---
title: "Create Produce Policy for Virtual Cluster"
method: POST
path: "/v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/produce-policies"
tags: ["Event Gateway Virtual Cluster Produce Policies"]
---

# Create Produce Policy for Virtual Cluster

`POST /v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/produce-policies`

Creates a new produce policy associated with the specified Event Gateway virtual cluster.

## Query parameters

- `before` string, uuid
- `after` string, uuid

## Request body

- union — The typed schema of the produce policy to modify it.
  - EventGatewayModifyHeadersPolicyCreate — A policy that modifies headers for requests.
    - `type` 'modify_headers', required — The type name of the policy.
    - `name` string — A unique user-defined name of the policy.
    - `description` string — A human-readable description of the policy.
    - `enabled` boolean — Whether the policy is enabled.
    - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
    - `config` object, required — The configuration of the modify headers policy.
      - `actions` EventGatewayModifyHeaderAction[] — Actions are run in sequential order and act on individual headers.
        - union — An action that modifies a header.
          - EventGatewayModifyHeaderRemoveAction — An action that removes a header by key.
            - `op` 'remove', required
            - `key` string, required — The key of the header to remove.
          - EventGatewayModifyHeaderSetAction — An action that sets a header key and value.
            - `op` 'set', required
            - `key` string, required — The key of the header to set.
            - `value` string, required — The value of the header to set.
    - `condition` string — A string containing the boolean expression that determines whether the policy is applied. When the policy is applied as a child policy of schema_validation, the expression can also reference `record.value` fields.
    - `parent_policy_id` string, uuid — The unique identifier of the parent schema validation policy, if any.
  - EventGatewayProduceSchemaValidationPolicy — A policy that validates produce messages against a schema registry.
    - `type` 'schema_validation', required — The type name of the policy.
    - `name` string — A unique user-defined name of the policy.
    - `description` string — A human-readable description of the policy.
    - `enabled` boolean — Whether the policy is enabled.
    - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
    - `config` union, required — The configuration of the produce schema validation policy.
      - EventGatewayProduceSchemaValidationPolicySchemaRegistryConfig — The configuration of the produce schema validation policy when using a schema registry.
        - `schema_registry` union — A reference to a schema Registry.
          - object
            - `id` string, uuid, required — The unique identifier of the schema registry.
          - object — Reference a schema registry by its unique name.
            - `name` string, required — The unique name of the schema registry.
        - `failure_mode` 'reject' | 'passthrough' | 'mark' — Describes how to handle a failure in a policy applied to produced records. * `reject` - rejects the record batch. * `passthrough` - passes the record silently to the backend cluster even though policy execution failed. * `mark` - passes the record to the backend cluster but marks it with a `kong/policy-failure-<id>` header whose value is the reason for the policy failure (truncated to 512 characters). **Requires a minimum runtime version of `1.2`**.
        - `validate_key` boolean — If true, validate the record key. **Requires a minimum runtime version of `1.2`**.
        - `validate_value` boolean — If true, validate the record value. **Requires a minimum runtime version of `1.2`**.
        - `key_validation_action` 'reject' | 'mark' — Defines a behavior when record key is not valid. * reject - rejects a batch for topic partition. Only available for produce. * mark - marks a record with kong/server header and client ID value to help to identify the clients violating schema.
        - `value_validation_action` 'reject' | 'mark' — Defines a behavior when record value is not valid. * reject - rejects a batch for topic partition. Only available for produce. * mark - marks a record with kong/server header and client ID value to help to identify the clients violating schema.
        - `type` 'confluent_schema_registry', required
      - EventGatewayProduceSchemaValidationPolicyJsonConfig — The configuration of the produce schema validation policy when using JSON parsing without schema.
        - `schema_registry` union — A reference to a schema Registry.
          - object
            - `id` string, uuid, required — The unique identifier of the schema registry.
          - object — Reference a schema registry by its unique name.
            - `name` string, required — The unique name of the schema registry.
        - `failure_mode` 'reject' | 'passthrough' | 'mark' — Describes how to handle a failure in a policy applied to produced records. * `reject` - rejects the record batch. * `passthrough` - passes the record silently to the backend cluster even though policy execution failed. * `mark` - passes the record to the backend cluster but marks it with a `kong/policy-failure-<id>` header whose value is the reason for the policy failure (truncated to 512 characters). **Requires a minimum runtime version of `1.2`**.
        - `validate_key` boolean — If true, validate the record key. **Requires a minimum runtime version of `1.2`**.
        - `validate_value` boolean — If true, validate the record value. **Requires a minimum runtime version of `1.2`**.
        - `key_validation_action` 'reject' | 'mark' — Defines a behavior when record key is not valid. * reject - rejects a batch for topic partition. Only available for produce. * mark - marks a record with kong/server header and client ID value to help to identify the clients violating schema.
        - `value_validation_action` 'reject' | 'mark' — Defines a behavior when record value is not valid. * reject - rejects a batch for topic partition. Only available for produce. * mark - marks a record with kong/server header and client ID value to help to identify the clients violating schema.
        - `type` 'json', required
    - `condition` string — A string containing the boolean expression that determines whether the policy is applied.
  - EventGatewayEncryptPolicy — Encrypts Kafka records or keys using AES_256_GCM. Keys are therefore 256 bits long.
    - `type` 'encrypt', required — The type name of the policy.
    - `name` string — A unique user-defined name of the policy.
    - `description` string — A human-readable description of the policy.
    - `enabled` boolean — Whether the policy is enabled.
    - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
    - `config` EventGatewayEncryptConfig, required — The configuration of the encrypt policy.
      - `failure_mode` 'error' | 'passthrough', required — Describes how to handle failing encryption or decryption. Use `error` if the record should be rejected if encryption or decryption fails. Use `passthrough` to ignore encryption or decryption failure and continue proxying the record.
      - `part_of_record` EncryptionRecordPart[], required — Describes the parts of a record to encrypt.
      - `encryption_key` union, required — The key to use for encryption.
        - EncryptionKeyAWS — The AWS KMS key to use for encryption.
          - `type` 'aws', required
          - `arn` string, required — The AWS KMS key ARN.
        - EncryptionKeyStatic — A static encryption key.
          - `type` 'static', required
          - `key` union, required — A static encryption key reference, either by ID or by value.
            - object — A static encryption key reference by ID.
              - …
            - object — A static encryption key reference by name.
              - …
    - `condition` string — A string containing the boolean expression that determines whether the policy is applied.
  - EventGatewayParsedRecordEncryptFieldsPolicyCreate — Encrypts fields of parsed Kafka records using AES_256_GCM. Keys are therefore 256 bits long. Note this policy can only be used as a child of a `EventGatewayProduceSchemaValidationPolicy` policy. **Requires a minimum runtime version of `1.2`**.
    - `type` 'encrypt_fields', required — The type name of the policy.
    - `name` string — A unique user-defined name of the policy.
    - `description` string — A human-readable description of the policy.
    - `enabled` boolean — Whether the policy is enabled.
    - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
    - `config` EventGatewayParsedRecordEncryptFieldsConfig, required — The configuration of the encrypt parsed record policy.
      - `failure_mode` 'reject' | 'passthrough' | 'mark', required — Describes how to handle a failure in a policy applied to produced records. * `reject` - rejects the record batch. * `passthrough` - passes the record silently to the backend cluster even though policy execution failed. * `mark` - passes the record to the backend cluster but marks it with a `kong/policy-failure-<id>` header whose value is the reason for the policy failure (truncated to 512 characters). **Requires a minimum runtime version of `1.2`**.
      - `encrypt_fields` EventGatewayParsedRecordEncryptionSelector[], required — Selects which fields to encrypt and with what keys.
        - `paths` union, required — Selects which fields of the parsed record to encrypt. A maximum of 50 path entries are allowed.
          - object[]
            - `match` string, required — A field selector. It can select nested fields and array entries. Currently supported are exact matches.
          - string — This expression should evaluate to an array of exact field paths, equivalent to the `match` values in the array variant.
        - `encryption_key` union, required — The key to use for encryption.
          - EncryptionKeyAWS — The AWS KMS key to use for encryption.
            - `type` 'aws', required
            - `arn` string, required — The AWS KMS key ARN.
          - EncryptionKeyStatic — A static encryption key.
            - `type` 'static', required
            - `key` union, required — A static encryption key reference, either by ID or by value.
              - …
    - `condition` string — A string containing the boolean expression that determines whether the policy is applied. When the policy is applied as a child policy of schema_validation, the expression can also reference `record.value` fields.
    - `parent_policy_id` string, uuid, required — The unique identifier of the parent schema validation policy.

## Response `201`

Created

- EventGatewayPolicy — A policy associated with an Event Gateway.
  - `type` string, required — The type name of the policy.
  - `name` string — A unique user-defined name of the policy.
  - `description` string — A human-readable description of the policy.
  - `enabled` boolean — Whether the policy is enabled.
  - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
  - `id` string, uuid, required — The unique identifier of the policy.
  - `config` object — The configuration of the policy.
  - `created_at` string, date-time, required — An ISO-8601 timestamp representation of entity creation date.
  - `parent_policy_id` string, uuid, nullable — The unique identifier of the parent policy, if any.
  - `updated_at` string, date-time, required — An ISO-8601 timestamp representation of entity update date.
  - `condition` string — A string containing the boolean expression that determines whether the policy is applied.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden

---

[API](https://skmtc.net/kong/apis/konnect-api-go-sdk.md) · [All operations](https://skmtc.net/kong/apis/konnect-api-go-sdk/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/kong/konnect-api-go-sdk/revisions/b1ea6bd77dec/schema)
