Validation Reference
Validation runs continuously per state as you edit. Error-severity issues block YAML download, both from the builder toolbar and from the Deploy tab; warnings never block Save or download. The builder additionally refuses to download while you have unsaved changes, because the download always renders the last saved gateway. The Deploy tab and the detail page have no unsaved-changes gate, since they only ever show saved state.
Blocking Errors
Section titled “Blocking Errors”Route
- Duplicate route, streaming domain, secret store, or per-side auth name within a state.
- A route referencing a streaming domain that doesn’t exist in that state, or a bootstrap ID that isn’t on the domain the route references. The second case is checked against that domain only, so a bootstrap ID that exists elsewhere in the state still errors.
- A swap route missing a secret store, or referencing one that isn’t defined in the state.
- A swap route missing a client auth or cluster auth reference, referencing one that no longer exists, or referencing a block of the wrong side (a client auth used as cluster auth, or vice versa).
- A passthrough route that still carries auth or secret-store references, clear them, or switch the route to swap.
Streaming Domain
- Duplicate name.
- No bootstrap server configured.
External Access
- LoadBalancer missing a domain, or with an out-of-range port.
- NodePort missing a host, or missing/negative/non-integer offset.
Advanced State Configuration
- Invalid image pull policy.
- Invalid Kubernetes resource quantities (e.g. a malformed
500mor1Givalue). - A probe port, the
admin.port, or thejvmTuning.jmxPortoutside the 1-65535 range. Non-positive values are also rejected, but the Inspector clears any of those three that you set to zero or below, so in practice that case only reaches validation through a direct API write or a gateway saved by an older version. - A JVM
heapMinorheapMaxthat isn’t in JVM short form (e.g.512m,1g,2048k).
Unresolved Placeholders
Literal <...>-style tokens (e.g. <bootstrap-server>:9092) seeded by templates or fresh palette drops are flagged as errors in the fields this check covers:
- Bootstrap server endpoints and their TLS secret references.
- Route endpoints, broker hostname patterns, and listener TLS secret references.
- Auth TLS, JAAS, admin, and OAuth Bearer secret references, plus the six OAuth settings.
- Secret store config, client credentials, and certificate references, plus the Vault address and prefix.
- The external access load balancer domain and NodePort host.
$(nodeId) expansion tokens contain no angle brackets and are never flagged.
Host/SNI vs. Port Strategy
Section titled “Host/SNI vs. Port Strategy”A route’s broker identification strategy determines what else it needs:
| Strategy | Requires |
|---|---|
| Host (SNI) | A TLS secret reference on the listener, and a broker hostname pattern such as broker$(nodeId).gateway.example.com. Selecting this strategy seeds the pattern with an angle-bracket placeholder for the domain, which is an error until you replace it with your real hostname. |
| Port | The route’s streaming domain must have node ID ranges defined. |
The toolbar’s issue badge counts every state’s issues, not just the state you are on, so it stays visible until all three states are clean. The per-state counts are the small red and amber badges on the Init, Fenced, and Switchover tabs. When no state has an issue, the badge disappears and the toolbar shows just Preview, Download, and Save, as below. That’s the state to aim for before downloading or deploying:

Non-Blocking Warnings
Section titled “Non-Blocking Warnings”Secret and Auth Mapping Completeness
- A swap route’s secret store has no auth mappings: its generated Secret will contain only placeholders.
- A File store’s auth mapping has no destination key: the generated credential entry will contain a placeholder. (Vault/AWS/Azure mappings are exempt, their real mapping lives in the external store, not a generated Secret.)
Secret Store Connection Fields File stores have no connection fields of their own and are exempt. For Vault, AWS, and Azure stores, a missing connection field warns that the generated config Secret will contain a placeholder in its place:
- Vault: address, auth token.
- AWS: region; access key and secret access key (only checked once either half of the pair is set, both blank is a valid IAM-role configuration).
- Azure: Key Vault URL, tenant ID, client ID, client secret.
SCRAM Registration
scram-registration-route is only needed in Init, for credential pre-registration before switchover. Leaving or moving it into Fenced or Switchover warns that it has no effect there and can be removed (keep it in Init). The check only runs on a state that also holds a client SCRAM auth block, so a registration route copied into a state without one is not flagged.
JVM Tuning
A JVM jmxPort that collides with the admin port warns of a runtime bind conflict, without blocking download.
Cross-State Sanity Checks
- Fenced state has no fenced route, so producers won’t actually be blocked during the migration window.
- Switchover state still has a fenced route, so clients remain blocked after cutover completes.
- Every one of Switchover’s bootstrap endpoints already appears in Init’s, so cutover wouldn’t introduce a new endpoint. This isn’t a full-set match: it fires even if Switchover has just one endpoint, as long as that one is also in Init’s set.
- Switchover declares no destination bootstrap endpoint at all, so there is no cluster to cut over to.
- Switchover has no routes at all, so there is nothing to cut over.
- Switchover still routes to the same streaming domain as Init, so traffic never cuts over. Routes are paired by name: Switchover routes whose names don’t appear in Init are ignored, and the warning fires only when every remaining pair still points at Init’s domain. Renaming a route in Switchover takes it out of this comparison deliberately, not as an oversight:
kubectl applyreplaces the spec wholesale, so route names are not a mapping key between applies, and a renamed Switchover route that targets the destination and carries no fence still cuts over correctly. The endpoint check above covers a different hole, a renamed streaming domain whose bootstrap entries still hold the source addresses.