Kong Partials API

Some entities in Kong Gateway share common configuration settings that often need to be repeated. For example, multiple plugins that connect to Redis may require the same connection settings. Without Partials, you would need to replicate this configuration across all plugins. If the settings change, you would need to update each plugin individually.

OpenAPI Specification

kong-partials-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  contact:
    email: support@konghq.com
    name: Kong Inc
    url: https://konghq.com
  description: 'OpenAPI 3.0 spec for Kong Gateway''s Admin API.


    You can learn more about Kong Gateway at [developer.konghq.com](https://developer.konghq.com).

    Give Kong a star at the [Kong/kong](https://github.com/kong/kong) repository.'
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
  title: Kong Enterprise Admin ACLs Partials API
  version: 3.14.0
servers:
- description: Default Admin API URL
  url: '{protocol}://{hostname}:{port}{path}'
  variables:
    hostname:
      default: localhost
      description: Hostname for Kong's Admin API
    path:
      default: /
      description: Base path for Kong's Admin API
    port:
      default: '8001'
      description: Port for Kong's Admin API
    protocol:
      default: http
      description: Protocol for requests to Kong's Admin API
      enum:
      - http
      - https
security:
- adminToken: []
tags:
- description: Some entities in Kong Gateway share common configuration settings that often need to be repeated. For example, multiple plugins that connect to Redis may require the same connection settings. Without Partials, you would need to replicate this configuration across all plugins. If the settings change, you would need to update each plugin individually.
  name: Partials
paths:
  /{workspace}/partials:
    post:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Partial#create
      operationId: create-partial
      summary: Create a new Partial
      description: Create a new Partial
      parameters:
      - $ref: '#/components/parameters/Workspace'
      requestBody:
        description: Description of the new Partial for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Partial'
      responses:
        '201':
          description: Successfully created Partial
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Partial'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Partials
  /{workspace}/partials/{PartialId}:
    parameters:
    - $ref: '#/components/parameters/PartialId'
    delete:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Partial#delete
      operationId: delete-partial
      summary: Delete a Partial
      description: Delete a Partial
      parameters:
      - $ref: '#/components/parameters/PartialId'
      - $ref: '#/components/parameters/Workspace'
      responses:
        '204':
          description: Successfully deleted Partial or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Partials
    get:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Partial#read
      operationId: get-partial
      summary: Get a Partial
      description: Get a Partial using ID.
      parameters:
      - $ref: '#/components/parameters/Workspace'
      responses:
        '200':
          description: Successfully fetched Partial
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Partial'
        '401':
          $ref: '#/components/responses/HTTP401Error'
        '404':
          description: Resource does not exist
      tags:
      - Partials
    put:
      x-speakeasy-entity-operation:
        terraform-datasource: null
        terraform-resource: Partial#update
      operationId: upsert-partial
      summary: Upsert a Partial
      description: Create or Update Partial using ID.
      parameters:
      - $ref: '#/components/parameters/Workspace'
      requestBody:
        description: Description of the Partial
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Partial'
      responses:
        '200':
          description: Successfully upserted Partial
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Partial'
        '401':
          $ref: '#/components/responses/HTTP401Error'
      tags:
      - Partials
  /v2/control-planes/{controlPlaneId}/core-entities/partials:
    parameters:
    - $ref: '#/components/parameters/controlPlaneId'
    get:
      operationId: list-partial
      summary: List all Partials
      description: List all Partials
      parameters:
      - $ref: '#/components/parameters/PaginationSize'
      - $ref: '#/components/parameters/PaginationOffset'
      - $ref: '#/components/parameters/PaginationTagsFilter'
      responses:
        '200':
          description: A successful response listing Partials
          content:
            application/json:
              schema:
                type: object
                properties:
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/Partial_2'
                  next:
                    $ref: '#/components/schemas/PaginationNextResponse'
                  offset:
                    $ref: '#/components/schemas/PaginationOffsetResponse'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Partials
    post:
      operationId: create-partial
      summary: Create a new Partial
      description: Create a new Partial
      requestBody:
        description: Description of the new Partial for creation
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Partial_2'
      responses:
        '201':
          description: Successfully created Partial
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Partial_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Partials
  /v2/control-planes/{controlPlaneId}/core-entities/partials/{PartialId}:
    parameters:
    - $ref: '#/components/parameters/PartialId_2'
    - $ref: '#/components/parameters/controlPlaneId'
    delete:
      operationId: delete-partial
      summary: Delete a Partial
      description: Delete a Partial
      parameters:
      - $ref: '#/components/parameters/PartialId_2'
      responses:
        '204':
          description: Successfully deleted Partial or the resource didn't exist
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Partials
    get:
      operationId: get-partial
      summary: Get a Partial
      description: Get a Partial using ID.
      responses:
        '200':
          description: Successfully fetched Partial
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Partial_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
        '404':
          description: Resource does not exist
      tags:
      - Partials
    put:
      operationId: upsert-partial
      summary: Upsert a Partial
      description: Create or Update Partial using ID.
      requestBody:
        description: Description of the Partial
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/Partial_2'
      responses:
        '200':
          description: Successfully upserted Partial
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Partial_2'
        '401':
          $ref: '#/components/responses/HTTP401Error_2'
      tags:
      - Partials
components:
  schemas:
    Partial:
      x-speakeasy-entity: Partial
      type: object
      discriminator:
        mapping:
          embeddings: '#/components/schemas/PartialEmbeddings'
          model: '#/components/schemas/PartialModel'
          redis-ce: '#/components/schemas/PartialRedisCe'
          redis-ee: '#/components/schemas/PartialRedisEe'
          vectordb: '#/components/schemas/PartialVectordb'
        propertyName: type
      oneOf:
      - $ref: '#/components/schemas/PartialRedisCe'
      - $ref: '#/components/schemas/PartialRedisEe'
      - $ref: '#/components/schemas/PartialVectordb'
      - $ref: '#/components/schemas/PartialEmbeddings'
      - $ref: '#/components/schemas/PartialModel'
    PartialRedisEe_2:
      type: object
      properties:
        config:
          type: object
          properties:
            cloud_authentication:
              description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
              type: object
              properties:
                auth_provider:
                  description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance.
                  type: string
                  enum:
                  - aws
                  - azure
                  - gcp
                  x-referenceable: true
                  x-speakeasy-unknown-values: allow
                aws_access_key_id:
                  description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                aws_assume_role_arn:
                  description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                aws_cache_name:
                  description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`.
                  type: string
                  x-referenceable: true
                aws_is_serverless:
                  description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`.
                  type: boolean
                  default: true
                aws_region:
                  description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`.
                  type: string
                  x-referenceable: true
                aws_role_session_name:
                  description: The session name for the temporary credentials when assuming the IAM role.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                aws_secret_access_key:
                  description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                azure_client_id:
                  description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                azure_client_secret:
                  description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                azure_tenant_id:
                  description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                gcp_service_account_json:
                  description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
            cluster_max_redirections:
              description: Maximum retry attempts for redirection.
              type: integer
              default: 5
            cluster_nodes:
              description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
              type: array
              items:
                properties:
                  ip:
                    description: A string representing a host name, such as example.com.
                    type: string
                    default: 127.0.0.1
                  port:
                    description: An integer representing a port number between 0 and 65535, inclusive.
                    type: integer
                    default: 6379
                    maximum: 65535
                    minimum: 0
                type: object
              minLength: 1
            connect_timeout:
              description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2.
              type: integer
              default: 2000
              maximum: 2147483646
              minimum: 0
            connection_is_proxied:
              description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address.
              type: boolean
              default: false
            database:
              description: Database to use for the Redis connection when using the `redis` strategy
              type: integer
              default: 0
            host:
              description: A string representing a host name, such as example.com.
              type: string
              default: 127.0.0.1
              x-referenceable: true
            keepalive_backlog:
              description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`.
              type: integer
              maximum: 2147483646
              minimum: 0
            keepalive_pool_size:
              description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low.
              type: integer
              default: 256
              maximum: 2147483646
              minimum: 1
            password:
              description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
              type: string
              x-encrypted: true
              x-referenceable: true
            port:
              description: An integer representing a port number between 0 and 65535, inclusive.
              type:
              - integer
              - string
              default: 6379
              maximum: 65535
              minimum: 0
              x-referenceable: true
            read_timeout:
              description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2.
              type: integer
              default: 2000
              maximum: 2147483646
              minimum: 0
            send_timeout:
              description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2.
              type: integer
              default: 2000
              maximum: 2147483646
              minimum: 0
            sentinel_master:
              description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
              type: string
            sentinel_nodes:
              description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
              type: array
              items:
                properties:
                  host:
                    description: A string representing a host name, such as example.com.
                    type: string
                    default: 127.0.0.1
                  port:
                    description: An integer representing a port number between 0 and 65535, inclusive.
                    type: integer
                    default: 6379
                    maximum: 65535
                    minimum: 0
                type: object
              minLength: 1
            sentinel_password:
              description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
              type: string
              x-encrypted: true
              x-referenceable: true
            sentinel_role:
              description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel.
              type: string
              enum:
              - any
              - master
              - slave
              x-speakeasy-unknown-values: allow
            sentinel_username:
              description: Sentinel username to authenticate with a Redis Sentinel instance. If undefined, ACL authentication won't be performed. This requires Redis v6.2.0+.
              type: string
              x-referenceable: true
            server_name:
              description: A string representing an SNI (server name indication) value for TLS.
              type: string
              x-referenceable: true
            ssl:
              description: If set to true, uses SSL to connect to Redis.
              type: boolean
              default: false
            ssl_verify:
              description: If set to true, verifies the validity of the server SSL certificate. If setting this parameter, also configure `lua_ssl_trusted_certificate` in `kong.conf` to specify the CA (or server) certificate used by your Redis server. You may also need to configure `lua_ssl_verify_depth` accordingly.
              type: boolean
              default: true
            username:
              description: Username to use for Redis connections. If undefined, ACL authentication won't be performed. This requires Redis v6.0.0+. To be compatible with Redis v5.x.y, you can set it to `default`.
              type: string
              x-referenceable: true
        created_at:
          description: Unix epoch when the resource was created.
          type: integer
          nullable: true
        id:
          description: A string representing a UUID (universally unique identifier).
          type: string
          nullable: true
        name:
          description: A unique string representing a UTF-8 encoded name.
          type: string
          nullable: true
        tags:
          description: A set of strings representing tags.
          type: array
          items:
            description: A string representing a tag.
            type: string
          nullable: true
        type:
          type: string
          const: redis-ee
        updated_at:
          description: Unix epoch when the resource was last updated.
          type: integer
          nullable: true
      example:
        config:
          cluster_nodes:
          - ip: 192.168.1.10
            port: 6380
          connect_timeout: 2000
          database: 0
          host: localhost
          keepalive_pool_size: 256
          password: password
          port: 6379
          read_timeout: 1000
          send_timeout: 1000
          sentinel_nodes:
          - host: sentinel1.redis.server
            port: 26379
          server_name: redis-ee
          ssl: false
          ssl_verify: false
          username: username
        type: redis-ee
      additionalProperties: false
      required:
      - type
      - config
    PartialVectordb_2:
      type: object
      properties:
        config:
          type: object
          properties:
            dimensions:
              description: the desired dimensionality for the vectors
              type: integer
            distance_metric:
              description: the distance metric to use for vector searches
              type: string
              enum:
              - cosine
              - euclidean
              x-speakeasy-unknown-values: allow
            pgvector:
              type: object
              properties:
                database:
                  description: the database of the pgvector database
                  type: string
                  default: kong-pgvector
                host:
                  description: the host of the pgvector database
                  type: string
                  default: 127.0.0.1
                password:
                  description: the password of the pgvector database
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                port:
                  description: the port of the pgvector database
                  type: integer
                  default: 5432
                ssl:
                  description: whether to use ssl for the pgvector database
                  type: boolean
                  default: false
                ssl_cert:
                  description: the path of ssl cert to use for the pgvector database
                  type: string
                ssl_cert_key:
                  description: the path of ssl cert key to use for the pgvector database
                  type: string
                ssl_required:
                  description: whether ssl is required for the pgvector database
                  type: boolean
                  default: false
                ssl_verify:
                  description: whether to verify ssl for the pgvector database
                  type: boolean
                  default: true
                ssl_version:
                  description: the ssl version to use for the pgvector database
                  type: string
                  default: tlsv1_2
                  enum:
                  - any
                  - tlsv1_2
                  - tlsv1_3
                  x-speakeasy-unknown-values: allow
                timeout:
                  description: the timeout of the pgvector database
                  type: number
                  default: 5000
                user:
                  description: the user of the pgvector database
                  type: string
                  default: postgres
                  x-referenceable: true
            redis:
              type: object
              properties:
                cloud_authentication:
                  description: Cloud auth related configs for connecting to a Cloud Provider's Redis instance.
                  type: object
                  properties:
                    auth_provider:
                      description: Auth providers to be used to authenticate to a Cloud Provider's Redis instance.
                      type: string
                      enum:
                      - aws
                      - azure
                      - gcp
                      x-referenceable: true
                      x-speakeasy-unknown-values: allow
                    aws_access_key_id:
                      description: AWS Access Key ID to be used for authentication when `auth_provider` is set to `aws`.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    aws_assume_role_arn:
                      description: The ARN of the IAM role to assume for generating ElastiCache IAM authentication tokens.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    aws_cache_name:
                      description: The name of the AWS Elasticache cluster when `auth_provider` is set to `aws`.
                      type: string
                      x-referenceable: true
                    aws_is_serverless:
                      description: This flag specifies whether the cluster is serverless when auth_provider is set to `aws`.
                      type: boolean
                      default: true
                    aws_region:
                      description: The region of the AWS ElastiCache cluster when `auth_provider` is set to `aws`.
                      type: string
                      x-referenceable: true
                    aws_role_session_name:
                      description: The session name for the temporary credentials when assuming the IAM role.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    aws_secret_access_key:
                      description: AWS Secret Access Key to be used for authentication when `auth_provider` is set to `aws`.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    azure_client_id:
                      description: Azure Client ID to be used for authentication when `auth_provider` is set to `azure`.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    azure_client_secret:
                      description: Azure Client Secret to be used for authentication when `auth_provider` is set to `azure`.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    azure_tenant_id:
                      description: Azure Tenant ID to be used for authentication when `auth_provider` is set to `azure`.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                    gcp_service_account_json:
                      description: GCP Service Account JSON to be used for authentication when `auth_provider` is set to `gcp`.
                      type: string
                      x-encrypted: true
                      x-referenceable: true
                cluster_max_redirections:
                  description: Maximum retry attempts for redirection.
                  type: integer
                  default: 5
                cluster_nodes:
                  description: Cluster addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Cluster. The minimum length of the array is 1 element.
                  type: array
                  items:
                    properties:
                      ip:
                        description: A string representing a host name, such as example.com.
                        type: string
                        default: 127.0.0.1
                      port:
                        description: An integer representing a port number between 0 and 65535, inclusive.
                        type: integer
                        default: 6379
                        maximum: 65535
                        minimum: 0
                    type: object
                  minLength: 1
                connect_timeout:
                  description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2.
                  type: integer
                  default: 2000
                  maximum: 2147483646
                  minimum: 0
                connection_is_proxied:
                  description: If the connection to Redis is proxied (e.g. Envoy), set it `true`. Set the `host` and `port` to point to the proxy address.
                  type: boolean
                  default: false
                database:
                  description: Database to use for the Redis connection when using the `redis` strategy
                  type: integer
                  default: 0
                host:
                  description: A string representing a host name, such as example.com.
                  type: string
                  default: 127.0.0.1
                  x-referenceable: true
                keepalive_backlog:
                  description: Limits the total number of opened connections for a pool. If the connection pool is full, connection queues above the limit go into the backlog queue. If the backlog queue is full, subsequent connect operations fail and return `nil`. Queued operations (subject to set timeouts) resume once the number of connections in the pool is less than `keepalive_pool_size`. If latency is high or throughput is low, try increasing this value. Empirically, this value is larger than `keepalive_pool_size`.
                  type: integer
                  maximum: 2147483646
                  minimum: 0
                keepalive_pool_size:
                  description: The size limit for every cosocket connection pool associated with every remote server, per worker process. If neither `keepalive_pool_size` nor `keepalive_backlog` is specified, no pool is created. If `keepalive_pool_size` isn't specified but `keepalive_backlog` is specified, then the pool uses the default value. Try to increase (e.g. 512) this value if latency is high or throughput is low.
                  type: integer
                  default: 256
                  maximum: 2147483646
                  minimum: 1
                password:
                  description: Password to use for Redis connections. If undefined, no AUTH commands are sent to Redis.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                port:
                  description: An integer representing a port number between 0 and 65535, inclusive.
                  type: integer
                  default: 6379
                  maximum: 65535
                  minimum: 0
                  x-referenceable: true
                read_timeout:
                  description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2.
                  type: integer
                  default: 2000
                  maximum: 2147483646
                  minimum: 0
                send_timeout:
                  description: An integer representing a timeout in milliseconds. Must be between 0 and 2^31-2.
                  type: integer
                  default: 2000
                  maximum: 2147483646
                  minimum: 0
                sentinel_master:
                  description: Sentinel master to use for Redis connections. Defining this value implies using Redis Sentinel.
                  type: string
                sentinel_nodes:
                  description: Sentinel node addresses to use for Redis connections when the `redis` strategy is defined. Defining this field implies using a Redis Sentinel. The minimum length of the array is 1 element.
                  type: array
                  items:
                    properties:
                      host:
                        description: A string representing a host name, such as example.com.
                        type: string
                        default: 127.0.0.1
                      port:
                        description: An integer representing a port number between 0 and 65535, inclusive.
                        type: integer
                        default: 6379
                        maximum: 65535
                        minimum: 0
                    type: object
                  minLength: 1
                sentinel_password:
                  description: Sentinel password to authenticate with a Redis Sentinel instance. If undefined, no AUTH commands are sent to Redis Sentinels.
                  type: string
                  x-encrypted: true
                  x-referenceable: true
                sentinel_role:
                  description: Sentinel role to use for Redis connections when the `redis` strategy is defined. Defining this value implies using Redis Sentinel.
                  type: string
 

# --- truncated at 32 KB (133 KB total) ---
# Full source: https://raw.githubusercontent.com/api-evangelist/kong/refs/heads/main/openapi/kong-partials-api-openapi.yml