openapi: 3.1.0 info: title: Kuma Dataplane MeshProxyPatch API description: Kuma API version: v1alpha1 x-ref-schema-name: DataplaneOverview security: - BasicAuth: [] - BearerAuth: [] - {} tags: - name: MeshProxyPatch paths: /meshes/{mesh}/meshproxypatches/{name}: get: operationId: getMeshProxyPatch summary: Returns MeshProxyPatch entity tags: - MeshProxyPatch parameters: - in: path name: mesh schema: type: string required: true description: name of the mesh - in: path name: name schema: type: string required: true description: name of the MeshProxyPatch responses: '200': $ref: '#/components/responses/MeshProxyPatchItem' '404': $ref: '#/components/responses/NotFound' put: operationId: putMeshProxyPatch summary: Creates or Updates MeshProxyPatch entity tags: - MeshProxyPatch parameters: - in: path name: mesh schema: type: string required: true description: name of the mesh - in: path name: name schema: type: string required: true description: name of the MeshProxyPatch requestBody: description: Put request required: true content: application/json: schema: $ref: '#/components/schemas/MeshProxyPatchItem' responses: '200': $ref: '#/components/responses/MeshProxyPatchCreateOrUpdateSuccessResponse' '201': $ref: '#/components/responses/MeshProxyPatchCreateOrUpdateSuccessResponse' delete: operationId: deleteMeshProxyPatch summary: Deletes MeshProxyPatch entity tags: - MeshProxyPatch parameters: - in: path name: mesh schema: type: string required: true description: name of the mesh - in: path name: name schema: type: string required: true description: name of the MeshProxyPatch responses: '200': $ref: '#/components/responses/MeshProxyPatchDeleteSuccessResponse' '404': $ref: '#/components/responses/NotFound' /meshes/{mesh}/meshproxypatches: get: operationId: getMeshProxyPatchList summary: Returns a list of MeshProxyPatch in the mesh. tags: - MeshProxyPatch parameters: - in: query name: offset description: offset in the list of entities required: false schema: type: integer example: 0 - in: query name: size description: the number of items per page required: false schema: type: integer default: 100 maximum: 1000 minimum: 1 - in: query name: filter description: filter by labels when multiple filters are present, they are ANDed required: false schema: type: object properties: key: type: string value: type: string example: label.k8s.kuma.io/namespace: my-ns - in: path name: mesh schema: type: string required: true description: name of the mesh responses: '200': $ref: '#/components/responses/MeshProxyPatchList' components: responses: NotFound: description: Not Found content: application/problem+json: schema: $ref: '#/components/schemas/NotFoundError' MeshProxyPatchDeleteSuccessResponse: description: Successful response content: application/json: schema: type: object MeshProxyPatchCreateOrUpdateSuccessResponse: description: Successful response content: application/json: schema: type: object properties: warnings: type: array readOnly: true description: 'warnings is a list of warning messages to return to the requesting Kuma API clients. Warning messages describe a problem the client making the API request should correct or be aware of. ' items: type: string MeshProxyPatchItem: description: Successful response content: application/json: schema: $ref: '#/components/schemas/MeshProxyPatchItem' MeshProxyPatchList: description: List content: application/json: schema: type: object properties: items: type: array items: $ref: '#/components/schemas/MeshProxyPatchItem' total: type: number description: The total number of entities next: type: string description: URL to the next page schemas: MeshProxyPatchItem: type: object description: MeshProxyPatch provides advanced customization of the Envoy proxy configuration generated by Kuma. It allows you to add, remove, or modify Envoy resources (clusters, listeners, filters, virtual hosts) using YAML patches or JSON patches for fine-grained control beyond standard policies. required: - type - name - spec properties: type: description: the type of the resource type: string enum: - MeshProxyPatch mesh: description: Mesh is the name of the Kuma mesh this resource belongs to. It may be omitted for cluster-scoped resources. type: string default: default kri: description: A unique identifier for this resource instance used by internal tooling and integrations. Typically derived from resource attributes and may be used for cross-references or indexing type: string readOnly: true example: kri_mpp_default_zone-east_kuma-demo_mypolicy1_ name: description: Name of the Kuma resource type: string labels: additionalProperties: type: string description: The labels to help identity resources type: object spec: description: Spec is the specification of the Kuma MeshProxyPatch resource. properties: default: description: 'Default is a configuration specific to the group of destinations referenced in ''targetRef''.' properties: appendModifications: description: AppendModifications is a list of modifications applied on the selected proxy. items: properties: cluster: description: Cluster is a modification of Envoy's Cluster resource. properties: jsonPatches: description: 'JsonPatches specifies list of jsonpatches to apply to on Envoy''s Cluster resource' items: description: JsonPatchBlock is one json patch operation block. properties: from: description: From is a jsonpatch from string, used by move and copy operations. type: string op: description: Op is a jsonpatch operation string. enum: - add - remove - replace - move - copy type: string path: description: Path is a jsonpatch path string. type: string value: description: Value must be a valid json value used by replace and add operations. x-kubernetes-preserve-unknown-fields: true required: - op - path type: object type: array match: description: Match is a set of conditions that have to be matched for modification operation to happen. properties: name: description: Name of the cluster to match. type: string origin: description: 'Origin is the name of the component or plugin that generated the resource. Here is the list of well-known origins: inbound - resources generated for handling incoming traffic. outbound - resources generated for handling outgoing traffic. transparent - resources generated for transparent proxy functionality. prometheus - resources generated when Prometheus metrics are enabled. direct-access - resources generated for Direct Access functionality. ingress - resources generated for Zone Ingress. egress - resources generated for Zone Egress. gateway - resources generated for MeshGateway. The list is not complete, because policy plugins can introduce new resources. For example MeshTrace plugin can create Cluster with "mesh-trace" origin.' type: string type: object operation: description: Operation to execute on matched cluster. enum: - Add - Remove - Patch type: string value: description: Value of xDS resource in YAML format to add or patch. type: string required: - operation type: object httpFilter: description: 'HTTPFilter is a modification of Envoy HTTP Filter available in HTTP Connection Manager in a Listener resource.' properties: jsonPatches: description: 'JsonPatches specifies list of jsonpatches to apply to on Envoy''s HTTP Filter available in HTTP Connection Manager in a Listener resource.' items: description: JsonPatchBlock is one json patch operation block. properties: from: description: From is a jsonpatch from string, used by move and copy operations. type: string op: description: Op is a jsonpatch operation string. enum: - add - remove - replace - move - copy type: string path: description: Path is a jsonpatch path string. type: string value: description: Value must be a valid json value used by replace and add operations. x-kubernetes-preserve-unknown-fields: true required: - op - path type: object type: array match: description: Match is a set of conditions that have to be matched for modification operation to happen. properties: listenerName: description: Name of the listener to match. type: string listenerTags: additionalProperties: type: string description: Listener tags available in Listener#Metadata#FilterMetadata[io.kuma.tags] type: object name: description: Name of the HTTP filter. For example "envoy.filters.http.local_ratelimit" type: string origin: description: 'Origin is the name of the component or plugin that generated the resource. Here is the list of well-known origins: inbound - resources generated for handling incoming traffic. outbound - resources generated for handling outgoing traffic. transparent - resources generated for transparent proxy functionality. prometheus - resources generated when Prometheus metrics are enabled. direct-access - resources generated for Direct Access functionality. ingress - resources generated for Zone Ingress. egress - resources generated for Zone Egress. gateway - resources generated for MeshGateway. The list is not complete, because policy plugins can introduce new resources. For example MeshTrace plugin can create Cluster with "mesh-trace" origin.' type: string type: object operation: description: Operation to execute on matched listener. enum: - Remove - Patch - AddFirst - AddBefore - AddAfter - AddLast type: string value: description: Value of xDS resource in YAML format to add or patch. type: string required: - operation type: object listener: description: Listener is a modification of Envoy's Listener resource. properties: jsonPatches: description: 'JsonPatches specifies list of jsonpatches to apply to on Envoy''s Listener resource' items: description: JsonPatchBlock is one json patch operation block. properties: from: description: From is a jsonpatch from string, used by move and copy operations. type: string op: description: Op is a jsonpatch operation string. enum: - add - remove - replace - move - copy type: string path: description: Path is a jsonpatch path string. type: string value: description: Value must be a valid json value used by replace and add operations. x-kubernetes-preserve-unknown-fields: true required: - op - path type: object type: array match: description: Match is a set of conditions that have to be matched for modification operation to happen. properties: name: description: Name of the listener to match. type: string origin: description: 'Origin is the name of the component or plugin that generated the resource. Here is the list of well-known origins: inbound - resources generated for handling incoming traffic. outbound - resources generated for handling outgoing traffic. transparent - resources generated for transparent proxy functionality. prometheus - resources generated when Prometheus metrics are enabled. direct-access - resources generated for Direct Access functionality. ingress - resources generated for Zone Ingress. egress - resources generated for Zone Egress. gateway - resources generated for MeshGateway. The list is not complete, because policy plugins can introduce new resources. For example MeshTrace plugin can create Cluster with "mesh-trace" origin.' type: string tags: additionalProperties: type: string description: Tags available in Listener#Metadata#FilterMetadata[io.kuma.tags] type: object type: object operation: description: Operation to execute on matched listener. enum: - Add - Remove - Patch type: string value: description: Value of xDS resource in YAML format to add or patch. type: string required: - operation type: object networkFilter: description: NetworkFilter is a modification of Envoy Listener's filter. properties: jsonPatches: description: 'JsonPatches specifies list of jsonpatches to apply to on Envoy Listener''s filter.' items: description: JsonPatchBlock is one json patch operation block. properties: from: description: From is a jsonpatch from string, used by move and copy operations. type: string op: description: Op is a jsonpatch operation string. enum: - add - remove - replace - move - copy type: string path: description: Path is a jsonpatch path string. type: string value: description: Value must be a valid json value used by replace and add operations. x-kubernetes-preserve-unknown-fields: true required: - op - path type: object type: array match: description: Match is a set of conditions that have to be matched for modification operation to happen. properties: listenerName: description: Name of the listener to match. type: string listenerTags: additionalProperties: type: string description: Listener tags available in Listener#Metadata#FilterMetadata[io.kuma.tags] type: object name: description: Name of the network filter. For example "envoy.filters.network.ratelimit" type: string origin: description: 'Origin is the name of the component or plugin that generated the resource. Here is the list of well-known origins: inbound - resources generated for handling incoming traffic. outbound - resources generated for handling outgoing traffic. transparent - resources generated for transparent proxy functionality. prometheus - resources generated when Prometheus metrics are enabled. direct-access - resources generated for Direct Access functionality. ingress - resources generated for Zone Ingress. egress - resources generated for Zone Egress. gateway - resources generated for MeshGateway. The list is not complete, because policy plugins can introduce new resources. For example MeshTrace plugin can create Cluster with "mesh-trace" origin.' type: string type: object operation: description: Operation to execute on matched listener. enum: - Remove - Patch - AddFirst - AddBefore - AddAfter - AddLast type: string value: description: Value of xDS resource in YAML format to add or patch. type: string required: - operation type: object virtualHost: description: 'VirtualHost is a modification of Envoy''s VirtualHost referenced in HTTP Connection Manager in a Listener resource.' properties: jsonPatches: description: 'JsonPatches specifies list of jsonpatches to apply to on Envoy''s VirtualHost resource' items: description: JsonPatchBlock is one json patch operation block. properties: from: description: From is a jsonpatch from string, used by move and copy operations. type: string op: description: Op is a jsonpatch operation string. enum: - add - remove - replace - move - copy type: string path: description: Path is a jsonpatch path string. type: string value: description: Value must be a valid json value used by replace and add operations. x-kubernetes-preserve-unknown-fields: true required: - op - path type: object type: array match: description: Match is a set of conditions that have to be matched for modification operation to happen. properties: name: description: Name of the VirtualHost to match. type: string origin: description: 'Origin is the name of the component or plugin that generated the resource. Here is the list of well-known origins: inbound - resources generated for handling incoming traffic. outbound - resources generated for handling outgoing traffic. transparent - resources generated for transparent proxy functionality. prometheus - resources generated when Prometheus metrics are enabled. direct-access - resources generated for Direct Access functionality. ingress - resources generated for Zone Ingress. egress - resources generated for Zone Egress. gateway - resources generated for MeshGateway. The list is not complete, because policy plugins can introduce new resources. For example MeshTrace plugin can create Cluster with "mesh-trace" origin.' type: string routeConfigurationName: description: Name of the RouteConfiguration resource to match. type: string type: object operation: description: Operation to execute on matched listener. enum: - Add - Remove - Patch type: string value: description: Value of xDS resource in YAML format to add or patch. type: string required: - match - operation type: object type: object type: array type: object targetRef: description: 'TargetRef is a reference to the resource the policy takes an effect on. The resource could be either a real store object or virtual resource defined inplace.' properties: kind: description: Kind of the referenced resource enum: - Mesh - MeshSubset - MeshGateway - MeshService - MeshExternalService - MeshMultiZoneService - MeshServiceSubset - MeshHTTPRoute - Dataplane type: string labels: additionalProperties: type: string description: 'Labels are used to select group of MeshServices that match labels. Either Labels or Name and Namespace can be used.' type: object mesh: description: Mesh is reserved for future use to identify cross mesh resources. type: string name: description: 'Name of the referenced resource. Can only be used with kinds: `MeshService`, `MeshServiceSubset` and `MeshGatewayRoute`' type: string namespace: description: 'Namespace specifies the namespace of target resource. If empty only resources in policy namespace will be targeted.' type: string proxyTypes: description: 'ProxyTypes specifies the data plane types that are subject to the policy. When not specified, all data plane types are targeted by the policy.' items: enum: - Sidecar - Gateway type: string type: array sectionName: description: 'SectionName is used to target specific section of resource. For example, you can target port from MeshService.ports[] by its name. Only traffic to this port will be affected.' type: string tags: additionalProperties: type: string description: 'Tags used to select a subset of proxies by tags. Can only be used with kinds `MeshSubset` and `MeshServiceSubset`' type: object required: - kind type: object required: - default type: object creationTime: readOnly: true type: string description: Time at which the resource was created format: date-time example: '0001-01-01T00:00:00Z' modificationTime: readOnly: true type: string description: Time at which the resource was updated format: date-time example: '0001-01-01T00:00:00Z' NotFoundError: allOf: - $ref: '#/components/schemas/Error' - type: object properties: status: type: integer enum: - 404 example: 404 description: 'The HTTP status code for NotFoundError MUST be 404. ' title: type: string example: Not Found type: type: string example: https://httpstatuses.com/404 detail: type: string example: The requested resource was not found InvalidParameters: type: object title: Invalid Parameters required: - field - reason - source properties: field: type: string description: The name of the field that caused the error. reason: type: string description: 'A short, human-readable description of the problem. _Should_ be provided as "Sentence case" for direct use in a UI. ' rule: type: string description: 'May be provided as a hint to the user to help understand the type of failure. Additional guidance may be provided in additional fields, i.e. `choices`. ' choices: type: array description: 'Optional field to provide a list of valid choices for the field that caused the error. ' items: type: string source: type: string description: 'The location of the field that caused the error. ' enum: - body - query - header - path Error: type: object title: Error description: 'Standard error. Follows the [AIP #193 - Errors](https://kong-aip.netlify.app/aip/193/) specification. ' x-examples: Example 1: status: 404 title: Not Found type: https://kongapi.info/konnect/not-found instance: portal:trace:2287285207635123011 detail: The requested document was not found required: - status - title - instance - type - detail properties: status: type: integer description: The HTTP status code. example: 404 title: type: string description: 'A short, human-readable summary of the problem. It **should not** change between occurrences of a problem, except for localization. Should be provided as "Sentence case" for potential direct use in a UI ' example: Not Found type: type: string description: 'A unique identifier for this error. When dereferenced it must provide human-readable documentation for the problem. ' example: Not Found instance: type: string example: portal:trace:2287285207635123011 description: 'Used to return the correlation ID back to the user, in the format `:trace:`. ' detail: type: string example: The requested team was not found description: 'A human readable explanation specific to this occurrence of the problem. This field may contain request/entity data to help the user understand what went wrong. Enclose variable values in square brackets. _Should_ be provided as "Sentence case" for direct use in a UI ' invalid_parameters: type: array description: 'All 400 errors **MUST** return an `invalid_parameters` key in the response. Used to indicate which fields have invalid values when validated. ' items: $ref: '#/components/schemas/InvalidParameters' securitySchemes: BasicAuth: type: http scheme: basic BearerAuth: type: http scheme: bearer