Layer7 API Security

 View Only

Layer7 Work in Progress Update - PI34

By Gregory Thompson posted Aug 04, 2023 01:49 PM

  

PI Planning for PI34 is now complete and development has kicked off. Below you will find the list of items that are included in this PI and a summary of the releases completed in the previous PI. As always, we invite you to provide feedback by commenting on this post below. We would love feedback on both the current and future PI items to help us prioritize the items that will have the most benefit for our customers.

 

Recent Releases:

The following product versions were released during PI33:

• API Portal 5.2.1 - Release Notes


PI34 Key Capabilities

 

The sections below provide a listing of the key capabilities being worked on across the Layer7 family of products. Note that some capabilities will span multiple PIs. 

 

API Gateway:

  • Gateway 11.0 CR1 Release Activities
  • Hardware image for Gateway 11.0 Release
  • New container gateway base image (RHEL UBI 9 from IronBank)
  • Add Swagger 2.0 support to OpenAPI validation assertion
  • Best effort support for gateway database in Percona XtraDB Clusters (PXC)
  • Best effort support for gateway database with group replication in MySQL Enterprise 
  • Certifying Software Gateway on RHEL9
  • Support entity mapping in Graphman
  • Common Criteria Evaluation Completion
  • Customize Tomcat to optionally add response reason phrase
  • Improve gateway URI resolution performance
  • Productize listener poller thread count fix
  • Add support for Radius and Radius+LDAP for SSH back to GW11
  • Back port Progress drivers replacement from 11.0 to 10.1
  • [JDK17] Java 17 ready develop branch (keep Java 11)
  • [JDK17] L7Platform support for JDK 17
  • [JDK17] Upgrade Javascript assertion to use standalone Nashorn engine
  • [Preview] Distributed Rate Limit with Redis
  • [Preview Prep] Operator productization
  • [Preview Prep] Cloud native auditing, logging, tracing, metrics for alerting, monitoring and analytics framework(s)
  • [Experimental] Provide experimental support for missing capabilities of new WebSocket preview feature
  • [Experimental] Demonstrate solution for singleton resources without a gateway database
  • [Experimental] External stored password management (policy driven)
  • [Experimental] External stored password management (operator driven)
  • [Experimental] Enhanced Throughput Quota Assertion for Redis using CRDT

 

OAuth Toolkit:

  • OTK Container Installation Improvements
  • Enhance Token Deletion to Allow for High Priority Tokens
  • OTK - Provide SMSession Authentication Support
  • OTK 4.6.2 Release Activities


Mobile SDK:

  • Android Push Notification Firebase Replacement
  • SDK - Android 14 Support
  • SDK - iOS 17 Support
  • SDK 2.4 Release Activities Part 1


API Portal:

  • Portal: Debian OVA (continued)
  • [Experimental] Decouple OTK from Portal (continued)
  • Allow Org Admin to pre-register Users within their Auth Scheme (continued)
  • [Spike] Portal Integration with Layer7 Operator
  • Bulk Deployment Improvements
  • Provide ability to configure DB Pool
  • Template Management Improvements
  • Support the ability to disable portal application sync
  • Upgrade to Java 17
  • Upgrade Ingress and PSSG to GW11
  • Portal container platform update
  • Portal: Major Release Activities: v5.2.2
  • Secret field support for API Templates

 

Note that some larger capabilities may span multiple PIs and, as always, plans are subject to change based on a number of different factors.

 

Candidates for PI35 and Beyond

While the capabilities to be included in the next PI are not yet set, please see below for a list of candidates being considered. Of course, not all of these will fit and we will select a subset of these based on your feedback. We'd love to know if there is a capability in the list you are eagerly awaiting and/or plan to use. We also would love to know if there is something missing from the list that is important to you. Please comment in the comments section below with your feedback.

 

API Gateway:

  • Gateway 10.1 CR4  Release
  • Gateway 11.0 CR2 Release
  • JDK17 upgrade
  • Debian 12 upgrade
  • Digital signing of gateway artifacts
  • Graphman entity mapping
  • SNI support for HTTPS in Gateway
  • Inbound HTTP and HTTP/2 port sharing in Tomcat
  • Dynamic private key management via Graphman using PEM
  • Container Gateway Optimizations (Size, Speed, Security, +)
  • [Preview] gRPC support in Gateway
  • [Preview] New WebSockets (Complete)
  • [Preview] Layer7 Operator
  • [Preview] Cloud native auditing, logging, tracing, metrics for alerting, monitoring and analytics framework(s)
  • [Preview] Distributed Throughput Quota with Redis
  • [Experimental] External private key management (policy driven)
  • [Experimental] External private key management (operator driven)

 

OAuth Toolkit:

  • FAPI 1.0 RAR Support
  • FAPI 2.0 Support
  • Customization for Token Deletion Policy
  • Optimization for large scope processing

 

Mobile SDK:

  • iOS 18 
  • Android 15

 

API Portal:

  • Rate Limits & Quotas for API per Application
  • Open API Catalog
  • mTLS support for Client Applications
  • Graphman Bundle Support
  • Support for central API Key Repo
  • Support for multiple backend routing locations based on API Proxy (gateway cluster)
  • Support for ephemeral gateways
  • Custom-defined user roles

 

0 comments
47 views

Permalink