Block Reference
For the builder’s toolbar, canvas, and palette, see Builder Workspace. This page covers every field the Inspector panel exposes, whether nothing is selected (state-level configuration) or a specific block is selected (block-level fields).
State-Level Configuration
Section titled “State-Level Configuration”Selecting nothing on the canvas shows state-level configuration:
| Section | Fields |
|---|---|
| External Access | LoadBalancer (domain required; optional port and prefix; an “Enable advertisedURL” toggle that reveals its own optional prefix field when checked; optional annotations) or NodePort (host required, offset required, optional annotations). Present by default on all three states of every new gateway. This section edits it but cannot create one, so once removed it can only be recovered by copying a state that still has it or by recreating the gateway. Reads “No external access configured.” when there is none. Also appears as a canvas node (see Builder Workspace). |
| Replicas | 0 or more. |
| Image | Application image; init container image; pull policy (default / Always / IfNotPresent / Never); a list of pull secret references. |
| Resources | Request and limit CPU and memory, as Kubernetes quantity strings (e.g. 500m, 1Gi). |
| Probes | Liveness and Readiness, each with Path, Port, Initial delay, Period, Timeout, and Failure threshold. |
| Admin | Port; Bind address; an Expose metrics endpoint toggle; a JVM metrics multi-select (jvm-memory, jvm-gc, jvm-threads, jvm-classloader, jvm-buffer-pool), with any already-set custom values listed alongside. |
| JVM Tuning | Heap min/max (Xms/Xmx); GC algorithm (G1GC / ZGC / Parallel); JMX port; a JMX authentication toggle; a free-text Extra opts field, with a live preview of the environment variables this generates. |
| Pod Template Advanced | Service account name; termination grace period; node selector (inline-editable key/value pairs); tolerations (inline-editable list, where each entry has key, operator, value, and effect); security context (runAsUser, runAsGroup, fsGroup, runAsNonRoot). |
| Env vars | An inline-editable list of name/value pairs. |
See Validation Reference for the port ranges and format constraints these accept.
| Property | Value |
|---|---|
| Name / Endpoint | The route’s name and its endpoint address. |
| Broker identification strategy | Host (SNI): reveals a broker hostname pattern field and a Listener TLS section (TLS secret reference, optional JKS password secret reference, optional directory path in container). Port: reveals an Advanced section with an optional broker-pattern override. See Validation Reference for what each strategy requires. |
| Streaming domain | Which domain this route resolves against. The route’s bootstrap entry is set for you: picking a domain binds the route to that domain’s first bootstrap server, and there’s no field for choosing a different one. |
| Auth mode | Passthrough or Swap: swap reveals Secret Store, Client Auth, and Cluster Auth selectors. Once a secret store is selected, a summary line shows its mapping count with an Open store shortcut that jumps to that block’s Inspector. |
| Fence this route | Checkbox; marks the route fenced for the current state (“Route - fenced” on the canvas) with a fixed scope and a default error code; there’s no separate scope or error-code field to configure. |
Client Auth and Cluster Auth
Section titled “Client Auth and Cluster Auth”Client Auth (used on the client-facing side of a route):
| Type | Fields |
|---|---|
| mTLS | Name; optional TLS secret reference; principal mapping rules; SSL client authentication (Required / Requested / None). |
| SCRAM | Name; Alter SCRAM credentials toggle; admin secret reference. |
| SASL Plain | Name; JAAS secret reference. |
| OAuth | Name; JAAS secret reference; OAuth settings (token endpoint, JWKS endpoint, audience, scope, expected issuer, sub claim name); optional principal mapping rules. |
| None | Name; optional TLS secret reference. |
Cluster Auth (used on the upstream side of a swap route):
| Type | Fields |
|---|---|
| mTLS | Name; optional TLS secret reference. |
| OAuth | Name; JAAS secret reference; OAuth settings (same fields as Client Auth OAuth); no principal mapping rules on this side. |
| OAuthBearer | Name; OAuth Bearer secret reference. |
| SASL Plain | Name; JAAS secret reference. |
| Digest | Name; JAAS secret reference; this is the upstream analogue of Client Auth’s SCRAM, but without its Alter SCRAM credentials toggle or admin secret reference. |
| None | Name only. |
Streaming Domain
Section titled “Streaming Domain”| Property | Value |
|---|---|
| Name / Streaming type | Domain name; type is Kafka. |
| Bootstrap Servers | Inline-editable list; each entry has a bootstrap ID, endpoint, optional TLS secret reference, and a toggle to skip trust-store verification. |
| Node ID Ranges | Inline-editable list; each entry has a name, start, and end. Only needed for port-strategy routes, not SNI/host routes. |
| Adding / removing entries | Directly in the Inspector, for either list. Selecting a validation issue raised on a bootstrap server or node ID range opens the owning Streaming Domain block. |
Secret Store
Section titled “Secret Store”Provider-specific fields:
| Provider | Fields |
|---|---|
| File | Name; config secret reference; optional client-credentials reference. |
| Vault | Name; config secret reference; optional Vault address, token, prefix, and separator. |
| AWS | Name; config secret reference; optional certificate reference; optional client-credentials reference; optional region, access key, secret key, prefix path, and separator. |
| Azure | Name; config secret reference; optional certificate reference; optional client-credentials reference; optional Key Vault URL, credential type, tenant ID, client ID, client secret, prefix path, and separator. |
Selecting a Secret Store block also shows its Auth mappings: this is where you create and edit them, not just view them. Each row has a Source key (client principal), a Destination key (username/API key), and, for Vault stores only, a Vault path. Add and remove rows directly here; the destination secret itself isn’t stored in the mapping, only the key. The generated Secret command asks for the real value at deploy time.
For a None (unauthenticated) source auth combination, the Source key is locked to ANONYMOUS and can’t be edited, since there is no real client principal to map from, so a new row seeds that value automatically instead of leaving it blank.