Lua plugin Offline notice
The Lua plugin has been retired from the API Gateway plugin marketplace due to security risks identified during a security assessment. This topic describes the impact on existing configurations and provides alternative solutions for request and response logging.
Impact
Gateways without the Lua plugin installed — The Lua plugin has been removed from the plugin marketplace. You can no longer install or enable it.
Gateways with the Lua plugin installed — Existing configurations continue to function normally. You can still edit or delete existing Lua plugin rules. To mitigate security risks, migrate to one of the following alternative solutions as soon as possible.
If you previously used the Lua plugin to log request and response content, see the following section to select an alternative and complete the migration.
Alternative solutions for request and response logging
For the request and response logging capability commonly implemented through the Lua plugin, the following two alternative solutions are available:
Item | Solution 1: Request/Response Collection (native gateway capability) | Solution 2: Request Response Log plugin (official WASM plugin) |
Implementation | Native gateway capability with a one-click toggle in the console | Install and configure the official WASM plugin |
Gateway upgrade required | Yes. Upgrade to cloud-native API Gateway engine version 2.1.18 or later, or AI Gateway engine version 2.1.20 or later. | No. Install and configure the plugin without upgrading the gateway. |
Log destination | Recorded in gateway access logs. Delivered to Simple Log Service (SLS) together with access logs for unified query and analysis. | Recorded in plugin logs. |
How to enable | Gateway details page > | Install the Request Response Log plugin from the plugin marketplace and configure it. |
How to choose
If your gateway version meets the requirements and you want request and response content stored and queried together with access logs, use Solution 1: Request/Response Collection. For more information, see Enable Gateway Log Delivery.
If your gateway version is older and you cannot upgrade at this time, use Solution 2: Request Response Log plugin. This solution does not require an upgrade. After you install and configure the plugin, content is recorded in plugin logs.