DEV Community

Cover image for Integration Digest for September 2026
Stanislav Deviatov
Stanislav Deviatov

Posted on Originally published at linkedin.com

Integration Digest for September 2026

Articles

🔍 API Features as a First-Class Artifact with OpenAPI Overlays

OpenAPI Overlay 1.1 documents model API features as separate, reviewable artifacts: each has metadata, a description, and ordered actions applied to a base specification. The examples add Bar schemas and paths, update Foo, and replace fragile JSON Patch array indexes such as /required/2 with the RFC 9535 selector $.components.schemas.Foo.required[@=="fizz"]. The workflow covers scoping, feature updates, promotion, dependency detection, rebasing, and impact tracing.

🔍 Authenticated Passthrough: Let the Gateway Serve the Metadata

An authenticated MCP gateway can stay stateless. It validates the caller's JWT in AuthorizationGW, challenges with its own RFC 9728 metadata whose resource points at the gateway while authorization_servers stays unchanged, and forwards the upstream bearer token in Authorization. The proxy must strip AuthorizationGW, rewrite resource_metadata on upstream 401 responses, and not buffer text/event-stream bodies. The pattern needs clients that support custom headers, and it does not validate opaque upstream tokens.

🔍 Getting a Row Change Out of Postgres Without Dual-Writing

A transactional outbox commits domain data and an outbox row together. Logical decoding instead streams committed changes through replication slots and decoders such as test_decoding, pgoutput, or wal2json, with no application changes. Topics include peek_changes versus get_changes, snapshot handoff, REPLICA IDENTITY limits, duplicate delivery, and slots that are active but lagging. An idle slot retained unrelated WAL growing from 1,488 bytes to 45 MB in under a minute; pg_replication_slots, wal_status, safe_wal_size, and max_slot_wal_keep_size monitor and contain it.

🔍 MCP Went Stateless: A Security Field Guide to the 2026–07–28 Revision

MCP's 2026-07-28 revision removes protocol sessions and replaces server-initiated requests with MRTR, so the gateway is the one place left for cross-request security state. It tests eight revision-specific vectors: header/body desync, forged or replayed requestState, cache poisoning, input phishing, task authorization, and transport downgrade. mcp-bastion binds requestState to principal, server, and tool with an HMAC and a 300-second TTL, rejects mismatched routing headers with HTTP 400/-32020 HeaderMismatch, clamps ttlMs, and makes public cache scope private on authenticated requests.

🔍 Three Years Later: What Happened to 1,927 Public API Specs

Re-fetching 1,927 APIs from the APIs.guru corpus gave 493 comparable, self-contained contracts. Of these, 48.9% changed structurally, 66.8% of the changed contracts contained breaking changes, and 88.8% of the 161 breaking contracts kept the same major version. Removed endpoints and removed response fields were the most common breaks. The method uses a 20-second fetch with no retries, inlines local references, compares path parameters by position, weights providers equally, and publishes the aggregation code.

🔍 When an iOS Retry Executes an Agent Twice: Building Effectively-Once Tool Workflows With LangGraph, MCP Tasks, Kafka, and App Attest

The iOS client creates a durable operationId before the first request and keeps it across retries. The server enforces a (subject_id, operation_id) uniqueness constraint with a payload hash and INSERT ... ON CONFLICT. The same ID maps to a LangGraph thread and to idempotent @task boundaries, and MCP task handles only retrieve results; they are not deduplication keys. Kafka transactions stay scoped to Kafka. App Attest binds each fresh assertion to the operation and payload, and its monotonic counter detects replay.

🔍 Why a Valid Token Is Not Enough: Securing a Remote MCP Server in Production

A remote MCP server sits behind independent WAF, Entra ID, application, and database gates. The design allowlists Anthropic's 160.79.104.0/21 range, validates MFA-backed JWTs, fails closed when Entra omits groups after the 200-group JWT limit, maps groups to table scopes, and limits the shared database account to SELECT on configured tables. Istio numTrustedProxies is tested with forged X-Forwarded-For, proxy-chain, and X-Real-IP requests. Tagged releases and Argo CD self-heal control policy deployment.

🔍 Your API gateway is not an identity provider, and promoting it to one is a liability

In a seven-hop agent flow, a gateway STS becomes a fourth authorization server next to IDP 0, IDP 1, and IDP 2. Re-minting at step 2.1 and mapping the gateway token into IDP 1 at step 5 can change Bob's sub across issuer scopes, obscure revocation and audit correlation, and open a confused-deputy path. RFC 8693 token exchange supplies subject_token, actor_token, act, and may_act, but it does not establish identity trust across issuers. Controls: RFC 8707 audience binding, client authentication, signing-key custody, issuance-log correlation, and issuer consolidation.

AWS

🔍 Building Enterprise MCP on AWS Bedrock AgentCore: Okta SSO + Trino

An OAuth 2.1 proxy presents itself as the MCP authorization server, relays Okta PKCE with a rewritten redirect_uri, and injects the user's JWT into params._meta. AgentCore Gateway validates the token with CUSTOM_JWT. CredentialExtractMiddleware buffers and replays the body, and InjectAcceptMiddleware restores application/json, text/event-stream to avoid 406 responses. The runtime maps the JWT principal to a Trino connection, and the backend validates independently and allows only read-only SQL.

Apache Camel

🔍 Authorizing what an AI agent may do in Apache Camel

Apache Camel guards AI tool routes with SPIFFE JWT-SVID validation and an OPA Rego policy compiled to WebAssembly. The Java DSL stores the verified SPIFFE ID in the subject exchange property, derives tool from ${routeId}, and uses interceptFrom with evaluationMode=wasm, policyBundle=classpath:opa/tools-bundle.tar.gz, and trusted orderId and amount inputs. A public chatbot is denied refundOrder before refundLedger runs; support-console may refund up to data.limits.refund_max. The bundle removes OPA network failures but turns the policy into a build artifact.

🔍 TypeSafe Jev meets Apache Camel: semantic decisions in Camel routes

camel-semantic maps System One Choice, Noul, and Score results into Camel expressions and predicates, and camel-typesafe-ai adapts Jev requests. The YAML examples set a 5000 ms timeout and max-concurrent-requests=8, reuse classifications through exchange variables, and apply 0.8 thresholds with explicit policies for uncertain results. Semantic categories serve as Aggregate correlation keys with completionSize: 5 and completionTimeout: 60000, and they gate outbound sends or actions; identity and permissions stay deterministic.

🔍 Workload identity in Apache Camel with SPIFFE and SPIRE

The Preview camel-spiffe component uses java-spiffe and the local Workload API for fetchJwtSvid, validateJwtSvid, and fetchX509Svid. JWT validation checks signature, expiry, and audience, exposes CamelSpiffeSpiffeId, and throws JwtSvidException on failure. SpiffeSSLContextParameters gives existing HTTP components live X.509-SVIDs and trust bundles, and acceptedSpiffeIds or acceptAnySpiffeId controls peer authorization. A Docker Compose example uses interceptFrom, per-route properties, second-hop audience tokens, and ten-minute certificate rotation.

Apache Kafka

🔍 Data liberation: Apache Kafka’s native cluster mirroring

KIP-1279 puts cross-cluster replication inside Kafka brokers. MirrorFetcherThread uses the follower fetch protocol to append committed batches byte for byte, so offsets, compression, and topic IDs survive. MirrorMetadataManager drives state from KRaft records, and ClusterMirrorCoordinator keeps mirror state in __mirror_state. Epochs align through reactive, proactive, and periodic bumps plus two-phase truncation; stopping appends ABORT markers and a MirrorPidResetRecord. Commands cover DR failover, reverse mirroring, and migration from ZooKeeper clusters as old as Kafka 2.1.

🔍 Diskless Kafka Isn’t One Technology — It’s Five Different Latency Contracts Wearing the Same Name

Diskless Kafka falls into three groups: leaderless object-storage designs, WAL-cached hybrids, and vendor-specific tiers, with reported P99 write latency from 12.87 ms to 3.5 s. KIP-1150 puts object-storage PUTs on the acknowledgment path; KIP-1176 acknowledges after a local WAL fsync and uploads asynchronously. A Python classify_topic function applies a 2x safety margin and a 500 ms floor for pure object storage to route topics such as orders.events, sessions.windowed, iot.telemetry, and app.logs by latency budget.

🔍 Diskless Kafka: What Happens When Brokers Stop Owning the Data?

Diskless Kafka batches records from several partitions into one object-storage object and rebuilds each partition's log from strongly consistent metadata that assigns offsets and commit status. WarpStream, AutoMQ's shared WAL, Redpanda's L0/L1 reorganization, Aiven's PostgreSQL Batch Coordinator, and Kafka's proposed __diskless_metadata topic with SQLite materialization are compared on acknowledgement latency, object compaction, feature limits, and cross-AZ cost.

🔍 How We Built Automated Capacity Testing for Kafka Consumers

A Kafka capacity-testing layer turns requested load ratios into temporary partition assignments through a priority-aware custom assignor. The scheduler picks one target and raises its share step by step; the Kafka API waits for each rebalance to settle and checks liveness, CPU, memory, lag, throughput, and errors. TTL leases restore normal assignment if the controller fails. Results record requested versus effective ratios, because P partitions limit resolution to about 1/P, and single-partition topics cannot ramp gradually.

🔍 I Enabled Kafka 4.0’s New Rebalance Protocol — My 90-Second Timeout Silently Became 45

With group.protocol=consumer, KIP-848 moves session timing and partition assignment to the group coordinator: group.consumer.session.timeout.ms, group.consumer.heartbeat.interval.ms, and group.consumer.assignors replace client settings. session.timeout.ms, heartbeat.interval.ms, and partition.assignment.strategy become silent no-ops, and a 45-second broker default fenced a consumer tuned for 90 s. Fixes: kafka-configs.sh per-group overrides, group.remote.assignor, --describe --state checks, and the newest 4.x patch, fixing KAFKA-19862 (groups stuck in CompletingRebalance).

🔍 Never lose quorum in Apache Kafka® - and what to do when you do

When a majority of KRaft controller voters is lost, the metadata high watermark freezes, and KIP-853 dynamic quorums cannot remove the lost voters because that change itself needs a quorum. Aiven's recovery takes the longest surviving __cluster_metadata log from any broker or controller, stops the controllers, appends VotersRecord entries offline until one voter remains, restarts it as the sole leader, and re-adds voters online. A shorter log would move broker leadership epochs backwards. KIP-1347 --override-voters fixes stale endpoints, not lost voters.

Azure

🔍 Prove It With curl First: On-Behalf-Of Onto Microsoft Work IQ

Microsoft Entra OBO exchanges a JWT issued for the gateway audience for a Work IQ token, which then authenticates MCP initialize and tools/list requests with HTTP 200. The curl test shows that oid stays stable while the pairwise sub changes, that token B can expire before token A, and that OBO returns every consented Work IQ scope instead of only the requested one. The gateway should cache B until min(exp_A, exp_B) minus a buffer and grant only WorkIQAgent.Ask.

MuleSoft

🔍 How Open Policies in Omni Gateway Secure Federated API Gateways in Minutes

Open policies in Agent Fabric's Omni Gateway apply one policy intent to gateways from several vendors. Scanners catalog APIs from Azure APIM, Apigee, Kong, and AWS in Agent Registry together with their existing policies. A team picks a protection such as IP allowlist, JWT validation, or rate limiting, selects APIs across vendors, and Agent Fabric translates it into each gateway's native configuration. Scanners can start read-only as one policy inventory and later get credentials to enable, disable, or delete vendor policies; Governance Controls flag APIs that do not conform.

SAP

🔍 Setting Up AgentGateway on SAP BTP Kyma

AgentGateway fronts ClusterIP-only MCP servers on Kyma. Its xDS control plane runs without a sidecar, the proxy sidecar accepts PERMISSIVE inbound traffic, and backends use STRICT mTLS restricted by SPIFFE identity. Kubernetes CRDs configure targets, routes, XSUAA JWT validation, and CEL scope checks such as jwt.scope.exists(s, s.endsWith(".mcp.utility")). The guide traces UnknownIssuer, filter_chain_not_found, InvalidIssuer, and PassthroughCluster failures, and explains why DNS-based url values keep Istio mTLS while backendRef can resolve to pod IPs.

Releases

🚀 Apache APISIX 3.19.0

APISIX 3.19.0 adds ws/wss upstreams with ws_handshake, ws_client_frame, ws_upstream_frame, and ws_close plugin phases, plus websocket-proxy payload limits. Stream listeners gain tls_passthrough and multi-SNI snis, and openapi-to-mcp serves cached OpenAPI 3.x or Swagger 2.0 operations over Streamable HTTP or HTTP+SSE. Also new: warm_up_conf, GraphQL complexity and node_quantifier cost strategies, and PUT /apisix/admin/configs?wait=. Breaking changes include upstream TLS verification, OIDC issuer checks, and batch response size limits.

🚀 Camel K 2.11.0

Camel K 2.11.0 makes plain-quarkus the default runtime provider, using Quarkus 3.39.1 and Camel 4.22.0, with non-root execution, Camel health and Prometheus endpoints, and the health trait on by default. Operators gain MultiNamespace reconciliation and allowlists such as MAVEN_REPOSITORIES_ALLOWED and BUILDER_NODE_SELECTOR_ALLOWED_LABELS. IntegrationPlatform is deprecated in favor of IntegrationProfile, and custom tasks, jolokia, Maven profiles, and Maven extensions are deprecated or removed.

🚀 Debezium 3.7

Debezium 3.7 adds reselect.cache.enabled, with heap and RocksDB backends, to cache TOAST and LOB reselections, and introduces io.debezium.time.ExtendedTimestamp as a STRUCT of seconds and nanos. Snapshot progress is exposed through TotalNumberOfReadEventsSeen. A new HTTP notification channel uses notification.enabled.channels and notification.http.url, with retries, timeouts, and SSRF controls. A faster JsonStringEncoder raises one-million-row snapshot throughput by up to 47% on PostgreSQL and 38% on MySQL.

🚀 Kong AI Gateway 2.0

Kong AI Gateway 2.0 GA adds MCP Server Bundling: one route aggregates tools/list results from mapped upstream MCP servers, and the MCP ACL plugin filters discovery and execution. ai-proxy-advanced prices calls from a Konnect catalog with text, audio, image, video, cache-read, and cache-write dimensions, and per-target model.options.input_cost/output_cost takes precedence. Also new: validated Microsoft Foundry azure_service selection, SageMaker OpenAI-to-HuggingFace conversion, Kong Identity Principal policies, and AWS SigV4 authentication from ai-a2a-proxy and ai-mcp-proxy to AgentCore.

🚀 Kong API Gateway 3.16: From Debugging to Billing to Compliance

Kong API Gateway 3.16 lets operators change the log level at runtime on Hybrid Data Planes, with a TTL after which it reverts. Schema-declared CEL expressions fill selected plugin fields from principal, consumer, and token-claim data for ACL, Rate Limiting, and Rate Limiting Advanced. The new OpenMeter-backed Entitlement Enforcement plugin blocks requests when prepaid credits, usage limits, or plan entitlements expire. A separate -fips-140-3 package provides validated cryptography for Gateway 3.14 LTS and 3.16.

🚀 KrakenD 3.0: AI Router, Semantic Cache, and On-the-Fly Stream Manipulation

KrakenD 3.0 moves LLM controls into the gateway. ai/router picks providers by header, CEL gate, or a Not Diamond classifier, with failover; ai/semantic-cache uses ONNX embeddings and Redis vector storage; ai/prompt-guard combines regex, CEL, and external classifiers. New sse, ndjson, and eventstream encodings let JMESPath, response-body, and quota policies process streams message by message. MCP gains protected-resource metadata authentication and audience-based tool filtering. Configurations must move from version: 3 to version: 4.

🚀 NATS Server 2.15

NATS Server 2.15 hands stream and consumer scaling, moves, and peer removal to desired-state reconciliation driven by asset leaders, with replication and catchup checks before any peer-set change. Stream backup v2 stores messages one by one and supports CLI filtering, sequence and time ranges, header edits, and obfuscation without an exclusive lock. Persisted source indexes detect recreated streams and avoid backward scans. Raft batching and dropping redundant per-message syncs raise sync: always replication throughput over 100x and cut tail latency over 40%; default_max_consumers is 1000.

🚀 Tyk AI Studio 2.2

Tyk AI Studio 2.2 routes OpenAI-compatible traffic through one governed endpoint, with explicit, affinity, keyword, embedding, and optional LLM-judge routes, a default fallback, and shadow mode. Semantic caching uses OpenAI-compatible embeddings, in-memory or Redis indexes, and a 0.95 cosine threshold; guardrails inspect prompts, streams, and tool calls. Governance adds RBAC, publish permissions, field-level audit diffs, metadata enforcement, team budgets, MCP cataloging, and failover. The microgateway handles about 9,000 requests/s on 4 vCPUs with sub-millisecond p50 overhead.

Books

📚 AI Agents with MCP: Model Context Protocol for Building Clients, Servers, and End-to-End Agents

Kyle Stratis builds up the Model Context Protocol layer by layer: the protocol structure, MCP clients that make an application agentic (basic and advanced use), MCP servers that expose tools, prompts, and resources along with utilities and client capabilities, testing, securing, and sharing a server, and the transports that connect clients and servers. The last chapter covers build tooling, MCP extensions, and contributing to the specification.

📚 Ultimate Apache Camel for Enterprise AI Integrations: Build AI-Powered Enterprise Integrations with Apache Camel, LangChain4j, RAG, Vector Databases, Neo4j, and LLM Workflows (English Edition)

Apache Camel 4.x routes connect to LangChain4j for chat, agents, embeddings, and prompt patterns, to Qdrant for retrieval and re-ranking, to KServe and TensorFlow Serving for online scoring, and to Neo4j for graph-enriched reasoning. The book builds runnable pipelines for summarization, RAG, contextual routing, audit, and human-in-the-loop workflows, then covers a multimodule Gradle structure, testing AI flows, observability, performance, cost controls, security, privacy, and governance.

Top comments (0)