---
title: "Update Produce Policy for Virtual Cluster"
method: PUT
path: "/v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/produce-policies/{policyId}#Encrypt"
tags: ["Event Gateway Virtual Cluster Produce Policies"]
---

# Update Produce Policy for Virtual Cluster

`PUT /v1/event-gateways/{gatewayId}/virtual-clusters/{virtualClusterId}/produce-policies/{policyId}#Encrypt`

Updates an existing produce policy associated with the specified Event Gateway virtual cluster.

## Request body

- EventGatewayEncryptPolicy — Encrypts Kafka records or keys using AES_256_GCM. Keys are therefore 256 bits long.
  - `type` 'encrypt', required — The type name of the policy.
  - `name` string — A unique user-defined name of the policy.
  - `description` string — A human-readable description of the policy.
  - `enabled` boolean — Whether the policy is enabled.
  - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
  - `config` EventGatewayEncryptConfig, required — The configuration of the encrypt policy.
    - `failure_mode` 'error' | 'passthrough', required — Describes how to handle failing encryption or decryption. Use `error` if the record should be rejected if encryption or decryption fails. Use `passthrough` to ignore encryption or decryption failure and continue proxying the record.
    - `part_of_record` EncryptionRecordPart[], required — Describes the parts of a record to encrypt.
    - `encryption_key` union, required — The key to use for encryption.
      - EncryptionKeyAWS — The AWS KMS key to use for encryption.
        - `type` 'aws', required
        - `arn` string, required — The AWS KMS key ARN.
      - EncryptionKeyStatic — A static encryption key.
        - `type` 'static', required
        - `key` EncryptionKeyStaticReference, required — A static encryption key reference by ID.
          - `id` string, uuid, required — The ID of the static key defined in the key source.
  - `condition` string — A string containing the boolean expression that determines whether the policy is applied.

## Response `200`

Updated produce policy object.

- EventGatewayPolicy — A policy associated with an Event Gateway.
  - `type` string, required — The type name of the policy.
  - `name` string — A unique user-defined name of the policy.
  - `description` string — A human-readable description of the policy.
  - `enabled` boolean — Whether the policy is enabled.
  - `labels` Labels — Labels store metadata of an entity that can be used for filtering an entity list or for searching across entity types. Keys must be of length 1-63 characters, and cannot start with "kong", "konnect", "mesh", "kic", or "_".
  - `id` string, uuid, required — The unique identifier of the policy.
  - `config` object, nullable — The configuration of the policy.
  - `created_at` string, date-time, required — An ISO-8601 timestamp representation of entity creation date.
  - `parent_policy_id` string, uuid, nullable — The unique identifier of the parent policy, if any.
  - `updated_at` string, date-time, required — An ISO-8601 timestamp representation of entity update date.
  - `condition` string — A string containing the boolean expression that determines whether the policy is applied.

## Other responses

- `400` — Bad Request
- `401` — Unauthorized
- `403` — Forbidden

---

[API](https://skmtc.net/kong/apis/konnect-api.md) · [All operations](https://skmtc.net/kong/apis/konnect-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/kong/konnect-api/revisions/06734a9c491f/schema)
