Skip to content

Deck 1.68.0 does not support plugin expressions such as Rate Limit Advanced limit override #2279

Description

@wgunn-em

Kong API Gateway 3.16 has been out for a few weeks now, and it appears that Deck currently doesn't support the new Expressions feature for plugins that allow you to do dynamic overrides, such as in the Rate Limit Advanced plugin, which I will use for my reproduction example:
Environment:
Kong Cloud Api Gateway v3.16.0.0 dataplane
Latest Konnect UI/management API as of today
Deck v1.68.0 (latest as of today)

When viewing a Rate Limit Advanced plugin in Konnect, clicking View Configuration on the Deck tab shows Konnect believes Deck supports configuring Expressions
Image

deck gateway sync/diff Expectation:

Running a sync command with a v3.16 plugin that has a Dynamic Expression (e.g. https://developer.konghq.com/plugins/rate-limiting-advanced/examples/rate-limit-by-principal-metadata/ ) successfully uploads a plugin with the specific limit override expression

Actual behavior:

Running deck gateway <sync|diff> with an input file that has a plugin with an expression property returns an error saying

Error: 1 errors occurred:
        reading file pluginDynamicExpressionsTestv1.68.0.json: validating file content: 1 errors occurred:
        validation error: object={"custom_key":null,"limit":["5*10"]}, err=plugins.0: Additional property expressions is not allowed

Reproduction file:
pluginDynamicExpressionsTestv1.68.0.json

{
  "_format_version": "3.0",
  "_info": {
    "select_tags": [
      "wgunnDeckExpressionsTest"
    ],
    "defaults": {}
  },
  "_konnect": {
    "control_plane_name": "dev"
  },
  "plugins": [
    {
      "name": "rate-limiting-advanced",
      "instance_name": "test-rate-limit-expression-deck",
      "config": {
        "compound_identifier": null,
        "consumer_groups": null,
        "counter_key": null,
        "custom_key": null,
        "dictionary_name": "kong_rate_limiting_counters",
        "disable_penalty": false,
        "enforce_consumer_groups": false,
        "error_code": 429,
        "error_message": "API rate limit exceeded",
        "header_name": null,
        "hide_client_headers": false,
        "identifier": "consumer",
        "limit": [
          5
        ],
        "lock_dictionary_name": "kong_locks",
        "namespace": "zqNbte6xs9IR5GrdN3Q2z3BAzRDXWYqQ",
        "path": null,
        "redis": {
          "cloud_authentication": null,
          "cluster_addresses": null,
          "cluster_max_redirections": 5,
          "cluster_nodes": null,
          "connect_timeout": 2000,
          "connection_is_proxied": false,
          "database": 0,
          "host": "127.0.0.1",
          "keepalive_backlog": null,
          "keepalive_pool_size": 256,
          "password": null,
          "port": 6379,
          "read_timeout": 2000,
          "redis_proxy_type": null,
          "send_timeout": 2000,
          "sentinel_addresses": null,
          "sentinel_master": null,
          "sentinel_nodes": null,
          "sentinel_password": null,
          "sentinel_role": null,
          "sentinel_username": null,
          "server_name": null,
          "ssl": false,
          "ssl_verify": false,
          "timeout": 2000,
          "username": null
        },
        "retry_after_jitter_max": 0,
        "strategy": "local",
        "sync_rate": null,
        "throttling": null,
        "window_size": [
          300
        ],
        "window_type": "fixed"
      },
      "enabled": true,
	  "expressions": {
		"custom_key": null,
		"limit": [
		  "5*10"
		]
	  },
      "protocols": [
        "http",
        "https"
      ],
      "tags": [
        "wgunnDeckExpressionsTest"
      ]
    }
  ]
}

As the dump command is silently stripping away the expressions properties, doing a round trip deck gateway dump -> deck gateway sync is not idempotent and silently removes all plugin expressions that were configured in Konnect via other means (the UI in our case).

Activity

  1. self-assigned this
    on Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions