You can change log levels dynamically, without restarting Kong Gateway, using the Admin API or the Konnect API.
A dynamic log level change is never persisted to kong.conf.
If a node restarts while an override is active, it reverts to the log level set in kong.conf, and the ttl doesn’t carry over.
Alternatively, you can configure log levels using the log_level parameter in the kong.conf file, which will persist. However, this requires you to restart Kong Gateway.
Use the following settings and endpoints for log levels in traditional mode and hybrid mode control planes:
In Konnect, you can only view the control plane log level. You can’t adjust it dynamically.
|
Use case
|
Setting or endpoint
|
|
View current log level v3.16+
|
GET /control-planes/{controlPlaneId}/nodes: View the log_level field in the response.
|
In hybrid mode, you can temporarily change the log level of data plane nodes from the control plane.
This is a runtime-only, on-demand override for debugging. It doesn’t persist, and it isn’t a substitute for permanent configuration in kong.conf.
Note: Dynamic log levels are supported for data plane nodes running in hybrid mode. DB-less deployments are not supported.
|
Use case
|
Setting or endpoint
|
|
Modify the log level for one or more data plane nodes.
|
POST /debug/cluster/data-planes/log-level-operations
|
|
List dynamic log level operations.
|
GET /debug/cluster/data-planes/log-level-operations
|
|
Get the status of a dynamic log level operation.
|
GET /debug/cluster/data-planes/log-level-operations/{id}
|
|
List the per-node results of a dynamic log level operation.
|
GET /debug/cluster/data-planes/log-level-operations/{id}/results
|
|
Get the result for one data plane node in an operation.
|
GET /debug/cluster/data-planes/log-level-operations/{id}/results/{node_id}
|
|
Use case
|
Setting or endpoint
|
|
Modify the log level for one or more data plane nodes.
|
POST /control-planes/{controlPlaneId}/nodes/log-level-operations
|
|
List dynamic log level operations.
|
GET /control-planes/{controlPlaneId}/nodes/log-level-operations
|
|
Get the status of a dynamic log level operation.
|
GET /control-planes/{controlPlaneId}/nodes/log-level-operations/{operationId}
|
|
List the per-node results of a dynamic log level operation.
|
GET /control-planes/{controlPlaneId}/nodes/log-level-operations/{operationId}/results
|
|
Get the result for one data plane node in an operation.
|
GET /control-planes/{controlPlaneId}/nodes/log-level-operations/{operationId}/results/{nodeId}
|
When you create an operation, you specify a log_level, a target (all data plane nodes, or a list of node_ids), and an optional ttl in seconds.
The data plane applies the new log level and automatically reverts to the previous level when the ttl expires.
Note: The ttl must be an integer between 10 and 3600 seconds. If you don’t set one, it defaults to 600 seconds (10 minutes). The 10 second minimum exists because data planes poll the control plane for updates every 5 seconds, so the ttl needs to cover at least two poll intervals for the node to reliably apply the change before it expires.
A dynamic log level operation reports one of the following statuses:
|
Status
|
Description
|
in_progress
|
The control plane accepted the operation. The data plane hasn’t applied it yet.
|
applied
|
The data plane applied the log level change.
|
reverted
|
The ttl expired, and the data plane reverted to its configured log level.
|
superseded
|
A newer operation replaced this one before it finished, because it targeted the same node.
|
failed
|
The data plane failed to apply the log level change.
|
unsupported
|
The data plane is on an older Kong Gateway version that doesn’t support dynamic log levels.
|
To see a data plane’s current effective log level, and the details of any active override, get its node information by sending the following request from a control plane:
curl -X GET "http://localhost:8001/clustering/data-planes" \
--no-progress-meter --fail-with-body \
-H "Accept: application/json"\
-H "Content-Type: application/json"
curl -X GET "https://us.api.konghq.com/v2/control-planes/$CONTROL_PLANE_ID/nodes" \
--no-progress-meter --fail-with-body \
-H "Authorization: Bearer $KONNECT_TOKEN"
Each node has a log_level field with its current effective level.
Reading the current log level is available to any Control Plane Viewer. You can also use the Debugger to do this directly from the Konnect UI.
Creating or changing a dynamic log level operation is a privileged action and requires Control Plane Admin permissions or higher.