Layer7 API Security

 View Only

Layer7 Work in Progress Update - PI33

By Gregory Thompson posted Apr 24, 2023 10:24 AM

  
PI Planning for PI33 is now complete and development has kicked off. Below you will find the list of items that are included in this PI and a summary of the releases completed in the previous PI. As always, we invite you to provide feedback by commenting on this post below. We would love feedback on both the current and future PI items in order to help us prioritize the items that will have the most benefit for our customers.
 
Recent Releases:
The following product versions were released during PI32:
• API Gateway 11.0 - Release Notes
• API Gateway 10.1 CR3 - Release Notes
• API Portal 5.2 - Release Notes
• OAuth Toolkit (OTK) 4.6.1 - Release Notes

PI33 Key Capabilities
 
The sections below provide a listing of the key capabilities being worked on across the Layer7 family of products. Note that some capabilities will span multiple PIs. 
 
API Gateway:
• [Limited Availability] Forward port Graphman to 11 CR1
• [Limited Availability] Gateway Read Environment Variables
• [Limited Availability] GraphQL Assertions
• [Preview] Distributed rate limiting
• [Preview] Redis as alternative to external Hazelcast
• Enhanced OpenAPI 3.0 request validation
• Support Kafka Consumers in Gateway
• Hardware image for V11
• Update container gateway platform support documentation [OpenShift]
• Best effort support for gateway database with group replication in MySQL Enterprise
• Best effort support for gateway database in Percona XtraDB Clusters (PXC)
• Best effort support for gateway database in MariaDB with Galera clusters
• Debian Gateway Patch Manager Enhancements
• Address Graphman/Policy Manager config gaps
• Inbound HTTP and HTTP/2 port sharing in Tomcat (Part 1)
• Continuing common criteria evaluation
• MySQL backed gateway cluster scalability benchmarks
• [Experimental] Distributed throughput quota enforcement
• [Experimental] External static secret/key/cert management framework
• [Experimental] External dynamic secret/key/cert management framework
• [Experimental] PEM formatted PKI support
• [Experimental] Pre-built dashboards for monitoring and analytics
• [Experimental] Policy as code
 
OAuth Toolkit:
• Solution Kit install without Requiring GW restart
• Redirect URI handling of special characters
• Support for DB connections for read only replicas
• Support for Cassandra 4
• Improve customization for OTK: Client JWT Validation routing (needs proxy)
• Support of Common Cloud MySQL Platforms

Mobile SDK:
• Early Validation of Android 14 Beta

API Portal:
• Bulk rejection of unwanted registration requests
• Optimization of Policy Template logic
• API Secret Expiration
• Support for Name Change for Gateway Published APIs
• Portal JDBC Driver Updates
• UI: Application API Tab updates for save/publish consistency
• [Experimental] Decouple OTK from Portal Part 1
• Portal Health Check Endpoint
• Organization Level RL&Q Support for Spread Window and Max Concurrency
• Portal: Debian OVA
• Portal: Major Release Activities: v5.2.1
• Allow Org Admin to pre-register Users within their Auth Scheme
• Portal 5.2.2 Helm Chart Improvements
• UI: Update React Scripts and Node Version

Note that some larger capabilities may span multiple PIs and, as always, plans are subject to change based on a number of different factors.
 
Candidates for PI34
While the capabilities to be included in the next PI are not yet set, please see below for a list of candidates being considered. Of course, not all of these will fit and we will select a subset of these based on your feedback. We'd love to know if there is a capability in the list you are eagerly awaiting and/or plan to use. We also would love to know if there is something missing from the list that is important to you. Please comment in the comments section below with your feedback.
 
API Gateway:
• New container gateway base image
• Certification of RHEL9 (and possibly Rocky Linux and/or AlmaLinux) for Software Gateway
• Graphman entity mapping enhancement
• SNI support for HTTPS in Gateway
• Inbound HTTP and HTTP/2 port sharing in Tomcat (Part 2)
• [Preview] gRPC support in Gateway
• Radius and Radius+LDAP for SSH support GW11
• Gateway URI resolution performance improvements
• [Preview] Complete WebSocket support over shared HTTP ports
• JDK 17 (Part 1)

OAuth Toolkit:
• FAPI 1.0 RAR Support
• FAPI 2.0 Support
• Customization for Token Deletion Policy
• Optimization for large scope processing

Mobile SDK:
• iOS 17
• Android 14

API Portal:
• Rate Limits & Quotas for API per Application
• Policy Template Management
• Bulk Deployment Improvements
• Open API Catalogue
• mTLS support for Client Applications
• Graphman Bundle Support
0 comments
71 views

Permalink