Skip to content
2023 API Summit Hackathon: Experiment with AI for APIs (August 28 - September 27) Learn More →
Kong Logo | Kong Docs Logo
search
  • We're Hiring!
  • Docs
    • Kong Gateway
      Lightweight, fast, and flexible cloud-native API gateway
      Kong Konnect
      Single platform for SaaS end-to-end connectivity
      Kong Mesh
      Enterprise service mesh based on Kuma and Envoy
      decK
      Helps manage Kong’s configuration in a declarative fashion
      Kong Ingress Controller
      Works inside a Kubernetes cluster and configures Kong to proxy traffic
      Insomnia
      Collaborative API development platform
      Kuma
      Open-source distributed control plane with a bundled Envoy Proxy integration
      Docs Contribution Guidelines
      Want to help out, or found an issue in the docs and want to let us know?
  • API Specs
  • Plugin Hub
    • Explore the Plugin Hub
      View all plugins View all plugins View all plugins arrow image
    • Functionality View all View all arrow image
      View all plugins
      Authentication's icon
      Authentication
      Protect your services with an authentication layer
      Security's icon
      Security
      Protect your services with additional security layer
      Traffic Control's icon
      Traffic Control
      Manage, throttle and restrict inbound and outbound API traffic
      Serverless's icon
      Serverless
      Invoke serverless functions in combination with other plugins
      Analytics & Monitoring's icon
      Analytics & Monitoring
      Visualize, inspect and monitor APIs and microservices traffic
      Transformations's icon
      Transformations
      Transform request and responses on the fly on Kong
      Logging's icon
      Logging
      Log request and response data using the best transport for your infrastructure
  • Support
  • Community
  • Kong Academy
Get a Demo Start Free Trial
Kong Gateway
3.4.x (latest)
  • Home icon
  • Kong Gateway
  • Plugin Development
  • PDK
  • kong.service
github-edit-pageEdit this page
report-issueReport an issue
  • Kong Gateway
  • Kong Konnect
  • Kong Mesh
  • Plugin Hub
  • decK
  • Kong Ingress Controller
  • Insomnia
  • Kuma

  • Docs contribution guidelines
  • 3.4.x (latest)
  • 3.3.x
  • 3.2.x
  • 3.1.x
  • 3.0.x
  • 2.8.x
  • 2.7.x
  • 2.6.x
  • Archive (pre-2.6)
enterprise-switcher-icon Switch to OSS
On this pageOn this page
  • kong.service.set_upstream(host)
  • kong.service.set_target(host, port)
  • kong.service.set_tls_cert_key(chain, key)
  • kong.service.set_tls_verify(on)
  • kong.service.set_tls_verify_depth(depth)
  • kong.service.set_tls_verify_store(store)

kong.service

The service module contains a set of functions to manipulate the connection aspect of the request to the Service, such as connecting to a given host, IP address/port, or choosing a given Upstream entity for load-balancing and healthchecking.

kong.service.set_upstream(host)

Sets the desired Upstream entity to handle the load-balancing step for this request. Using this method is equivalent to creating a Service with a host property equal to that of an Upstream entity (in which case, the request would be proxied to one of the Targets associated with that Upstream).

The host argument should receive a string equal to the name of one of the Upstream entities currently configured.

Phases

  • access

Parameters

  • host (string):

Returns

  1. boolean|nil: true on success, or nil if no upstream entities where found

  2. string|nil: An error message describing the error if there was one.

Usage

local ok, err = kong.service.set_upstream("service.prod")
if not ok then
  kong.log.err(err)
  return
end

kong.service.set_target(host, port)

Sets the host and port on which to connect to for proxying the request. Using this method is equivalent to ask Kong to not run the load-balancing phase for this request, and consider it manually overridden. Load-balancing components such as retries and health-checks will also be ignored for this request.

The host argument expects the hostname or IP address of the upstream server, and the port expects a port number.

Phases

  • access

Parameters

  • host (string):
  • port (number):

Usage

kong.service.set_target("service.local", 443)
kong.service.set_target("192.168.130.1", 80)

kong.service.set_tls_cert_key(chain, key)

Sets the client certificate used while handshaking with the Service.

The chain argument is the client certificate and intermediate chain (if any) returned by functions such as ngx.ssl.parse_pem_cert.

The key argument is the private key corresponding to the client certificate returned by functions such as ngx.ssl.parse_pem_priv_key.

Phases

  • rewrite, access, balancer, preread

Parameters

  • chain (cdata): The client certificate chain
  • key (cdata): The client certificate private key

Returns

  1. boolean|nil: true if the operation succeeded, nil if an error occurred

  2. string|nil: An error message describing the error if there was one

Usage

local chain = assert(ssl.parse_pem_cert(cert_data))
local key = assert(ssl.parse_pem_priv_key(key_data))

local ok, err = kong.service.set_tls_cert_key(chain, key)
if not ok then
  -- do something with error
end

kong.service.set_tls_verify(on)

Sets whether TLS verification is enabled while handshaking with the Service.

The on argument is a boolean flag, where true means upstream verification is enabled and false disables it.

This call affects only the current request. If the trusted certificate store is not set already (via proxy_ssl_trusted_certificate or kong.service.set_upstream_ssl_trusted_store), then TLS verification will always fail with “unable to get local issuer certificate” error.

Phases

  • rewrite, access, balancer, preread

Parameters

  • on (boolean): Whether to enable TLS certificate verification for the current request

Returns

  1. boolean|nil: true if the operation succeeded, nil if an error occurred

  2. string|nil: An error message describing the error if there was one

Usage

local ok, err = kong.service.set_tls_verify(true)
if not ok then
  -- do something with error
end

kong.service.set_tls_verify_depth(depth)

Sets the maximum depth of verification when validating upstream server’s TLS certificate.

This call affects only the current request. For the depth to be actually used the verification has to be enabled with either the proxy_ssl_verify directive or using the kong.service.set_tls_verify function.

Phases

  • rewrite, access, balancer, preread

Parameters

  • depth (number): Depth to use when validating. Must be non-negative

Returns

  1. boolean|nil: true if the operation succeeded, nil if an error occurred

  2. string|nil: An error message describing the error if there was one

Usage

local ok, err = kong.service.set_tls_verify_depth(3)
if not ok then
  -- do something with error
end

kong.service.set_tls_verify_store(store)

Sets the CA trust store to use when validating upstream server’s TLS certificate.

This call affects only the current request. For the store to be actually used the verification has to be enabled with either the proxy_ssl_verify directive or using the kong.service.set_tls_verify function.

The resty.openssl.x509.store object can be created by following examples from the Kong/lua-kong-nginx-module repo.

Phases

  • rewrite, access, balancer, preread

Parameters

  • store (table): resty.openssl.x509.store object to use

Returns

  1. boolean|nil: true if the operation succeeded, nil if an error occurred

  2. string|nil: An error message describing the error if there was one

Usage

local store = require("resty.openssl.x509.store")
local st = assert(store.new())
-- st:add(...certificate)

local ok, err = kong.service.set_tls_verify_store(st)
if not ok then
  -- do something with error
end
Thank you for your feedback.
Was this page useful?
Too much on your plate? close cta icon
More features, less infrastructure with Kong Konnect. 1M requests per month for free.
Try it for Free
  • Kong
    THE CLOUD CONNECTIVITY COMPANY

    Kong powers reliable digital connections across APIs, hybrid and multi-cloud environments.

    • Company
    • Customers
    • Events
    • Investors
    • Careers Hiring!
    • Partners
    • Press
    • Contact
  • Products
    • Kong Konnect
    • Kong Gateway
    • Kong Mesh
    • Get Started
    • Pricing
  • Resources
    • eBooks
    • Webinars
    • Briefs
    • Blog
    • API Gateway
    • Microservices
  • Open Source
    • Install Kong Gateway
    • Kong Community
    • Kubernetes Ingress
    • Kuma
    • Insomnia
  • Solutions
    • Decentralize
    • Secure & Govern
    • Create a Dev Platform
    • API Gateway
    • Kubernetes
    • Service Mesh
Star
  • Terms•Privacy
© Kong Inc. 2023