Lua plugin Offline notice

更新时间: 2026-07-08 15:47:34

The Lua plugin has been retired from the API Gateway plugin marketplace due to security risks identified during a security assessment. This topic describes the impact on existing configurations and provides alternative solutions for request and response logging.

Impact

  • Gateways without the Lua plugin installed — The Lua plugin has been removed from the plugin marketplace. You can no longer install or enable it.

  • Gateways with the Lua plugin installed — Existing configurations continue to function normally. You can still edit or delete existing Lua plugin rules. To mitigate security risks, migrate to one of the following alternative solutions as soon as possible.

Note

If you previously used the Lua plugin to log request and response content, see the following section to select an alternative and complete the migration.

Alternative solutions for request and response logging

For the request and response logging capability commonly implemented through the Lua plugin, the following two alternative solutions are available:

Item

Solution 1: Request/Response Collection (native gateway capability)

Solution 2: Request Response Log plugin (official WASM plugin)

Implementation

Native gateway capability with a one-click toggle in the console

Install and configure the official WASM plugin

Gateway upgrade required

Yes. Upgrade to cloud-native API Gateway engine version 2.1.18 or later, or AI Gateway engine version 2.1.20 or later.

No. Install and configure the plugin without upgrading the gateway.

Log destination

Recorded in gateway access logs. Delivered to Simple Log Service (SLS) together with access logs for unified query and analysis.

Recorded in plugin logs.

How to enable

Gateway details page > Access Log Delivery Configuration > Request/Response Collection

Install the Request Response Log plugin from the plugin marketplace and configure it.

How to choose

  • If your gateway version meets the requirements and you want request and response content stored and queried together with access logs, use Solution 1: Request/Response Collection. For more information, see Enable Gateway Log Delivery.

  • If your gateway version is older and you cannot upgrade at this time, use Solution 2: Request Response Log plugin. This solution does not require an upgrade. After you install and configure the plugin, content is recorded in plugin logs.

上一篇: Announcement on the Public Preview of the Serverless Edition of Cloud-native API Gateway 下一篇: Environment management feature deprecation