LICENSEWARE

Kong Mesh licensing

This article is about how Kong Mesh, Kong's service mesh built on the open-source Kuma project, is licensed: the licence file, the pre-bundled licence, the data plane proxy metric, multi-zone counting, expiry behaviour and version support. It does not cover Kong Gateway or Konnect.

On This Page

Kong Mesh is Kong’s service mesh product. Its Enterprise documentation says it “builds on top of Kuma” and adds features such as additional mTLS backends, role-based access control, FIPS 140-2 support and signed images.[2] Kong describes the product as deployable on Kubernetes, in the cloud, on-premises, with containers or on virtual machines, and as installable and manageable through Konnect.[8] The licence is a file that Kong issues; the Customer Agreement treats delivery of Software as complete when Kong provides the download and the licence key.[6] The production Helm guide tells customers to obtain the licence from their Kong Account Manager.[7] Catalog proof: Kong Mesh Enterprise features build on the open-source Kuma project.

Unlike the Konnect rate card, Mesh licensing is a count against the licence file. The documentation states the philosophy briefly: the licence “encourages a pay-as-you-go model” so that the derived value of Kong Mesh is directly associated with real service mesh usage.[1]

Editions

Kong’s documentation describes one licensed form of Kong Mesh. The Enterprise features page lists what it adds on top of Kuma.[2]

Enterprise feature What the documentation says 
Additional mTLS backends HashiCorp Vault CA, Amazon Certificate Manager Private CA and Kubernetes cert-manager CA[2] 
Open Policy Agent support OPA agent included in the data plane proxy sidecar[2] 
Multi-zone authentication Authentication of zone control planes to the global control plane through a Zone Token[2] 
FIPS 140-2 support (v1.2 and later) Envoy FIPS-compliant mode for BoringSSL; not supported on macOS[2] 
Certificate Authority rotation Change of mTLS backend, for example from the built-in CA to a Vault CA[2] 
Role-Based Access Control Restrict access to resources and actions by user role[2] 
Red Hat Universal Base Images Images with the ubi- prefix[2] 
Image signing (v2.7.4 and later) and build provenance (v2.8.0 and later) cosign and slsa-verifier verification[2] 

The documentation does not tie any of these features to a separately priced edition, and it does not describe tiers of Kong Mesh. An inventory should record the version, whether the licence file is the pre-bundled one, and the expiry date. Catalog SKU: Kong Mesh Enterprise.

Metrics

The licence “is based on” two things: the total number of connected data plane proxies across all zones, and the licence expiration date.[1] Catalog proof: Kong Mesh licences are based on connected data plane proxies and expiration date.

A data plane proxy (DPP) is defined as “a standard data plane proxy that is deployed next to your Services, either as a sidecar container or in a virtual machine”. Gateway data plane proxies, zone ingresses and zone egresses are not counted.[1] The documentation gives a sizing formula: “Number of DPPs = Number of Pods + Number of VMs”, measured against the Services to be included in the service meshes.[1] Catalog proof: Gateway data plane proxies, zone ingresses and zone egresses are not counted as DPPs.

Counting / floors

Pre-bundled licence. “Kong Mesh requires a valid license to start the global control plane process. If no license is set, a pre-bundled license is used” with a data plane proxy limit of 10 and an expiration of 30 days.[1] The documentation says to override the default by providing a new licence file that the customer requests from the Kong Mesh team.[1] Catalog proof: Kong Mesh without a licence uses a pre-bundled licence of 10 DPPs for 30 days; Kong Mesh pre-bundled licence.

Multi-zone deployments. The licence is applied only to the global control plane and synchronises automatically to remote control planes.[1] The DPP count is the aggregate across every zone: with a limit of 10 DPPs and 2 zones, a customer can connect 6 in one zone and 4 in the other, but not 10 in each.[1] Catalog proof: In multi-zone Kong Mesh the DPP limit is aggregate across all zones.

Above the limit. Behaviour differs by licence type. “With a valid issued license, a data plane proxy will always be able to join the service mesh, even if you go above the allowed limit to prevent service disruptions.” The control plane then shows a warning in the GUI and in its logs. With the pre-bundled licence, connections above the maximum are refused automatically.[1] Because a valid licence does not block excess proxies, over-deployment is not prevented technically, and the Customer Agreement and Order Form limits remain the contractual position: Subscriptions “are subject to usage limits set out in the Order Form”, and Kong “may invoice Customer for any excess or additional use”.[6] Catalog proof: A valid Kong Mesh licence never blocks a proxy over the limit; the pre-bundled licence does.

Expiry. With an expired or invalid licence the control plane fails to start. If the licence expires while the control plane runs, it keeps running, but a restart fails. The control plane warns in the logs and the GUI when the licence has less than 30 days left.[1] A licence calendar for Mesh should therefore treat the expiry date as a restart risk, not an immediate outage. Catalog proof: An expired Kong Mesh licence prevents control plane restart.

How the file is installed. The licence file can be passed to kumactl with —license-path, supplied to Helm through a Kubernetes secret named kong-mesh-license, or in Universal mode set through KMESH_LICENSE_PATH or KMESH_LICENSE_INLINE.[1] To update, the customer edits the secret or file and restarts the control plane.[1]

Virtualization & partitioning

Kong Mesh counts proxies, not hosts or cores. Because a DPP is “next to your Services” as a sidecar container or in a virtual machine, a Kubernetes cluster with 40 Pods that are in the mesh and 5 virtual machines that run mesh proxies is, on the documentation’s formula, 45 DPPs, wherever the nodes run.[1] The documents retrieved contain no processor, core, sub-capacity or hard-partitioning rule of the kind described in virtualization and partitioning.

Cloud / BYOL

The Product-Specific Terms group Kong Mesh with Kong API Gateway Enterprise and the on-prem Kong AI Gateway under a single verification clause. At Kong’s request the customer promptly provides a Software-generated report specified in the Documentation, or data reasonably requested by Kong, to verify use of the Software and purchased usage limits.[5] The customer may disable the Software feature that sends Usage Data to Kong, in which case Kong will not collect Usage Data automatically.[5] The Customer Agreement permits installing the Software only in the Customer Network Environment, which includes the customer’s own servers and servers of third-party cloud providers.[6] Catalog proof: Customer must provide a Software-generated report on request.

Programs

  • Kong Mesh LTS releases. Starting from version 2.13, Kong plans one LTS release per year in January, supported for 2 years from release, so adjacent LTS releases overlap by 1 year. Kong plans four minor versions a year, in January, April, July and October.[3] The support table lists 2.13.x (LTS, released 2025-12-22, end of full support 2027-12-22) and 2.7.x (LTS, end of full support 2026-10-19), among other lines.[3] Catalog proof: Kong Mesh plans one LTS per year, supported for 2 years.
  • Contractual support period. The Support and Maintenance Policy says Kong supports Kong Mesh releases for 12 months from the first release of the major version, then assists for a further 6 months to upgrade to the most recent major version.[4] Catalog proof: Kong Mesh releases are supported for 12 months from the major version release. The contract measures from the first release of the major version, while the support policy page lists an end-of-full-support date for each minor version and LTS line, so a customer should read both against its Order Form.

Out of scope

This article does not cover the open-source Kuma project’s own licence, partner-resold Mesh subscriptions, or the price of a Mesh subscription, which Kong does not publish. It also does not cover Mesh in Konnect beyond noting that Kong describes Konnect as an installation and management route.[8]

References

  1. Kong Mesh license | Kong DocsLicence deployment, pre-bundled licence, licensed metrics and behaviours. Undated.Retrieved 2026-10-08.
  2. Enterprise features | Kong Mesh DocsFeatures Kong Mesh adds on top of Kuma. Undated.Retrieved 2026-10-08.
  3. Kong Mesh version support policy | Kong DocsRelease cadence, LTS plan and supported versions table. Undated.Retrieved 2026-10-08.
  4. Kong Support and Maintenance Policys.7(iii) Kong Mesh support periods. Last updated August 31, 2026.Effective 2026-08-31. Retrieved 2026-10-08.
  5. Kong Product-Specific TermsVerification and telemetry terms for Kong Mesh. Last updated September 1, 2026.Effective 2026-09-01. Retrieved 2026-10-08.
  6. Kong Customer Agreements.2.1 licence grant; s.8.2 delivery of licence key. Last updated August 10, 2026.Effective 2026-08-10. Retrieved 2026-10-08.
  7. Deploy Kong Mesh in production with Helm | Kong DocsProduction Helm values; licence is obtained from the Kong account manager. Undated.Retrieved 2026-10-08.
  8. Kong Mesh (product page)Product description; installation and management through Konnect.Retrieved 2026-10-08.

See also

Catalog Rows Cited

10Rules1SKUs1Metrics2Programs

Esc