Blog
  • AI Gateway
  • AI Security
  • AIOps
  • API Security
  • API Gateway
|
    • API Management
    • API Development
    • API Design
    • Automation
    • Service Mesh
    • Insomnia
    • View All Blogs
  1. Home
  2. Blog
  3. Product Releases
  4. Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS
Product Releases
June 20, 2025
3 min read

Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS

Umair Waheed
Product Marketing, Runtimes, Kong
Andrew Jessup
Director of Product, Gateways and Mesh, Kong
Justin Davies
Product Manager, Mesh and Kubernetes, Kong

We’re at it again, bringing more incremental improvements to Kong Mesh! 

Built on top of Kuma, Kong Mesh brings much-needed simplicity and production-grade tooling. Kong Mesh is built for smooth operations with platform teams in mind, providing security, observability, and traffic control for modern, distributed applications. A single mesh can seamlessly span multiple zones: multiple cloud providers, Kubernetes clusters, and traditional server (VM / bare-metal) environments while offering zero-trust security, multiple isolated mesh support, and global/remote control planes. Konnect Mesh Manager provides a global view across all your Mesh deployments. With Kong Mesh, organizations can deploy with confidence and efficiency, managing mission-critical services reliably at high performance.

Kong Mesh 2.11 delivers several enhancements, including Amazon ECS support with automated Route 53 configuration, the ability to reduce the need for cluster roles when setting up Mesh, Embedded DNS, and experimental support for incremental configuration propagation, and an expansion of the supported policies for MeshHTTPRoute.

Read on to learn more!

ECS Support with automated Route 53 configuration 

While we have supported ECS with Kuma Mesh for a while, customers still have to manually configure the outbounds. This was cumbersome and time-consuming. With Mesh 2.11, you can now configure the control plane to create Route53 domains that will resolve to local addresses for service communication.

Reduction in RBAC scope for Mesh deployments

By default, Kong Mesh observes resources across an entire Kubernetes cluster. In production or shared clusters, this may not be desired as not all namespaces need to be monitored, or your teams do not have the cluster-wide scope to do this.  When deploying Mesh using Helm, you can now specify the namespaces that Mesh is allowed to watch:

This is achieved by taking the kuma-control-plane ClusterRole and binding it to only the allowed namespace via a RoleBinding, greatly reducing the RBAC permissions to allowed namespaces.

Move to Embedded DNS

Historically, we've used CoreDNS for service mapping to VIPs, which was used on all dataplanes. As we look to greatly reduce dataplane resource consumption, we've moved to an Embedded DNS specifically designed for Kuma Mesh. Beyond the reduction in resources needed, this opens up some interesting things we can do in the future to map out service-to-service communication and analytics for your workloads. Stay tuned for where we go with this!

Incremental configuration propagation (Incremental xDS)

By default, Kong Mesh will send the full configuration to the dataplane whenever updates are made in the Mesh. With Incremental configuration, only the differences (delta) of the configuration that has changed are sent to the dataplanes. This reduces CPU and memory utilization and is especially useful as the number of workloads increases.

This is an experimental feature, but can be enabled per dataplane with a Kubernetes annotation, or with an environment variable if using Universal:

Additional policy support for MeshHTTPRoute

MeshHTTPRoute is a routing policy in Kong Mesh that allows you to match and redirect HTTP traffic within the Mesh. This update gives you a much greater level of control over the HTTP protocol, the path, headers, and query parameters.  

We're releasing further policy support for MeshHTTPRoute in the following Mesh policies:

  • MeshTimeout: Specify explicit request timeouts for routes
  • MeshAccessLog: Capture access logs for traffic that matches a specific route
  • MeshRetry: Apply retry logic to specific routes based on HTTP error codes

Next steps

For a deeper dive into a complete list of features, updates, and changes, please refer to the CHANGELOG here.

Want to see Kong Mesh in action? Request a demo or start using Kong Mesh today.

Thank you for your continued support and trust in our product.

Kong MeshService MeshKubernetesAWS

More on this topic

Videos

Demystifying the Latest in Kong Mesh

eBooks

Hybrid API Gateway Clusters With Kong Konnect and Amazon Elastic Kubernetes Service

See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

Get a Demo
Topics
Kong MeshService MeshKubernetesAWS
Share on Social
Umair Waheed
Product Marketing, Runtimes, Kong
Andrew Jessup
Director of Product, Gateways and Mesh, Kong
Justin Davies
Product Manager, Mesh and Kubernetes, Kong

Recommended posts

Kong Mesh 2.12: SPIFFE/SPIRE Support and Consistent XDS Resource Names

Kong Logo
Product ReleasesSeptember 18, 2025

We're very excited to announce Kong Mesh 2.12 to the world! Kong Mesh 2.12 delivers two very important features: SPIFFE / SPIRE support, which provides enterprise-class workload identity and trust models for your mesh, as well as a consistent Kuma R

Justin Davies

Deploying Kong Mesh with Konnect on AWS ECS

Kong Logo
EngineeringFebruary 7, 2025

Deploying Kong Mesh on ECS The focus of this blog is to provide step-by-step instructions for deploying and configuring Kong Mesh with Kong Konnect on an AWS ECS instance so that anyone will be able to get pre-production installation of Kong Mesh st

Vince Russo

Announcing Mesh Manager Support in Konnect Terraform Provider

Kong Logo
Product ReleasesJuly 17, 2025

What Is Terraform? Terraform is an infrastructure-as-code (IaC) tool developed by HashiCorp. It allows users to define and provision data center infrastructure using a declarative configuration language known as HashiCorp Configuration Language (HCL

Krzysztof Słonka

Kuma 1.6.0 and Kong Mesh 1.7.0 Released With Kubernetes Gateway API support, AWS ACM Integration and more!

Kong Logo
Product ReleasesApril 12, 2022

We are happy to announce the latest release for both Kong Mesh and Kuma, which is packed with features and improvements. Kong Mesh 1.7 is focused on security and stability, as it allows to better integrate with AWS thanks to a native AWS ACM integra

Marco Palladino

Kong Cloud Gateways: A Year in Review

Kong Logo
Product ReleasesDecember 17, 2025

A quick refresher: Kong Cloud Gateways Kong Cloud Gateways are fully managed, high-performance data planes running on customer-dedicated infrastructure, orchestrated and operated by Kong through Kong Konnect . Customers can choose between: Serverle

Josh Wigginton

Announcing Kong Operator 2.0

Kong Logo
Product ReleasesOctober 1, 2025

Simplified controller configuration When using the Kong Ingress Controller, a significant amount of effort was needed to apply configuration to the controller by setting environment variables. The new ControlPlane resource greatly simplifies this an

Justin Davies

Building a First-Class Kubernetes Experience in Kong Konnect

Kong Logo
Product ReleasesSeptember 18, 2025

Simplify operations and scale with confidence To unlock Kubernetes’ full potential, many enterprises are relying on three key building blocks available in Kong Konnect today: Kubernetes Ingress Controllers: Ingress controllers are used for managing

Adam Jiroun

Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

Get a Demo
Powering the API world

Increase developer productivity, security, and performance at scale with the unified platform for API management, AI gateways, service mesh, and ingress controller.

Sign up for Kong newsletter

    • Platform
    • Kong Konnect
    • Kong Gateway
    • Kong AI Gateway
    • Kong Insomnia
    • Developer Portal
    • Gateway Manager
    • Cloud Gateway
    • Get a Demo
    • Explore More
    • Open Banking API Solutions
    • API Governance Solutions
    • Istio API Gateway Integration
    • Kubernetes API Management
    • API Gateway: Build vs Buy
    • Kong vs Postman
    • Kong vs MuleSoft
    • Kong vs Apigee
    • Documentation
    • Kong Konnect Docs
    • Kong Gateway Docs
    • Kong Mesh Docs
    • Kong AI Gateway
    • Kong Insomnia Docs
    • Kong Plugin Hub
    • Open Source
    • Kong Gateway
    • Kuma
    • Insomnia
    • Kong Community
    • Company
    • About Kong
    • Customers
    • Careers
    • Press
    • Events
    • Contact
    • Pricing
  • Terms
  • Privacy
  • Trust and Compliance
  • © Kong Inc. 2025