News KrakenD 3.0 Is Here: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation

Product Updates

4 min read

KrakenD CE v3.0 Released

by Albert Lombarte

KrakenD CE v3.0 is the first Community Edition release of Series 3. It makes JWT validation more flexible, adds the HTTP method to endpoint logs, and removes long-deprecated components, which leaves a leaner binary with far fewer dependencies. For the full picture of Series 3, read the KrakenD 3.0 announcement.

This is a major version, so check the breaking changes below before you upgrade.

Wildcards and Array Indexes in JWT Claims

JWT validation now reads roles, scopes, and propagated claims using a path syntax that supports wildcards (*) and array indexes. You can reach claims whose position in the token isn’t fixed, for instance, the roles of every client in a Keycloak token with resource_access.*.roles, without flattening the token first.

HTTP Method in Endpoint Logs

Endpoint logs now include the HTTP method of the request, so GET /foo and POST /foo are no longer indistinguishable in your logs. This release also fixes the Logstash formatter, which removed the prefix of log lines coming from some components.

A Leaner Binary

Removing plugins, OpenCensus, and InfluxDB takes dozens of dependencies out of the binary. Fewer dependencies mean a smaller attack surface and fewer security advisories to track in your scans. It also upgrades gRPC, the OpenTelemetry exporters, and the compression library to versions that fix known CVEs.

In addition, krakend audit now takes the HTTP circuit breaker into account when evaluating rule 3.1.3.

Breaking Changes

The following changes can prevent an existing configuration from working after the upgrade. Review each one, and then run your configuration through the upgrade guide.

Configuration Version 4

KrakenD 3.0 reads a new syntax version of the configuration file. Every configuration must declare "version": 4, instead of the "version": 3 used by all 2.x releases. KrakenD refuses to start with the old value and logs unsupported version: 3 (want: 4):

 {
   "$schema": "https://www.krakend.io/schema/krakend.json",
-  "version": 3,
+  "version": 4,
   "endpoints": []
 }

Remember to update every file that declares the version, including the templates and settings of flexible configuration.

Plugins Moved to Enterprise Edition

KrakenD CE no longer loads plugins, and the krakend check-plugin and krakend test-plugin commands are gone. If your gateway depends on plugins, read Dropping plugin support in KrakenD Open Source and Lura for the reasoning and the options, or talk to us about your migration path.

OpenCensus Removed

The OpenCensus integration (telemetry/opencensus) has been frozen for years in favor of OpenTelemetry, and v3.0 removes it along with all of its exporters: Datadog, InfluxDB, Jaeger, OC Agent, Prometheus, Stackdriver, X-Ray, and Zipkin. Move to OpenTelemetry, which all of these systems support.

InfluxDB Component Removed

The native InfluxDB exporter (telemetry/influx) is also gone. Send your metrics through OpenTelemetry instead.

Legacy Namespaces No Longer Accepted

KrakenD 2.0 renamed the old repository-style namespaces, such as github_com/devopsfaith/krakend-gologging, to short names like telemetry/logging, but kept accepting the old ones as aliases. KrakenD CE v3.0 drops those aliases. KrakenD no longer recognizes a component declared under an old namespace, so the component stops working, even though the gateway still starts. Replace them with their current names:

 "extra_config": {
-  "github_com/devopsfaith/krakend-gologging": {
+  "telemetry/logging": {
     "level": "ERROR"
   }
 }

🚀 Summary of changes for CEv3.0

The first release of Series 3 brings wildcard JWT claim paths, the HTTP method in endpoint logs, a leaner binary, and the removal of deprecated components.

  • JWT validation accepts wildcards and array indexes in the paths of roles, scopes, and propagated claims.
  • Endpoint logs include the HTTP method of the request.
  • The audit command takes the HTTP circuit breaker into account in rule 3.1.3.
  • Removing deprecated components takes dozens of dependencies out of the binary, reducing the attack surface.
  • Lura and the KrakenD components moved to new major module paths (e.g., github.com/luraproject/lura/v3), and NewHTTPProxyWithHTTPExecutor can now be overridden. Custom builds must update their imports.
  • Fixed the Logstash formatter removing the prefix of log lines coming from external components.
  • All previous configurations used version: 3. Migrate your configuration and use version: 4 instead.
  • Plugins are no longer supported in the Community Edition, and the check-plugin and test-plugin commands are gone. See Dropping plugin support in KrakenD Open Source and Lura.
  • Removed OpenCensus (telemetry/opencensus) and all its exporters. Use OpenTelemetry instead.
  • Removed the InfluxDB component (telemetry/influx). Use OpenTelemetry instead.
  • Legacy repository-style namespaces (e.g., github_com/devopsfaith/krakend-gologging) are no longer accepted. Use their current names (e.g., telemetry/logging).
  • Removed Telemetry Port (telemetry/metrics). KrakenD could listen to an alternative port for metrics, but this is no longer supported.

Upgrading to the latest version is always advised.

Happy gatewaying! 🐙

Categories: Product Updates

Stay up to date with KrakenD releases and important updates