\n"
      type: object
      example:
        env: test
      additionalProperties:
        type: string
        pattern: ^[a-z0-9A-Z]{1}([a-z0-9A-Z-._]*[a-z0-9A-Z]+)?$
        minLength: 1
        maxLength: 63
      maxProperties: 50
      title: Labels
    ForbiddenError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 403
          title:
            example: Forbidden
          type:
            example: https://httpstatuses.com/403
          instance:
            example: kong:trace:1234567890
          detail:
            example: Forbidden
    UnauthorizedError:
      allOf:
      - $ref: '#/components/schemas/BaseError'
      - type: object
        properties:
          status:
            example: 401
          title:
            example: Unauthorized
          type:
            example: https://httpstatuses.com/401
          instance:
            example: kong:trace:1234567890
          detail:
            example: Invalid credentials
    EventGatewaySkipRecordPolicy:
      description: A policy that skips processing of a record.
      type: object
      properties:
        type:
          description: The type name of the policy.
          type: string
          const: skip_record
          maxLength: 255
          minLength: 1
        name:
          description: A unique user-defined name of the policy.
          type: string
          maxLength: 255
          x-unicode-pattern: ^[\p{L}\p{N}][\p{L}\p{N} _\-\.:/+']*[\p{L}\p{N}]$
        description:
          description: A human-readable description of the policy.
          type: string
          default: ''
          maxLength: 512
        enabled:
          description: Whether the policy is enabled.
          type: boolean
          default: true
        labels:
          $ref: '#/components/schemas/Labels'
        condition:
          description: 'A string containing the boolean expression that determines whether the policy is applied.


            When the policy is applied as a child policy of schema_validation, the expression can also reference

            `record.value` fields.

            '
          type: string
          example: record.value.content.foo.bar == "a-value"
          default: ''
          maxLength: 1000
          x-expression:
            type: boolean
            fields:
            - name: context.auth.principal.name
              type: string
              description: Name of authenticated principal. Username in case of PLAIN/SCRAM, `sub` claim in case of OAUTHBEARER.
            - name: context.auth.type
              type: string
              description: 'The matched authentication type from a virtual cluster: anonymous, sasl_plain, sasl_scram_sha256, sasl_scram_sha512, sasl_oauth_bearer.

                '
            - name: context.topic.name
              type: string
              description: The name of the topic.
            - name: record.headers
              type: object
              description: An associative array of header key value pairs.
            - name: record.value.validated
              type: boolean
              description: Indicates whether the record value was successfully validated.
            - name: record.value.content
              type: object
              description: The content of the record value.
      required:
      - type
    EventGatewayParsedRecordDecryptFieldsPolicyCreate:
      description: 'Decrypts fields of parsed Kafka records using AES_256_GCM. Keys are therefore 256 bits long.


        Note this policy can only be used as a child of a `EventGatewayConsumeSchemaValidationPolicy` policy.

        '
      type: object
      properties:
        type:
          description: The type name of the policy.
          type: string
          const: decrypt_fields
          maxLength: 255
          minLength: 1
        name:
          description: A unique user-defined name of the policy.
          type: string
          maxLength: 255
          x-unicode-pattern: ^[\p{L}\p{N}][\p{L}\p{N} _\-\.:/+']*[\p{L}\p{N}]$
        description:
          description: A human-readable description of the policy.
          type: string
          default: ''
          maxLength: 512
        enabled:
          description: Whether the policy is enabled.
          type: boolean
          default: true
        labels:
          $ref: '#/components/schemas/Labels'
        config:
          description: The configuration of the policy.
          type: object
          $ref: '#/components/schemas/EventGatewayParsedRecordDecryptFieldsConfig'
        condition:
          description: 'A string containing the boolean expression that determines whether the policy is applied.


            When the policy is applied as a child policy of schema_validation, the expression can also reference

            `record.value` fields.

            '
          type: string
          example: record.value.content.foo.bar == "a-value"
          default: ''
          maxLength: 1000
          x-expression:
            type: boolean
            fields:
            - name: context.auth.principal.name
              type: string
              description: Name of authenticated principal. Username in case of PLAIN/SCRAM, `sub` claim in case of OAUTHBEARER.
            - name: context.auth.type
              type: string
              description: 'The matched authentication type from a virtual cluster: anonymous, sasl_plain, sasl_scram_sha256, sasl_scram_sha512, sasl_oauth_bearer.

                '
            - name: context.topic.name
              type: string
              description: The name of the topic.
            - name: record.headers
              type: object
              description: An associative array of header key value pairs.
            - name: record.value.validated
              type: boolean
              description: Indicates whether the record value was successfully validated.
            - name: record.value.content
              type: object
              description: The content of the record value.
        parent_policy_id:
          description: The unique identifier of the parent schema validation policy.
          type: string
          format: uuid
      required:
      - type
      - config
      - parent_policy_id
      title: Decrypt Parsed Record Fields
    EventGatewayStaticKeySource:
      description: 'A key source that uses static symmetric keys.

        '
      type: object
      properties:
        type:
          type: string
          

# --- truncated at 32 KB (59 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/kong/refs/heads/main/openapi/kong-event-gateway-virtual-cluster-consume-policies-api-openapi.yml