Kong API Gateway 3.16 has been out for a few weeks now, and it appears that Deck currently doesn't support the new Expressions feature for plugins that allow you to do dynamic overrides, such as in the Rate Limit Advanced plugin, which I will use for my reproduction example:
Environment:
Kong Cloud Api Gateway v3.16.0.0 dataplane
Latest Konnect UI/management API as of today
Deck v1.68.0 (latest as of today)
When viewing a Rate Limit Advanced plugin in Konnect, clicking View Configuration on the Deck tab shows Konnect believes Deck supports configuring Expressions

Error: 1 errors occurred:
reading file pluginDynamicExpressionsTestv1.68.0.json: validating file content: 1 errors occurred:
validation error: object={"custom_key":null,"limit":["5*10"]}, err=plugins.0: Additional property expressions is not allowed
{
"_format_version": "3.0",
"_info": {
"select_tags": [
"wgunnDeckExpressionsTest"
],
"defaults": {}
},
"_konnect": {
"control_plane_name": "dev"
},
"plugins": [
{
"name": "rate-limiting-advanced",
"instance_name": "test-rate-limit-expression-deck",
"config": {
"compound_identifier": null,
"consumer_groups": null,
"counter_key": null,
"custom_key": null,
"dictionary_name": "kong_rate_limiting_counters",
"disable_penalty": false,
"enforce_consumer_groups": false,
"error_code": 429,
"error_message": "API rate limit exceeded",
"header_name": null,
"hide_client_headers": false,
"identifier": "consumer",
"limit": [
5
],
"lock_dictionary_name": "kong_locks",
"namespace": "zqNbte6xs9IR5GrdN3Q2z3BAzRDXWYqQ",
"path": null,
"redis": {
"cloud_authentication": null,
"cluster_addresses": null,
"cluster_max_redirections": 5,
"cluster_nodes": null,
"connect_timeout": 2000,
"connection_is_proxied": false,
"database": 0,
"host": "127.0.0.1",
"keepalive_backlog": null,
"keepalive_pool_size": 256,
"password": null,
"port": 6379,
"read_timeout": 2000,
"redis_proxy_type": null,
"send_timeout": 2000,
"sentinel_addresses": null,
"sentinel_master": null,
"sentinel_nodes": null,
"sentinel_password": null,
"sentinel_role": null,
"sentinel_username": null,
"server_name": null,
"ssl": false,
"ssl_verify": false,
"timeout": 2000,
"username": null
},
"retry_after_jitter_max": 0,
"strategy": "local",
"sync_rate": null,
"throttling": null,
"window_size": [
300
],
"window_type": "fixed"
},
"enabled": true,
"expressions": {
"custom_key": null,
"limit": [
"5*10"
]
},
"protocols": [
"http",
"https"
],
"tags": [
"wgunnDeckExpressionsTest"
]
}
]
}
As the dump command is silently stripping away the expressions properties, doing a round trip deck gateway dump -> deck gateway sync is not idempotent and silently removes all plugin expressions that were configured in Konnect via other means (the UI in our case).
Kong API Gateway 3.16 has been out for a few weeks now, and it appears that Deck currently doesn't support the new Expressions feature for plugins that allow you to do dynamic overrides, such as in the Rate Limit Advanced plugin, which I will use for my reproduction example:
Environment:
Kong Cloud Api Gateway v3.16.0.0 dataplane
Latest Konnect UI/management API as of today
Deck v1.68.0 (latest as of today)
When viewing a Rate Limit Advanced plugin in Konnect, clicking View Configuration on the Deck tab shows Konnect believes Deck supports configuring Expressions

deck gateway sync/diff Expectation:
Running a sync command with a v3.16 plugin that has a Dynamic Expression (e.g. https://developer.konghq.com/plugins/rate-limiting-advanced/examples/rate-limit-by-principal-metadata/ ) successfully uploads a plugin with the specific limit override expression
Actual behavior:
Running
deck gateway <sync|diff>with an input file that has a plugin with an expression property returns an error sayingReproduction file:
pluginDynamicExpressionsTestv1.68.0.json
As the dump command is silently stripping away the expressions properties, doing a round trip
deck gateway dump->deck gateway syncis not idempotent and silently removes all plugin expressions that were configured in Konnect via other means (the UI in our case).