• The API Platform for AI.

      Explore More
      Platform Runtimes
      Kong Gateway
      • Kong Cloud Gateways
      • Kong Ingress Controller
      • Kong Operator
      • Kong Gateway Plugins
      Kong AI Gateway
      Kong Event Gateway
      Kong Mesh
      Platform Core Services
      • Gateway Manager
      • Mesh Manager
      • Service Catalog
      Platform Applications
      • Developer Portal
      • API and AI Analytics
      • API Products
      Development Tools
      Kong Insomnia
      • API Design
      • API Testing and Debugging
      Self-Hosted API Management
      Kong Gateway Enterprise
      Kong Open Source Projects
      • Kong Gateway OSS
      • Kuma
      • Kong Insomnia OSS
      • Kong Community
      Get Started
      • Sign Up for Kong Konnect
      • Documentation
    • Featured
      Open Banking SolutionsMobile Application API DevelopmentBuild a Developer PlatformAPI SecurityAPI GovernanceKafka Event StreamingAI GovernanceAPI Productization
      Industry
      Financial ServicesHealthcareHigher EducationInsuranceManufacturingRetailSoftware & TechnologyTransportation
      Use Case
      API Gateway for IstioBuild on KubernetesDecentralized Load BalancingMonolith to MicroservicesObservabilityPower OpenAI ApplicationsService Mesh ConnectivityZero Trust SecuritySee all Solutions
      Demo

      Learn how to innovate faster while maintaining the highest security standards and customer trust

      Register Now
  • Customers
    • Documentation
      Kong KonnectKong GatewayKong MeshKong AI GatewayKong InsomniaPlugin Hub
      Explore
      BlogLearning CentereBooksReportsDemosCase StudiesVideos
      Events
      API SummitWebinarsUser CallsWorkshopsMeetupsSee All Events
      For Developers
      Get StartedCommunityCertificationTraining
    • Company
      About UsWhy Kong?CareersPress RoomInvestorsContact Us
      Partner
      Kong Partner Program
      Security
      Trust and Compliance
      Support
      Enterprise Support PortalProfessional ServicesDocumentation
      Press Release

      Kong Expands with New Headquarters in Downtown San Francisco

      Read More
  • Pricing
  • Login
  • Get a Demo
  • Start for Free
Blog
  • Engineering
  • Enterprise
  • Learning Center
  • Kong News
  • Product Releases
    • API Gateway
    • Service Mesh
    • Insomnia
    • Kubernetes
    • API Security
    • AI Gateway
  • Home
  • Blog
  • Product Releases
  • Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS
Product Releases
June 20, 2025
3 min read

Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS

Umair Waheed
Product Marketing, Runtimes, Kong
Andrew Jessup
Principal Product Manager, KIC, Kong
Justin Davies
Product Manager, Mesh and Kubernetes, Kong

We’re at it again, bringing more incremental improvements to Kong Mesh! 

Built on top of Kuma, Kong Mesh brings much-needed simplicity and production-grade tooling. Kong Mesh is built for smooth operations with platform teams in mind, providing security, observability, and traffic control for modern, distributed applications. A single mesh can seamlessly span multiple zones: multiple cloud providers, Kubernetes clusters, and traditional server (VM / bare-metal) environments while offering zero-trust security, multiple isolated mesh support, and global/remote control planes. Konnect Mesh Manager provides a global view across all your Mesh deployments. With Kong Mesh, organizations can deploy with confidence and efficiency, managing mission-critical services reliably at high performance.

Kong Mesh 2.11 delivers several enhancements, including Amazon ECS support with automated Route 53 configuration, the ability to reduce the need for cluster roles when setting up Mesh, Embedded DNS, and experimental support for incremental configuration propagation, and an expansion of the supported policies for MeshHTTPRoute.

Read on to learn more!

ECS Support with automated Route 53 configuration 

While we have supported ECS with Kuma Mesh for a while, customers still have to manually configure the outbounds. This was cumbersome and time-consuming. With Mesh 2.11, you can now configure the control plane to create Route53 domains that will resolve to local addresses for service communication.

Reduction in RBAC scope for Mesh deployments

By default, Kong Mesh observes resources across an entire Kubernetes cluster. In production or shared clusters, this may not be desired as not all namespaces need to be monitored, or your teams do not have the cluster-wide scope to do this.  When deploying Mesh using Helm, you can now specify the namespaces that Mesh is allowed to watch:

This is achieved by taking the kuma-control-plane ClusterRole and binding it to only the allowed namespace via a RoleBinding, greatly reducing the RBAC permissions to allowed namespaces.

Move to Embedded DNS

Historically, we've used CoreDNS for service mapping to VIPs, which was used on all dataplanes. As we look to greatly reduce dataplane resource consumption, we've moved to an Embedded DNS specifically designed for Kuma Mesh. Beyond the reduction in resources needed, this opens up some interesting things we can do in the future to map out service-to-service communication and analytics for your workloads. Stay tuned for where we go with this!

Incremental configuration propagation (Incremental xDS)

By default, Kong Mesh will send the full configuration to the dataplane whenever updates are made in the Mesh. With Incremental configuration, only the differences (delta) of the configuration that has changed are sent to the dataplanes. This reduces CPU and memory utilization and is especially useful as the number of workloads increases.

This is an experimental feature, but can be enabled per dataplane with a Kubernetes annotation, or with an environment variable if using Universal:

Additional policy support for MeshHTTPRoute

MeshHTTPRoute is a routing policy in Kong Mesh that allows you to match and redirect HTTP traffic within the Mesh. This update gives you a much greater level of control over the HTTP protocol, the path, headers, and query parameters.  

We're releasing further policy support for MeshHTTPRoute in the following Mesh policies:

  • MeshTimeout: Specify explicit request timeouts for routes
  • MeshAccessLog: Capture access logs for traffic that matches a specific route
  • MeshRetry: Apply retry logic to specific routes based on HTTP error codes

Next steps

For a deeper dive into a complete list of features, updates, and changes, please refer to the CHANGELOG here.

Want to see Kong Mesh in action? Request a demo or start using Kong Mesh today.

Thank you for your continued support and trust in our product.

Topics:Kong Mesh
|
Service Mesh
|
Kubernetes
|
AWS
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, service mesh, and ingress controller.

Sign up for Kong newsletter

Platform
Kong KonnectKong GatewayKong AI GatewayKong InsomniaDeveloper PortalGateway ManagerCloud GatewayGet a Demo
Explore More
Open Banking API SolutionsAPI Governance SolutionsIstio API Gateway IntegrationKubernetes API ManagementAPI Gateway: Build vs BuyKong vs PostmanKong vs MuleSoftKong vs Apigee
Documentation
Kong Konnect DocsKong Gateway DocsKong Mesh DocsKong AI GatewayKong Insomnia DocsKong Plugin Hub
Open Source
Kong GatewayKumaInsomniaKong Community
Company
About KongCustomersCareersPressEventsContactPricing
  • Terms•
  • Privacy•
  • Trust and Compliance
  • © Kong Inc. 2025