DISCOVER & TEST KONNECT APIS IN REAL TIME WITH INSOMNIA 13 MIGRATE 50% FASTER WITH KONG MIGRATION SERVICES DON'T MISS OUT ON API + AI SUMMIT 2026 | PRICES INCREASE AUGUST 16
  • [Why Kong ](/company/why-kong)Why Kong
  • _API & AI CONNECTIVITY TECHNOLOGIES_
    The Unified API and AI Platform
    []
    API ManagementAI ManagementEvent ManagementMonetization
    Migration Services
    API Advisory Services + Forward Deployed EngineersNEW
    • RUNTIMES
    • [API Gateway ](/products/kong-gateway)API Gateway
    • [AI Gateway HOT](/products/kong-ai-gateway)AI Gateway HOT
    • [Event Gateway ](/products/event-gateway)Event Gateway
    • [Service Mesh ](/products/kong-mesh)Service Mesh
    • [Context Mesh ](/products/kong-konnect/features/context-mesh)Context Mesh
    • [Ingress Controller ](/products/kong-ingress-controller)Ingress Controller
    • [Kong Operator ](/products/kong-operator)Kong Operator
    • CORE SERVICES
    • [MCP Registry NEW](/products/mcp-registry)MCP Registry NEW
    • [API Service Catalog ](/products/kong-konnect/features/api-service-catalog)API Service Catalog
    • [Runtime Management ](/products/kong-konnect/features/runtime-management)Runtime Management
    • [APIOps & Automation ](/products/apiops-automation)APIOps & Automation
    • APPS & AI AGENTS
    • [Developer Portal ](/products/kong-konnect/features/developer-portal)Developer Portal
    • [Usage Billing & Metering ](/products/kong-konnect/features/usage-based-metering-and-billing)Usage Billing & Metering
    • [Observability ](/products/kong-konnect/features/api-observability)Observability
    • [KAi Agent ](/products/kong-konnect/features/kai-ai-agent)KAi Agent
    DEVELOPER TOOLS
    [Insomnia ](https://insomnia.rest/)Insomnia [Plugins ](https://developer.konghq.com/plugins/)Plugins [Volcano ](https://volcano.dev/)Volcano [Kong MCP ](https://developer.konghq.com/konnect-platform/konnect-mcp/)Kong MCP [Documentation ](https://docs.konghq.com/)Documentation [Open Source ](/community)Open Source
      • FOR PLATFORM TEAMS
      • [Developer Platform ](/solutions/building-developer-platform)Developer Platform
      • [Kubernetes and Microservices ](/solutions/build-on-kubernetes)Kubernetes and Microservices
      • [Observability ](/solutions/observability)Observability
      • [Service Mesh Connectivity ](/solutions/service-mesh-connectivity)Service Mesh Connectivity
      • [Kafka Event Streaming ](/solutions/kafka-stream-api-management)Kafka Event Streaming
      • FOR EXECUTIVES
      • [AI Connectivity ](/ai-connectivity)AI Connectivity
      • [Open Banking ](/solutions/open-banking)Open Banking
      • [Legacy Migration ](/solutions/legacy-api-management-migration)Legacy Migration
      • [Platform Cost Reduction ](/solutions/api-platform-consolidation)Platform Cost Reduction
      • [Kafka Cost Optimization ](/solutions/reduce-kafka-cost)Kafka Cost Optimization
      • [API Monetization ](/solutions/api-monetization)API Monetization
      • [AI Monetization ](/solutions/ai-monetization)AI Monetization
      • [AI FinOps ](/solutions/ai-cost-governance-finops)AI FinOps
      • FOR AI TEAMS
      • [Agent Gateway ](/agent-gateway)Agent Gateway
      • [AI Governance ](/solutions/ai-governance)AI Governance
      • [AI Security ](/solutions/ai-security)AI Security
      • [AI Cost Control ](/solutions/ai-cost-optimization-management)AI Cost Control
      • [Agentic Infrastructure ](/solutions/agentic-ai-workflows)Agentic Infrastructure
      • [MCP Production ](/solutions/mcp-production-and-consumption)MCP Production
      • [MCP Traffic Gateway ](/solutions/mcp-governance)MCP Traffic Gateway
      • FOR DEVELOPERS
      • [Mobile App API Development ](/solutions/mobile-application-api-development)Mobile App API Development
      • [GenAI App Development ](/solutions/power-openai-applications)GenAI App Development
      • [API Gateway for Istio ](/solutions/istio-gateway)API Gateway for Istio
      • [Decentralized Load Balancing ](/solutions/decentralized-load-balancing)Decentralized Load Balancing
      • BY INDUSTRY
      • [Financial Services ](/solutions/financial-services-industry)Financial Services
      • [Healthcare ](/solutions/healthcare)Healthcare
      • [Higher Education ](/solutions/api-platform-for-education-services)Higher Education
      • [Insurance ](/solutions/insurance)Insurance
      • [Manufacturing ](/solutions/manufacturing)Manufacturing
      • [Retail ](/solutions/retail)Retail
      • [Software & Technology ](/solutions/software-and-technology)Software & Technology
      • [Transportation ](/solutions/transportation-and-logistics)Transportation
  • [Pricing ](/pricing)Pricing
      • DOCUMENTATION
      • [Kong Konnect ](https://developer.konghq.com/konnect/)Kong Konnect
      • [Kong Gateway ](https://developer.konghq.com/gateway/)Kong Gateway
      • [Kong Mesh ](https://developer.konghq.com/mesh/)Kong Mesh
      • [Kong AI Gateway ](https://developer.konghq.com/ai-gateway/)Kong AI Gateway
      • [Kong Event Gateway ](https://developer.konghq.com/event-gateway/)Kong Event Gateway
      • [Kong Insomnia ](https://developer.konghq.com/insomnia/)Kong Insomnia
      • [Plugin Hub ](https://developer.konghq.com/plugins/)Plugin Hub
      • EXPLORE
      • [Blog ](/blog)Blog
      • [Learning Center ](/blog/learning-center)Learning Center
      • [eBooks ](/resources/e-book)eBooks
      • [Reports ](/resources/reports)Reports
      • [Demos ](/resources/demos)Demos
      • [Customer Stories ](/customer-stories)Customer Stories
      • [Videos ](/resources/videos)Videos
      • EVENTS
      • [API + AI Summit ](/events/conferences/api-ai-summit)API + AI Summit
      • [Agentic Era World Tour ](/agentic-era-world-tour)Agentic Era World Tour
      • [Webinars ](/events/webinars)Webinars
      • [User Calls ](/events/user-calls)User Calls
      • [Workshops ](/events/workshops)Workshops
      • [Meetups ](/events/meetups)Meetups
      • [See All Events ](/events)See All Events
      • FOR DEVELOPERS
      • [Get Started ](https://developer.konghq.com/)Get Started
      • [Community ](/community)Community
      • [Certification ](/academy/certification)Certification
      • [Training ](https://education.konghq.com)Training
      • COMPANY
      • [About Us ](/company/about-us)About Us
      • [We're Hiring! ](/company/careers)We're Hiring!
      • [Press Room ](/company/press-room)Press Room
      • [Contact Us ](/company/contact-us)Contact Us
      • [Kong Partner Program ](/partners)Kong Partner Program
      • [Enterprise Support Portal ](https://support.konghq.com/s/)Enterprise Support Portal
      • [Documentation ](https://developer.konghq.com/?_gl=1*tphanb*_gcl_au*MTcxNTQ5NjQ0MC4xNzY5Nzg4MDY0LjIwMTI3NzEwOTEuMTc3MzMxODI2MS4xNzczMzE4MjYw*_ga*NDIwMDU4MTU3LjE3Njk3ODgwNjQ.*_ga_4JK9146J1H*czE3NzQwMjg1MjkkbzE4OSRnMCR0MTc3NDAyODUyOSRqNjAkbDAkaDA)Documentation
  • [](/search)
  • [Login](https://cloud.konghq.com/login)Login
  • [Book Demo](/contact-sales)Book Demo
  • [Get Started](/products/kong-konnect/register)Get Started
[Blog](/blog)Blog
  • [AI Gateway ](/blog/tag/ai-gateway)AI Gateway
  • [AI Security ](/blog/tag/ai-security)AI Security
  • [AIOps ](/blog/tag/aiops)AIOps
  • [API Security ](/blog/tag/api-security)API Security
  • [API Gateway ](/blog/tag/api-gateway)API Gateway
|
    • [API Management ](/blog/tag/api-management)API Management
    • [API Development ](/blog/tag/api-development)API Development
    • [API Design ](/blog/tag/api-design)API Design
    • [Automation ](/blog/tag/automation)Automation
    • [Service Mesh ](/blog/tag/service-mesh)Service Mesh
    • [Insomnia ](/blog/tag/insomnia)Insomnia
    • [Event Gateway ](/blog/tag/event-gateway)Event Gateway
    • [View All Blogs ](/blog/page/1)View All Blogs
We're Entering the Age of AI Connectivity [Read more](/blog/news/the-age-of-ai-connectivity)Read moreProducts & Agents:
    • [Kong AI Gateway](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong API Gateway](/products/kong-gateway)Kong API Gateway
    • [Kong Event Gateway](/products/event-gateway)Kong Event Gateway
    • [Kong Metering & Billing](/products/kong-konnect/features/usage-based-metering-and-billing)Kong Metering & Billing
    • [Kong Insomnia](/products/kong-insomnia)Kong Insomnia
    • [Kong Konnect](/products/kong-konnect)Kong Konnect
  • [Documentation](https://developer.konghq.com)Documentation
  • [Book Demo](/contact-sales)Book Demo
  1. Home
  2. Blog
  3. Product Releases
  4. Kong Mesh 2.14: Mesh-Scoped Zone Proxy Policies, SNI Matching, and Stronger Security Defaults
[Kong Mesh](/blog/tag/kong-mesh)Kong Mesh
June 23, 2026
7 min read

# Kong Mesh 2.14: Mesh-Scoped Zone Proxy Policies, SNI Matching, and Stronger Security Defaults

Justin Davies
Product Manager, Mesh and Kubernetes, Kong

Kong Mesh 2.14 delivers important improvements for multi-zone customers, with expanded policy support for zone proxies, new SNI-based matching for cross-zone and external-service traffic, stronger default security settings, and better observability through OpenTelemetry and Grafana dashboards.

**What is Kong Mesh?**

Built on top of the open source Kuma service mesh, Kong Mesh is all about bringing simplicity and enterprise features to our customers. Kong Mesh is built for smooth operations with platform teams in mind, providing security, observability, and traffic control for modern, distributed applications. A single mesh can seamlessly span multiple zones: multiple cloud providers, Kubernetes clusters, and traditional server (VM / bare-metal) environments, while offering zero-trust security, multiple isolated mesh support, and global/remote control planes. Konnect Mesh Manager provides a global view across all your Mesh deployments. With Kong Mesh, organizations can deploy with confidence and efficiency, managing mission-critical services reliably at high performance.

## Mesh-scoped zone proxy deployment model

Kong Mesh 2.14 also introduces improvements to the mesh-scoped zone proxy deployment model. This makes it easier to configure and operate zone proxies for specific meshes, including Helm support for mesh zone proxy configuration.

For customers running many meshes or more complex multi-zone topologies, this gives finer-grained control over how zone proxy infrastructure is deployed and managed. For example:

meshes:
  - name: default
    ingress:
      enabled: true
      service:
        type: LoadBalancer
        port: 10001
      deployment:
        replicas: 2
    egress:
      enabled: true
      service:
        type: ClusterIP
        port: 10002
      deployment:
        replicas: 2

## Policy support for mesh scoped zone proxies

In Kong Mesh 2.14, we have added support for applying policies to mesh scoped zone proxies. This gives platform teams more control over traffic moving between zones and helps bring the same policy-driven operational model to cross-zone traffic that customers already use for workloads inside a mesh.  For example, being able to apply observability and permissions policies on a MeshExternalService, or gathering telemetry on all zone egress.

This release adds zone proxy support across policies:

  • - `MeshTrafficPermission`
  • - `MeshTimeout`
  • - `MeshRateLimit`
  • - `MeshFaultInjection`
  • - `MeshCircuitBreaker`
  • - `MeshHealthCheck`
  • - `MeshProxyPatch`

As well as proxy observability:

  • - `MeshMetric`
  • - `MeshTrace`
  • - `MeshAccessLog`

This is especially useful for larger multi-zone deployments where zone ingress and zone egress proxies are critical parts of the traffic path.

For example, to apply a MeshMetric policy to your egress proxies, you can use something like this:

type: MeshMetric
name: zone-egress-metrics
mesh: default
spec:
  targetRef:
    kind: Dataplane
    labels:
      kuma.io/listener-zoneegress: enabled
  default:
    backends:
      - type: Prometheus
        prometheus:
          port: 5670
          path: /metrics
          tls:
            mode: Disabled

## SNI matching for Mesh scoped zone proxy traffic

Historically, customers had limited ways to apply fine-grained policy at the zone proxy layer. Zone egress traffic often represents many different upstream destinations flowing through the same proxy, so matching only on the proxy itself was too broad for many real-world use cases.

With Kong Mesh 2.14, policies can match on SNI for zone proxy traffic. This means teams can apply traffic controls based on the actual destination being reached, rather than applying the same behavior to every request passing through the zone proxy.

For example, you can inject failures for one external service reached through zone egress without affecting other external services:

type: MeshFaultInjection
name: zone-egress-fault-injection
mesh: default
spec:
  targetRef:
    kind: Dataplane
    labels:
      kuma.io/listener-zoneegress: enabled
  rules:
    - matches:
        - sni:
            type: Exact
            value: sni.extsvc.default.us-east-1.payments.443
      default:
        http:
          - abort:
              httpStatus: 503
              percentage: 50

The same matching model can also be used for rate limiting:

type: MeshRateLimit
name: zone-egress-rate-limit
mesh: default
spec:
  targetRef:
    kind: Dataplane
    labels:
      kuma.io/listener-zoneegress: enabled
  rules:
    - matches:
        - sni:
            type: Exact
            value: sni.extsvc.default.us-east-1.payments.443
      default:
        local:
          http:
            requestRate:
              num: 1
              interval: 1h
            onRateLimit:
              status: 429

This is a big step forward for customers operating shared zone egress infrastructure. Platform teams can now express policies that are specific to a destination, while still keeping the operational simplicity of centralized zone proxy deployments.

## Better observability with OpenTelemetry and Grafana

Kong Mesh 2.14 includes several observability improvements.

Control plane metrics can now be pushed through OpenTelemetry when an OTLP endpoint is configured, making it easier to integrate Kong Mesh operational metrics into existing observability pipelines.

We have also added and improved Grafana dashboards, including dashboards for zone proxies, so operators can more easily understand the health and behavior of their mesh infrastructure.

MeshMetric and MeshTrace have also been improved, including better workload identity information in metrics and traces.

For example, Mesh tracing, logging, and metrics can now be configured with a ***MeshOpenTelemetryBackend*** backend:

apiVersion: kuma.io/v1alpha1
kind: MeshOpenTelemetryBackend
metadata:
  name: main-collector
  namespace: kuma-system
  labels:
    kuma.io/mesh: default
spec:
  endpoint:
    address: otel-collector.observability
    port: 4317
  protocol: grpc
---
apiVersion: kuma.io/v1alpha1
kind: MeshMetric
metadata:
  name: all-metrics
  namespace: kuma-system
  labels:
    kuma.io/mesh: default
spec:
  targetRef:
    kind: Mesh
  default:
    backends:
      - type: OpenTelemetry
        openTelemetry:
          backendRef:
            kind: MeshOpenTelemetryBackend
     labels:
        kuma.io/display-name: main-collector
          refreshInterval: 30s
---
apiVersion: kuma.io/v1alpha1
kind: MeshTrace
metadata:
  name: all-traces
  namespace: kuma-system
  labels:
    kuma.io/mesh: default
spec:
  targetRef:
    kind: Mesh
  default:
    backends:
      - type: OpenTelemetry
        openTelemetry:
          backendRef:
            kind: MeshOpenTelemetryBackend
     labels:
        kuma.io/display-name: main-collector

    sampling:
      overall: 80
---
apiVersion: kuma.io/v1alpha1
kind: MeshAccessLog
metadata:
  name: all-access-logs
  namespace: kuma-system
  labels:
    kuma.io/mesh: default
spec:
  targetRef:
    kind: Mesh
  default:
    backends:
      - type: OpenTelemetry
        openTelemetry:
          backendRef:
            kind: MeshOpenTelemetryBackend
     labels:
        kuma.io/display-name: main-collector

## Stronger security defaults

This release tightens several defaults to improve the security posture of Kong Mesh deployments.

The Envoy admin API now uses a Unix domain socket by default instead of binding to localhost TCP. This reduces the risk of application containers in the same pod being able to access sensitive Envoy admin endpoints.

Localhost admin behavior has also been restricted so that only direct loopback requests are treated as admin requests, and CORS allowed domains are now empty by default unless explicitly configured.

These changes are designed to make the secure path the default path.

## Kubernetes native sidecars enabled by default

Kong Mesh 2.14 enables Kubernetes native sidecar containers by default for Kubernetes 1.29 and newer.

This improves startup and shutdown behavior by using Kubernetes' native sidecar lifecycle support, helping the sidecar start before application containers and remain available while the application shuts down.

## Other improvements worth highlighting

Kong Mesh 2.14 also includes a number of smaller improvements that are useful for enterprise operations.

### KDS offline signing tokens

Customers can now generate zone tokens with an offline signing key. This is useful for environments where token issuance is part of a separate automation flow, or where operators want to avoid calling the control plane at token-generation time. For example:

kumactl generate zone-token \
  --zone zone-1 \
  --valid-for 24h \
  --scope ingress \
  --scope egress \
  --signing-key-path /keys/key.pem \
  --kid 1

The same offline signing flow is also available for user tokens:

kumactl generate user-token \
  --name john.doe@example.com \
  --group users \
  --valid-for 24h \
  --signing-key-path /keys/key.pem \
  --kid 1

### MeshIdentity extension providers

Kong Mesh 2.14 expands the MeshIdentity provider model with extension providers. This allows MeshIdentity to integrate with external certificate authority systems such as AWS ACM Private CA, Vault, and cert-manager, while keeping the MeshIdentity API consistent for workloads.

For example, a MeshIdentity can use an ACM PCA-backed extension provider:

type: MeshIdentity
name: acm-pca-identity
mesh: default
spec:
  spiffeID:
    trustDomain: "{{ .Mesh }}.{{ .Zone }}.mesh.local"
    path: "/ns/{{ .Namespace }}/sa/{{ .ServiceAccount }}"
  provider:
    type: Extension
    extension:
      name: acmpca
      config:
        certificateAuthorityArn: arn:aws:acm-pca:us-east-1:123456789012:certificate-authority/example
        region: us-east-1

Or a Vault-backed extension provider:

type: MeshIdentity
name: vault-identity
mesh: default
spec:
  spiffeID:
    trustDomain: "{{ .Mesh }}.{{ .Zone }}.mesh.local"
    path: "/ns/{{ .Namespace }}/sa/{{ .ServiceAccount }}"
  provider:
    type: Extension
    extension:
      name: vault
      config:
        address: https://vault.example.com
        mountPath: pki
        role: kong-mesh-workload

Or a cert-manager-backed extension provider:

type: MeshIdentity
name: cert-manager-identity
mesh: default
spec:
  spiffeID:
    trustDomain: "{{ .Mesh }}.{{ .Zone }}.mesh.local"
    path: "/ns/{{ .Namespace }}/sa/{{ .ServiceAccount }}"
  provider:
    type: Extension
    extension:
      name: certmanager
      config:
        issuerRef:
          name: mesh-issuer
          kind: ClusterIssuer

The exact `config` fields depend on the extension provider being used, but the MeshIdentity shape stays the same: select workloads, define their SPIFFE ID format, and choose the provider that issues their certificates.

### Label-based MeshService matching without inbound tags

Kong Mesh 2.14 also adds support for running without generated inbound tags. Historically, Kuma and Kong Mesh relied heavily on inbound tags such as `kuma.io/service `to identify service membership. That worked, but it also made MeshService generation dependent on tag data attached to individual inbound ports.

With 2.14, customers can opt in to label-based MeshService matching. This allows generated MeshServices to select dataplanes using workload labels instead of inbound tags, which is a cleaner model for Kubernetes and Universal environments and an important step toward the future 3.0 model.

This can be enabled through Helm:

experimental:
  inboundTagsDisabled: true

With this enabled, generated MeshServices use `dataplaneLabels` selectors:

type: MeshService
name: backend
mesh: default
spec:
  selector:
    dataplaneLabels:
      matchLabels:
        app: backend
        k8s.kuma.io/namespace: demo
  ports:
    - name: http
      port: 80
      targetPort: 8080
      appProtocol: http

This is especially useful for customers who want MeshService selection to follow platform labels, or who are preparing for a model where inbound tags are no longer the primary way to describe service membership.

## Improved dataplane and xDS performance (Experimental)

Inbound Envoy listeners now use SO_REUSEPORT by default, improving connection distribution under load.

Kong Mesh 2.14 also includes improvements to delta xDS configuration through Helm and Kubernetes injection, plus additional xDS stability and size improvements. These changes help larger environments scale more smoothly as the number of workloads, services, and policies grows.

This is part of the Experimental deltaXds feature for 2.14, which will be the default in Kong Mesh 3.0:

helm upgrade --install kong-mesh kong-mesh/kong-mesh \
  --namespace kong-mesh-system \
  --set experimental.deltaXds=true

## Important upgrade considerations

Before upgrading, customers should review the 2.14 upgrade notes carefully.

A few changes worth calling out:

  • - The readiness reporter is now TCP-only on port 9902.
  • - Envoy admin access now uses a Unix domain socket by default.
  • - MeshAccessLog OpenTelemetry attribute keys are now validated.
  • - Prometheus metrics changed from Summary to Histogram format.
  • - MeshMultiZoneService names longer than 63 characters are deprecated.
  • - CPU limits have been removed from default injected Kuma containers.
  • - Externally managed RBAC manifests may need updates.

## Next steps

Want a deeper dive into a complete list of features, updates, and changes? Please refer to the [CHANGELOG](https://developer.konghq.com/mesh/changelog/)CHANGELOG.

Want to see Kong Mesh 2.14 in action? [Get a demo](https://konghq.com/products/kong-mesh/request-demo)Get a demo or [start using Kong Mesh](https://docs.konghq.com/mesh/2.11.x/introduction/install/)start using Kong Mesh today.

## Mesh your services together effortlessly with Kong

[Learn More](/products/kong-mesh/)Learn More[Get a Demo](/contact-sales)Get a Demo

## FAQs

**1. What is a mesh-scoped zone proxy deployment model?**

A mesh-scoped zone proxy deployment model lets you deploy dedicated ingress and egress proxies for each mesh instance rather than sharing a single set across all meshes in a zone. This gives you independent traffic isolation, per-mesh policy enforcement, and cleaner failure domains. Kong Mesh 2.14 adds full Helm support for this model, so you can configure it declaratively alongside the rest of your GitOps workflow.

**2. How does SNI matching improve zone proxy traffic control?**

SNI matching lets zone proxies inspect the Server Name Indication field on incoming TLS connections and apply policies based on the destination service. Instead of blanket rules at the zone boundary, you get fine-grained control over which traffic policies apply to which services as traffic enters or exits a zone. This makes multi-mesh and multi-cluster policy enforcement significantly more precise.

**3. What policies can you apply to mesh-scoped zone proxies?**

Kong Mesh 2.14 supports ten policies on mesh-scoped zone proxies: MeshTrafficPermission, MeshTimeout, MeshRateLimit, MeshFaultInjection, MeshCircuitBreaker, MeshHealthCheck, MeshProxyPatch, MeshMetric, MeshTrace, and MeshAccessLog. These cover access control, resilience, observability, and traffic shaping at the zone proxy layer, giving you the same policy granularity at the mesh boundary that you already have at the sidecar level.

**4. How do Kubernetes native sidecars change sidecar management?**

Starting with Kong Mesh 2.14, Kubernetes native sidecars are enabled by default on clusters running Kubernetes 1.29 or later. Native sidecars use the Kubernetes init container lifecycle, which means the sidecar starts before your application container and stops after it. This eliminates common race conditions during pod startup and shutdown and removes the need for custom workarounds to manage sidecar ordering.

**5. What changed with observability in Kong Mesh 2.14?**

Control plane metrics now export via OTLP (OpenTelemetry Protocol), and the Grafana dashboards have been updated to use these improved metrics. A new MeshOpenTelemetryBackend resource gives you a declarative way to configure OpenTelemetry collection per mesh. Together, these changes consolidate observability into a single standards-based pipeline rather than relying on fragmented metric sources.

**6. How does Kong Mesh 2.14 strengthen security defaults?**

Three defaults changed. The Envoy admin API now communicates over a Unix domain socket instead of a TCP port, reducing the attack surface on each proxy. Localhost access to the admin API is restricted by default. And CORS headers ship empty by default, so cross-origin requests are blocked unless you explicitly configure an allow list. These changes enforce a stricter zero-trust baseline without requiring manual hardening.

**7. What are KDS offline signing tokens and when would you use them?**

KDS offline signing tokens let you pre-generate authentication tokens for zone control planes and users without requiring a live connection to the global control plane. This is useful for air-gapped deployments, disaster recovery scenarios, or any environment where the global control plane may be temporarily unreachable. You generate the tokens ahead of time and distribute them to zones or users as part of your provisioning workflow.

- [Kong Mesh](/blog/tag/kong-mesh)Kong Mesh- [Service Mesh](/blog/tag/service-mesh)Service Mesh- [Zero-Trust](/blog/tag/zero-trust)Zero-Trust- [Kubernetes](/blog/tag/kubernetes)Kubernetes- [Observability](/blog/tag/observability)Observability

Table of Contents

  • Mesh-scoped zone proxy deployment model
  • Policy support for mesh scoped zone proxies
  • SNI matching for Mesh scoped zone proxy traffic
  • Better observability with OpenTelemetry and Grafana
  • Stronger security defaults
  • Kubernetes native sidecars enabled by default
  • Other improvements worth highlighting
  • Improved dataplane and xDS performance (Experimental)
  • Important upgrade considerations
  • Next steps
  • FAQs

## More on this topic

_Videos_

## Demystifying the Latest in Kong Mesh

_Videos_

## Strategies for Adopting Service Mesh

## See Kong in action

Accelerate deployments, reduce vulnerabilities, and gain real-time visibility. 

[Get a Demo](/contact-sales)Get a Demo
**Topics**
- [Kong Mesh](/blog/tag/kong-mesh)Kong Mesh- [Service Mesh](/blog/tag/service-mesh)Service Mesh- [Zero-Trust](/blog/tag/zero-trust)Zero-Trust- [Kubernetes](/blog/tag/kubernetes)Kubernetes- [Observability](/blog/tag/observability)Observability
Justin Davies
Product Manager, Mesh and Kubernetes, Kong

Recommended posts

# Kong Mesh 2.12: SPIFFE/SPIRE Support and Consistent XDS Resource Names

[Product Releases](/blog/tag)Product ReleasesSeptember 18, 2025

We're very excited to announce Kong Mesh 2.12 to the world! Kong Mesh 2.12 delivers two very important features: SPIFFE / SPIRE support, which provides enterprise-class workload identity and trust models for your mesh, as well as a consistent Kuma R

Justin Davies

# Kong Mesh 2.13: Mesh Identity Support for Universal Mode & LTS

[Product Releases](/blog/tag)Product ReleasesJanuary 22, 2026

Kong Mesh 2.13 delivers full support for Mesh Identity for Kubernetes and Universal mode. Plus, it's been designated as a Long Term Support release, with support for a total of 2 years. But first, what's Kong Mesh for the uninitiated? Built on top

Justin Davies

# Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS

[Product Releases](/blog/tag)Product ReleasesJune 20, 2025

We’re at it again, bringing more incremental improvements to Kong Mesh!  Built on top of Kuma, Kong Mesh brings much-needed simplicity and production-grade tooling. Kong Mesh is built for smooth operations with platform teams in mind, providing secu

Justin Davies

# Achieving Zero Trust on VMs with Universal Mesh

[Engineering](/blog/tag)EngineeringJune 10, 2024

Two of the main tenets of Zero Trust are encryption between services and managing the connections each service is allowed to use. Achieving this generally falls to running a service mesh in a Kubernetes cluster. Refactoring applications to run prope

George Fridrich

# Announcing Mesh Manager Support in Konnect Terraform Provider

[Product Releases](/blog/tag)Product ReleasesJuly 17, 2025

What Is Terraform? Terraform is an infrastructure-as-code (IaC) tool developed by HashiCorp. It allows users to define and provision data center infrastructure using a declarative configuration language known as HashiCorp Configuration Language (HCL

Krzysztof Słonka

# Announcing Kong Operator 2.2

[Product Releases](/blog/tag)Product ReleasesJune 12, 2026

Kong Operator 2.2 introduces support for Kong Event Gateway . This allows customers to manage Kong Event Gateway resources directly from Kubernetes, whilst still using Konnect as the managed control plane. For teams already using Kubernetes as the

Justin Davies

# Kong A2A and MCP Metrics: Visibility and Governance for AI Tool Adoption at Scale

[Product Releases](/blog/tag)Product ReleasesApril 23, 2026

When an organization deploys AI agents at scale, high uptime and low latency are an important baseline. However, Platform owners and business stakeholders could be flying blind on several fronts: The Insights Gap: Non-technical stakeholders have li

Amit Shah

# Kong Mesh 2.12: SPIFFE/SPIRE Support and Consistent XDS Resource Names

[Product Releases](/blog/tag)Product ReleasesSeptember 18, 2025

We're very excited to announce Kong Mesh 2.12 to the world! Kong Mesh 2.12 delivers two very important features: SPIFFE / SPIRE support, which provides enterprise-class workload identity and trust models for your mesh, as well as a consistent Kuma R

Justin Davies

# Kong Mesh 2.13: Mesh Identity Support for Universal Mode & LTS

[Product Releases](/blog/tag)Product ReleasesJanuary 22, 2026

Kong Mesh 2.13 delivers full support for Mesh Identity for Kubernetes and Universal mode. Plus, it's been designated as a Long Term Support release, with support for a total of 2 years. But first, what's Kong Mesh for the uninitiated? Built on top

Justin Davies

# Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS

[Product Releases](/blog/tag)Product ReleasesJune 20, 2025

We’re at it again, bringing more incremental improvements to Kong Mesh!  Built on top of Kuma, Kong Mesh brings much-needed simplicity and production-grade tooling. Kong Mesh is built for smooth operations with platform teams in mind, providing secu

Justin Davies

# Achieving Zero Trust on VMs with Universal Mesh

[Engineering](/blog/tag)EngineeringJune 10, 2024

Two of the main tenets of Zero Trust are encryption between services and managing the connections each service is allowed to use. Achieving this generally falls to running a service mesh in a Kubernetes cluster. Refactoring applications to run prope

George Fridrich

# Announcing Mesh Manager Support in Konnect Terraform Provider

[Product Releases](/blog/tag)Product ReleasesJuly 17, 2025

What Is Terraform? Terraform is an infrastructure-as-code (IaC) tool developed by HashiCorp. It allows users to define and provision data center infrastructure using a declarative configuration language known as HashiCorp Configuration Language (HCL

Krzysztof Słonka

# Announcing Kong Operator 2.2

[Product Releases](/blog/tag)Product ReleasesJune 12, 2026

Kong Operator 2.2 introduces support for Kong Event Gateway . This allows customers to manage Kong Event Gateway resources directly from Kubernetes, whilst still using Konnect as the managed control plane. For teams already using Kubernetes as the

Justin Davies

# Kong A2A and MCP Metrics: Visibility and Governance for AI Tool Adoption at Scale

[Product Releases](/blog/tag)Product ReleasesApril 23, 2026

When an organization deploys AI agents at scale, high uptime and low latency are an important baseline. However, Platform owners and business stakeholders could be flying blind on several fronts: The Insights Gap: Non-technical stakeholders have li

Amit Shah

# Kong Mesh 2.12: SPIFFE/SPIRE Support and Consistent XDS Resource Names

[Product Releases](/blog/tag)Product ReleasesSeptember 18, 2025

We're very excited to announce Kong Mesh 2.12 to the world! Kong Mesh 2.12 delivers two very important features: SPIFFE / SPIRE support, which provides enterprise-class workload identity and trust models for your mesh, as well as a consistent Kuma R

Justin Davies

# Kong Mesh 2.13: Mesh Identity Support for Universal Mode & LTS

[Product Releases](/blog/tag)Product ReleasesJanuary 22, 2026

Kong Mesh 2.13 delivers full support for Mesh Identity for Kubernetes and Universal mode. Plus, it's been designated as a Long Term Support release, with support for a total of 2 years. But first, what's Kong Mesh for the uninitiated? Built on top

Justin Davies

# Kong Mesh 2.11: Reduced Privileges, Improved Support for AWS ECS

[Product Releases](/blog/tag)Product ReleasesJune 20, 2025

We’re at it again, bringing more incremental improvements to Kong Mesh!  Built on top of Kuma, Kong Mesh brings much-needed simplicity and production-grade tooling. Kong Mesh is built for smooth operations with platform teams in mind, providing secu

Justin Davies

# Achieving Zero Trust on VMs with Universal Mesh

[Engineering](/blog/tag)EngineeringJune 10, 2024

Two of the main tenets of Zero Trust are encryption between services and managing the connections each service is allowed to use. Achieving this generally falls to running a service mesh in a Kubernetes cluster. Refactoring applications to run prope

George Fridrich

# Announcing Mesh Manager Support in Konnect Terraform Provider

[Product Releases](/blog/tag)Product ReleasesJuly 17, 2025

What Is Terraform? Terraform is an infrastructure-as-code (IaC) tool developed by HashiCorp. It allows users to define and provision data center infrastructure using a declarative configuration language known as HashiCorp Configuration Language (HCL

Krzysztof Słonka

# Announcing Kong Operator 2.2

[Product Releases](/blog/tag)Product ReleasesJune 12, 2026

Kong Operator 2.2 introduces support for Kong Event Gateway . This allows customers to manage Kong Event Gateway resources directly from Kubernetes, whilst still using Konnect as the managed control plane. For teams already using Kubernetes as the

Justin Davies

# Kong A2A and MCP Metrics: Visibility and Governance for AI Tool Adoption at Scale

[Product Releases](/blog/tag)Product ReleasesApril 23, 2026

When an organization deploys AI agents at scale, high uptime and low latency are an important baseline. However, Platform owners and business stakeholders could be flying blind on several fronts: The Insights Gap: Non-technical stakeholders have li

Amit Shah

## Ready to see Kong in action?

Get a personalized walkthrough of Kong's platform tailored to your architecture, use cases, and scale requirements.

[Get a Demo](/contact-sales)Get a Demo

## step-0

    • Company
    • [About Kong ](/company/about-us)About Kong
    • [Customers ](/customer-stories)Customers
    • [Careers ](/company/careers)Careers
    • [Press ](/company/press-room)Press
    • [Events ](/events)Events
    • [Contact ](/company/contact-us)Contact
    • [Pricing ](/pricing)Pricing
      •    * [Terms](/legal/terms-of-use)
      •    * [Privacy](/legal/privacy-policy)
      •    * [Trust and Compliance](https://trust.konghq.com/)
    • Platform
    • [Kong AI Gateway ](/products/kong-ai-gateway)Kong AI Gateway
    • [Kong Konnect ](/products/kong-konnect)Kong Konnect
    • [Kong Gateway ](/products/kong-gateway)Kong Gateway
    • [Kong Event Gateway ](/products/event-gateway)Kong Event Gateway
    • [Kong Insomnia ](/products/kong-insomnia)Kong Insomnia
    • [Documentation ](https://developer.konghq.com)Documentation
    • [Book Demo ](/contact-sales)Book Demo
    • Compare
    • [AI Gateway Alternatives ](/performance-comparison/ai-gateway-alternatives)AI Gateway Alternatives
    • [Kong vs Apigee ](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • [Kong vs IBM ](/performance-comparison/ibm-api-connect-vs-kong)Kong vs IBM
    • [Kong vs Postman ](/performance-comparison/kong-vs-postman)Kong vs Postman
    • [Kong vs Mulesoft ](/performance-comparison/kong-vs-mulesoft)Kong vs Mulesoft
    • Explore More
    • [Open Banking API Solutions ](/solutions/open-banking)Open Banking API Solutions
    • [API Governance Solutions ](/solutions/api-governance)API Governance Solutions
    • [Istio API Gateway Integration ](/solutions/istio-gateway)Istio API Gateway Integration
    • [Kubernetes API Management ](/solutions/build-on-kubernetes)Kubernetes API Management
    • [API Gateway: Build vs Buy ](/campaign/secure-api-scalability)API Gateway: Build vs Buy
    • [Kong vs Apigee ](/performance-comparison/kong-vs-apigee)Kong vs Apigee
    • Open Source
    • [Kong Gateway ](https://developer.konghq.com/gateway/install/)Kong Gateway
    • [Kuma ](https://kuma.io/)Kuma
    • [Insomnia ](https://insomnia.rest/)Insomnia
    • [Kong Community ](/community)Kong Community

Kong enables the connectivity layer for the agentic era – securely connecting, governing, and monetizing APIs and AI tokens across any model or cloud.

  • English
  • Japanese
  • Frenchcoming soon
  • Spanishcoming soon
  • Germancoming soon
[Everything is 200 OK](https://status.konghq.com/)
© Kong Inc. 2026
Interaction mode