Skip to content

Block Reference

For the builder’s toolbar, canvas, and palette, see Builder Workspace. This page covers every field the Inspector panel exposes, whether nothing is selected (state-level configuration) or a specific block is selected (block-level fields).

Selecting nothing on the canvas shows state-level configuration:

SectionFields
External AccessLoadBalancer (domain required; optional port and prefix; an “Enable advertisedURL” toggle that reveals its own optional prefix field when checked; optional annotations) or NodePort (host required, offset required, optional annotations). Present by default on all three states of every new gateway. This section edits it but cannot create one, so once removed it can only be recovered by copying a state that still has it or by recreating the gateway. Reads “No external access configured.” when there is none. Also appears as a canvas node (see Builder Workspace).
Replicas0 or more.
ImageApplication image; init container image; pull policy (default / Always / IfNotPresent / Never); a list of pull secret references.
ResourcesRequest and limit CPU and memory, as Kubernetes quantity strings (e.g. 500m, 1Gi).
ProbesLiveness and Readiness, each with Path, Port, Initial delay, Period, Timeout, and Failure threshold.
AdminPort; Bind address; an Expose metrics endpoint toggle; a JVM metrics multi-select (jvm-memory, jvm-gc, jvm-threads, jvm-classloader, jvm-buffer-pool), with any already-set custom values listed alongside.
JVM TuningHeap min/max (Xms/Xmx); GC algorithm (G1GC / ZGC / Parallel); JMX port; a JMX authentication toggle; a free-text Extra opts field, with a live preview of the environment variables this generates.
Pod Template AdvancedService account name; termination grace period; node selector (inline-editable key/value pairs); tolerations (inline-editable list, where each entry has key, operator, value, and effect); security context (runAsUser, runAsGroup, fsGroup, runAsNonRoot).
Env varsAn inline-editable list of name/value pairs.

See Validation Reference for the port ranges and format constraints these accept.

PropertyValue
Name / EndpointThe route’s name and its endpoint address.
Broker identification strategyHost (SNI): reveals a broker hostname pattern field and a Listener TLS section (TLS secret reference, optional JKS password secret reference, optional directory path in container). Port: reveals an Advanced section with an optional broker-pattern override. See Validation Reference for what each strategy requires.
Streaming domainWhich domain this route resolves against. The route’s bootstrap entry is set for you: picking a domain binds the route to that domain’s first bootstrap server, and there’s no field for choosing a different one.
Auth modePassthrough or Swap: swap reveals Secret Store, Client Auth, and Cluster Auth selectors. Once a secret store is selected, a summary line shows its mapping count with an Open store shortcut that jumps to that block’s Inspector.
Fence this routeCheckbox; marks the route fenced for the current state (“Route - fenced” on the canvas) with a fixed scope and a default error code; there’s no separate scope or error-code field to configure.

Client Auth (used on the client-facing side of a route):

TypeFields
mTLSName; optional TLS secret reference; principal mapping rules; SSL client authentication (Required / Requested / None).
SCRAMName; Alter SCRAM credentials toggle; admin secret reference.
SASL PlainName; JAAS secret reference.
OAuthName; JAAS secret reference; OAuth settings (token endpoint, JWKS endpoint, audience, scope, expected issuer, sub claim name); optional principal mapping rules.
NoneName; optional TLS secret reference.

Cluster Auth (used on the upstream side of a swap route):

TypeFields
mTLSName; optional TLS secret reference.
OAuthName; JAAS secret reference; OAuth settings (same fields as Client Auth OAuth); no principal mapping rules on this side.
OAuthBearerName; OAuth Bearer secret reference.
SASL PlainName; JAAS secret reference.
DigestName; JAAS secret reference; this is the upstream analogue of Client Auth’s SCRAM, but without its Alter SCRAM credentials toggle or admin secret reference.
NoneName only.
PropertyValue
Name / Streaming typeDomain name; type is Kafka.
Bootstrap ServersInline-editable list; each entry has a bootstrap ID, endpoint, optional TLS secret reference, and a toggle to skip trust-store verification.
Node ID RangesInline-editable list; each entry has a name, start, and end. Only needed for port-strategy routes, not SNI/host routes.
Adding / removing entriesDirectly in the Inspector, for either list. Selecting a validation issue raised on a bootstrap server or node ID range opens the owning Streaming Domain block.

Provider-specific fields:

ProviderFields
FileName; config secret reference; optional client-credentials reference.
VaultName; config secret reference; optional Vault address, token, prefix, and separator.
AWSName; config secret reference; optional certificate reference; optional client-credentials reference; optional region, access key, secret key, prefix path, and separator.
AzureName; config secret reference; optional certificate reference; optional client-credentials reference; optional Key Vault URL, credential type, tenant ID, client ID, client secret, prefix path, and separator.

Selecting a Secret Store block also shows its Auth mappings: this is where you create and edit them, not just view them. Each row has a Source key (client principal), a Destination key (username/API key), and, for Vault stores only, a Vault path. Add and remove rows directly here; the destination secret itself isn’t stored in the mapping, only the key. The generated Secret command asks for the real value at deploy time.

For a None (unauthenticated) source auth combination, the Source key is locked to ANONYMOUS and can’t be edited, since there is no real client principal to map from, so a new row seeds that value automatically instead of leaving it blank.