For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.
Configuration schema explorer
Explore the agentgateway standalone configuration schema interactively, including nested fields and validation details.
Generated from the agentgateway JSON schema.
- config
- enableIpv6boolean
- dns
- lookupFamilystring
- edns0boolean
- localXdsPathstring
- modelCatalog
- *filestring
- database
- *urlstring
- maxConnectionsinteger
- storage
- modestring
- caAddressstring
- caAuthTokenstring
- xdsAddressstring
- xdsAuthTokenstring
- spiffe
- endpointstring
- namespacestring
- gatewaystring
- trustDomainstring
- additionalTrustDomainsstring
- skipValidateTrustDomainboolean
- serviceAccountstring
- clusterIdstring
- networkstring
- adminAddrstring
- standardAttributes
- userstring
- groupstring
- statsAddrstring
- histogramsstring
- readinessAddrstring
- session
- *keystring
- mcp
- sessionTtlstring
- sensitiveHeadersstring[]
- customFunctionsstring
- connectionTerminationDeadlinestring
- connectionMinTerminationDeadlinestring
- workerThreadsstring|integer
- tracing
- otlpEndpointstring
- headersobject
- otlpProtocolstring
- fields
- removestring[]
- addobject
- randomSamplingstring|number|boolean
- clientSamplingstring|number|boolean
- pathstring
- logging
- filterstring
- fields
- removestring[]
- addobject
- levelstring[]
- formatstring
- database
- *urlstring
- maxConnectionsinteger
- metrics
- removestring[]
- fields
- addobject
- backend
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- poolIdleTimeoutstring
- poolMaxSizeinteger
- h2KeepaliveIntervalstring
- h2KeepaliveTimeoutstring
- hbone
- windowSizeinteger
- connectionWindowSizeinteger
- frameSizeinteger
- poolMaxStreamsPerConninteger
- poolUnusedReleaseTimeoutstring
- frontendPolicies
- http
- maxBufferSizeinteger
- http1MaxHeadersinteger
- http1IdleTimeoutstring
- http1HeaderCasestring
- http2WindowSizeinteger
- http2ConnectionWindowSizeinteger
- http2FrameSizeinteger
- http2MaxHeaderSizeinteger
- http2KeepaliveIntervalstring
- http2KeepaliveTimeoutstring
- maxConnectionDurationstring
- maxConcurrentRequestsinteger
- tls
- handshakeTimeoutstring
- alpnarray[]
- minVersionstring
- maxVersionstring
- cipherSuitesstring[]
- keyExchangeGroupsstring[]
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- maxConnectionsinteger
- networkAuthorization
- *rules
- allowstring
- denystring
- requirestring
- networkExtAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateEgressActorResolution
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- proxy
- versionstring
- modestring
- proxyProtocol
- versionstring
- modestring
- connect
- *modestring
- accessLog
- presetstring
- filterstring
- addobject
- removestring[]
- otlp
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- database
- llmstring
- addobject
- logging
- presetstring
- filterstring
- addobject
- removestring[]
- otlp
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- database
- llmstring
- addobject
- tracing
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- binds
- portinteger
- protocolstring
- *listeners
- namestring
- namespacestring
- hostnamestring
- protocolstring
- tls
- modestring
- certstring
- keystring
- rootstring
- spiffeobject
- cipherSuitesstring[]
- minTLSVersionstring
- minTlsVersionstring
- maxTLSVersionstring
- maxTlsVersionstring
- keyExchangeGroupsstring[]
- routes
- namestring
- namespacestring
- ruleNamestring
- hostnamesstring[]
- matches
- headers
- *namestring
- *value
- *exactstring
- path
- *exactstring
- methodstring
- query
- *namestring
- *value
- *exactstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- urlRewrite
- authority
- *fullstring
- path
- fullstring
- prefixstring
- requestMirror
- *backend
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- *percentagenumber
- directResponse
- conditional
- conditionstring
- bodyarray|string
- bodyExpressionstring
- headersobject
- *statusinteger
- bodyarray|string
- bodyExpressionstring
- headersobject
- statusinteger
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthentication
- *issuerstring
- audiencesstring[]
- provider
- auth0object
- keycloakobject
- oktaobject
- descopeobject
- authentikobject
- entraobject
- *resourceMetadataobject
- jwks
- *filestring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- jwtValidationOptions
- requiredClaimsstring[]
- clientIdstring
- clientSecretstring
- a2aobject
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- backendAuth
- *key
- *filestring
- localRateLimit
- *conditional
- conditionstring
- maxTokensinteger
- tokensPerFillinteger
- *fillIntervalstring
- typestring
- remoteRateLimit
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateIngress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateEgress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- csrf
- additionalOriginsstring[]
- buffer
- request
- maxBytesinteger
- failureModestring
- response
- maxBytesinteger
- failureModestring
- timeout
- requestTimeoutstring
- backendRequestTimeoutstring
- responseIdleTimeoutstring
- retry
- attemptsinteger
- backoffstring
- *codesinteger[]
- preconditionstring
- conditionstring
- delay
- *durationstring
- backends
- service
- *namestring
- *portinteger
- backendstring
- hoststring
- internalstring
- dynamic
- targetstring
- mcp
- targets
- sse
- *hoststring
- mcp
- *hoststring
- stdio
- *cmdstring
- argsstring[]
- envobject
- clear_envboolean
- openapi
- *schema
- *filestring
- statefulModestring
- prefixModestring
- failureModestring
- dnsRebindingProtectionboolean
- ai
- namestring
- provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- groups
- *providers
- *namestring
- *provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- aws
- *agentCore
- *agentRuntimeArnstring
- qualifierstring
- routeGroupstring
- invalidnull
- tcpRoutes
- namestring
- namespacestring
- ruleNamestring
- hostnamesstring[]
- policies
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backends
- service
- *namestring
- *portinteger
- hoststring
- dynamic
- targetstring
- backendstring
- policies
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- authorization
- *rules
- allowstring
- denystring
- requirestring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- tunnelProtocolstring
- modestring
- llm
- gatewaysstring[]
- portinteger
- tls
- modestring
- certstring
- keystring
- rootstring
- spiffeobject
- cipherSuitesstring[]
- minTLSVersionstring
- minTlsVersionstring
- maxTLSVersionstring
- maxTlsVersionstring
- keyExchangeGroupsstring[]
- providers
- *namestring
- params
- modelstring
- apiKey
- *filestring
- awsRegionstring
- vertexRegionstring
- vertexProjectstring
- azureResourceNamestring
- azureResourceTypestring
- azureApiVersionstring
- azureProjectNamestring
- baseUrlstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- *provider
- *referencestring
- defaults
- defaultsobject
- overridesobject
- transformationobject
- requestHeaders
- addobject
- setobject
- removestring[]
- responseHeaders
- addobject
- setobject
- removestring[]
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- tls
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- auth
- *key
- *filestring
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- models
- idstring
- *namestring
- visibilitystring
- params
- modelstring
- apiKey
- *filestring
- awsRegionstring
- vertexRegionstring
- vertexProjectstring
- azureResourceNamestring
- azureResourceTypestring
- azureApiVersionstring
- azureProjectNamestring
- baseUrlstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- *provider
- *referencestring
- passthroughstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- defaultsobject
- overridesobject
- transformationobject
- finalTransformationobject
- requestHeaders
- addobject
- setobject
- removestring[]
- responseHeaders
- addobject
- setobject
- removestring[]
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- tls
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- auth
- *key
- *filestring
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- guardrails
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- matches
- headers
- *namestring
- *value
- *exactstring
- virtualModels
- *namestring
- *routing
- weighted
- *targets
- *modelstring
- weightinteger
- failover
- *targets
- *modelstring
- *priorityinteger
- conditional
- *targets
- whenstring
- *modelstring
- policies
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- authorization
- *rules
- allowstring
- denystring
- requirestring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- guardrails
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- localRateLimit
- maxTokensinteger
- tokensPerFillinteger
- *fillIntervalstring
- typestring
- remoteRateLimit
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- timeout
- requestTimeoutstring
- backendRequestTimeoutstring
- responseIdleTimeoutstring
- mcp
- gatewaysstring[]
- portinteger
- targets
- sse
- *hoststring
- mcp
- *hoststring
- stdio
- *cmdstring
- argsstring[]
- envobject
- clear_envboolean
- openapi
- *schema
- *filestring
- statefulModestring
- prefixModestring
- failureModestring
- dnsRebindingProtectionboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- urlRewrite
- authority
- *fullstring
- path
- fullstring
- prefixstring
- requestMirror
- *backend
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- *percentagenumber
- directResponse
- conditional
- conditionstring
- bodyarray|string
- bodyExpressionstring
- headersobject
- *statusinteger
- bodyarray|string
- bodyExpressionstring
- headersobject
- statusinteger
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthentication
- *issuerstring
- audiencesstring[]
- provider
- auth0object
- keycloakobject
- oktaobject
- descopeobject
- authentikobject
- entraobject
- *resourceMetadataobject
- jwks
- *filestring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- jwtValidationOptions
- requiredClaimsstring[]
- clientIdstring
- clientSecretstring
- a2aobject
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- backendAuth
- *key
- *filestring
- localRateLimit
- *conditional
- conditionstring
- maxTokensinteger
- tokensPerFillinteger
- *fillIntervalstring
- typestring
- remoteRateLimit
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateIngress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateEgress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- csrf
- additionalOriginsstring[]
- buffer
- request
- maxBytesinteger
- failureModestring
- response
- maxBytesinteger
- failureModestring
- timeout
- requestTimeoutstring
- backendRequestTimeoutstring
- responseIdleTimeoutstring
- retry
- attemptsinteger
- backoffstring
- *codesinteger[]
- preconditionstring
- conditionstring
- delay
- *durationstring
- policies
- *name
- *namestring
- *namespacestring
- *target
- gateway
- *gatewayNamestring
- *gatewayNamespacestring
- listenerNamestring
- portinteger
- route
- *namestring
- *namespacestring
- ruleNamestring
- kindstring
- backend
- *backend
- *namestring
- *namespacestring
- sectionstring
- listenerSet
- *namestring
- *namespacestring
- sectionstring
- phasestring
- *policy
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- urlRewrite
- authority
- *fullstring
- path
- fullstring
- prefixstring
- requestMirror
- *backend
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- *percentagenumber
- directResponse
- conditional
- conditionstring
- bodyarray|string
- bodyExpressionstring
- headersobject
- *statusinteger
- bodyarray|string
- bodyExpressionstring
- headersobject
- statusinteger
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthentication
- *issuerstring
- audiencesstring[]
- provider
- auth0object
- keycloakobject
- oktaobject
- descopeobject
- authentikobject
- entraobject
- *resourceMetadataobject
- jwks
- *filestring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- jwtValidationOptions
- requiredClaimsstring[]
- clientIdstring
- clientSecretstring
- a2aobject
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- backendAuth
- *key
- *filestring
- localRateLimit
- *conditional
- conditionstring
- maxTokensinteger
- tokensPerFillinteger
- *fillIntervalstring
- typestring
- remoteRateLimit
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateIngress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateEgress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- csrf
- additionalOriginsstring[]
- buffer
- request
- maxBytesinteger
- failureModestring
- response
- maxBytesinteger
- failureModestring
- timeout
- requestTimeoutstring
- backendRequestTimeoutstring
- responseIdleTimeoutstring
- retry
- attemptsinteger
- backoffstring
- *codesinteger[]
- preconditionstring
- conditionstring
- delay
- *durationstring
- workloadsobject[]
- servicesobject[]
- backends
- hoststring
- dynamic
- targetstring
- internalstring
- mcp
- targets
- sse
- *hoststring
- mcp
- *hoststring
- stdio
- *cmdstring
- argsstring[]
- envobject
- clear_envboolean
- openapi
- *schema
- *filestring
- statefulModestring
- prefixModestring
- failureModestring
- dnsRebindingProtectionboolean
- ai
- namestring
- provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- groups
- *providers
- *namestring
- *provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- aws
- *agentCore
- *agentRuntimeArnstring
- qualifierstring
- routeGroups
- *namestring
- *routes
- namestring
- namespacestring
- ruleNamestring
- hostnamesstring[]
- matches
- headers
- *namestring
- *value
- *exactstring
- path
- *exactstring
- methodstring
- query
- *namestring
- *value
- *exactstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- urlRewrite
- authority
- *fullstring
- path
- fullstring
- prefixstring
- requestMirror
- *backend
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- *percentagenumber
- directResponse
- conditional
- conditionstring
- bodyarray|string
- bodyExpressionstring
- headersobject
- *statusinteger
- bodyarray|string
- bodyExpressionstring
- headersobject
- statusinteger
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthentication
- *issuerstring
- audiencesstring[]
- provider
- auth0object
- keycloakobject
- oktaobject
- descopeobject
- authentikobject
- entraobject
- *resourceMetadataobject
- jwks
- *filestring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- jwtValidationOptions
- requiredClaimsstring[]
- clientIdstring
- clientSecretstring
- a2aobject
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- backendAuth
- *key
- *filestring
- localRateLimit
- *conditional
- conditionstring
- maxTokensinteger
- tokensPerFillinteger
- *fillIntervalstring
- typestring
- remoteRateLimit
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateIngress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateEgress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- csrf
- additionalOriginsstring[]
- buffer
- request
- maxBytesinteger
- failureModestring
- response
- maxBytesinteger
- failureModestring
- timeout
- requestTimeoutstring
- backendRequestTimeoutstring
- responseIdleTimeoutstring
- retry
- attemptsinteger
- backoffstring
- *codesinteger[]
- preconditionstring
- conditionstring
- delay
- *durationstring
- backends
- service
- *namestring
- *portinteger
- backendstring
- hoststring
- internalstring
- dynamic
- targetstring
- mcp
- targets
- sse
- *hoststring
- mcp
- *hoststring
- stdio
- *cmdstring
- argsstring[]
- envobject
- clear_envboolean
- openapi
- *schema
- *filestring
- statefulModestring
- prefixModestring
- failureModestring
- dnsRebindingProtectionboolean
- ai
- namestring
- provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- groups
- *providers
- *namestring
- *provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- aws
- *agentCore
- *agentRuntimeArnstring
- qualifierstring
- routeGroupstring
- invalidnull
- gatewaysobject
- routes
- gatewaysstring[]
- namestring
- namespacestring
- ruleNamestring
- hostnamesstring[]
- matches
- headers
- *namestring
- *value
- *exactstring
- path
- *exactstring
- methodstring
- query
- *namestring
- *value
- *exactstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- urlRewrite
- authority
- *fullstring
- path
- fullstring
- prefixstring
- requestMirror
- *backend
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- *percentagenumber
- directResponse
- conditional
- conditionstring
- bodyarray|string
- bodyExpressionstring
- headersobject
- *statusinteger
- bodyarray|string
- bodyExpressionstring
- headersobject
- statusinteger
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthentication
- *issuerstring
- audiencesstring[]
- provider
- auth0object
- keycloakobject
- oktaobject
- descopeobject
- authentikobject
- entraobject
- *resourceMetadataobject
- jwks
- *filestring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- jwtValidationOptions
- requiredClaimsstring[]
- clientIdstring
- clientSecretstring
- a2aobject
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- backendAuth
- *key
- *filestring
- localRateLimit
- *conditional
- conditionstring
- maxTokensinteger
- tokensPerFillinteger
- *fillIntervalstring
- typestring
- remoteRateLimit
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- extProc
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateIngress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- substrateEgress
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- transformations
- conditional
- conditionstring
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- csrf
- additionalOriginsstring[]
- buffer
- request
- maxBytesinteger
- failureModestring
- response
- maxBytesinteger
- failureModestring
- timeout
- requestTimeoutstring
- backendRequestTimeoutstring
- responseIdleTimeoutstring
- retry
- attemptsinteger
- backoffstring
- *codesinteger[]
- preconditionstring
- conditionstring
- delay
- *durationstring
- backends
- service
- *namestring
- *portinteger
- backendstring
- hoststring
- internalstring
- dynamic
- targetstring
- mcp
- targets
- sse
- *hoststring
- mcp
- *hoststring
- stdio
- *cmdstring
- argsstring[]
- envobject
- clear_envboolean
- openapi
- *schema
- *filestring
- statefulModestring
- prefixModestring
- failureModestring
- dnsRebindingProtectionboolean
- ai
- namestring
- provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- groups
- *providers
- *namestring
- *provider
- openAI
- modelstring
- moderation
- modelstring
- policy
- input
- *modestring
- output
- *modestring
- gemini
- modelstring
- vertex
- modelstring
- regionstring
- *projectIdstring
- anthropic
- modelstring
- bedrock
- modelstring
- *regionstring
- guardrailIdentifierstring
- guardrailVersionstring
- azure
- modelstring
- *resourceNamestring
- *resourceTypestring
- apiVersionstring
- projectNamestring
- copilot
- modelstring
- custom
- modelstring
- providerOverridestring
- *formats
- *typestring
- pathstring
- hostOverridestring
- pathOverridestring
- pathPrefixstring
- tokenizeboolean
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnelobject
- responseHeaderModifier
- addobject
- setobject
- removestring[]
- requestRedirect
- schemestring
- authority
- *fullstring
- path
- fullstring
- prefixstring
- statusinteger
- health
- unhealthyExpressionstring
- eviction
- durationstring
- restoreHealthnumber
- consecutiveFailuresinteger
- healthThresholdnumber
- extAuthz
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- authorization
- *rules
- allowstring
- denystring
- requirestring
- mcpAuthorization
- *rules
- allowstring
- denystring
- requirestring
- mcpGuardrails
- *processors
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- a2aobject
- inferenceRouting
- *endpointPicker
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- destinationModestring
- sessionAffinity
- *sourcestring
- ai
- promptGuard
- streamingstring
- request
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- openAIModeration
- modelstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- response
- regex
- actionstring
- *rules
- builtinstring
- patternstring
- webhook
- *target
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- headersobject
- forwardHeaderMatches
- *namestring
- *value
- *exactstring
- failureModestring
- actionstring
- bedrockGuardrails
- *guardrailIdentifierstring
- *guardrailVersionstring
- *regionstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- googleModelArmor
- *templateIdstring
- *projectIdstring
- locationstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- azureContentSafety
- *endpointstring
- actionstring
- policies
- requestHeaderModifier
- addobject
- setobject
- removestring[]
- transformations
- request
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- response
- addobject
- setobject
- removestring[]
- replacestring
- bodystring
- metadataobject
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backendAuth
- *key
- *filestring
- http
- versionstring
- requestTimeoutstring
- maxConnectionDurationstring
- tcp
- keepalives
- enabledboolean
- timestring
- intervalstring
- retriesinteger
- connectTimeoutstring
- backendTunnel
- *proxy
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- modestring
- policiesobject
- analyzeText
- severityThresholdinteger
- apiVersionstring
- blocklistNamesstring[]
- haltOnBlocklistHitboolean
- detectJailbreak
- apiVersionstring
- defaultsobject
- overridesobject
- transformationsobject
- finalTransformationsobject
- prompts
- append
- *rolestring
- *contentstring
- prepend
- *rolestring
- *contentstring
- modelAliasesobject
- promptCaching
- cacheSystemboolean
- cacheMessagesboolean
- cacheToolsboolean
- minTokensinteger
- cacheMessageOffsetinteger
- routesobject
- aws
- *agentCore
- *agentRuntimeArnstring
- qualifierstring
- routeGroupstring
- invalidnull
- tcpRoutes
- gatewaysstring[]
- namestring
- namespacestring
- ruleNamestring
- hostnamesstring[]
- policies
- backendTLS
- certstring
- keystring
- rootstring
- hostnamestring
- insecureboolean
- insecureHostboolean
- alpnstring[]
- subjectAltNamesstring[]
- keyExchangeGroupsstring[]
- spiffeobject
- backends
- service
- *namestring
- *portinteger
- hoststring
- dynamic
- targetstring
- backendstring
- ui
- gatewaysstring[]
- policies
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgestring
- oidc
- *issuerstring
- discovery
- *filestring
- authorizationEndpointstring
- tokenEndpointstring
- tokenEndpointAuthstring
- jwks
- *filestring
- *clientIdstring
- *clientSecretstring
- *redirectURIstring
- scopesstring[]
- jwtAuth
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- preserveTokenboolean
- *providers
- *issuerstring
- audiencesstring[]
- *jwks
- *filestring
- jwtValidationOptions
- requiredClaimsstring[]
- authorization
- *rules
- allowstring
- denystring
- requirestring
- extAuthz
- conditional
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- service
- *namestring
- *portinteger
- hoststring
- backendstring
- basicAuth
- *htpasswd
- *filestring
- realmstring
- modestring
- authorizationLocation
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- apiKey
- *keys
- *keystring
- metadata
- allowedModelsstring[]
- budgets
- *namestring
- *limit
- *unitstring
- *amountnumber
- *window
- *rollingstring
- *onBudgetExceededstring
- modestring
- location
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- cookie
- *namestring
- expressionstring
- csrf
- additionalOriginsstring[]
management. Unlike other sections, these are applied only at startup, except modelCatalog and
standardAttributes, which are dynamically reloaded.
Validation
upstream connections.
Accepted values: All, Auto, V4Preferred, V4Only, V6Only.
Defaults to Auto (IPv4-only when enableIpv6 is false, both when true).
Validation
When
None, the system-provided resolver setting is preserved.Can also be set via the
DNS_EDNS0 environment variable.When the request log and config stores have matching database settings, they share one pool
with this limit.
Validation
Validation
When set, listeners and backends may source their TLS identity from SPIFFE.
unix:///run/spire/agent.sock).connections. The local trust_domain is always implicitly included.
agentgateway.user request log attribute.agentgateway.group request log attribute.Prometheus protobuf format. Defaults to classic.
Validation
If not set, sessions will not be encrypted.
For example, generated via
openssl rand -hex 32.Validation
Validation
can be used in any expressions.
Configure as a block string containing one or more definitions, for example:
customFunctions: |isInternal() { request.headers["x-env"] == "internal" }this.joined(prefix, parts...) { prefix + this + parts.join("") }Validation
Validation
Validation
grpc or http.Validation
Validation
Validation
Random sampling will initiate a new trace span if the incoming request does not have a trace already.
This should evaluate to either a float between 0.0-1.0 (0-100%) or true/false.
This defaults to 'false'.
Client sampling determines whether to initiate a new trace span if the incoming request does have a trace already.
This should evaluate to either a float between 0.0-1.0 (0-100%) or true/false.
This defaults to 'true'.
Validation
Validation
info), a comma-separated string of per-module levels (e.g. info,agent_core=trace), or a list of per-module levels (e.g. [info, agent_core=trace]).text or json.Validation
When the request log and config stores have matching database settings, they share one pool
with this limit.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
the total number of connections kept alive to any given host.
Note: excess connections will still be created, they will just not remain idle.
If unset, there is no limit
Validation
PINGs are sent even on idle connections to proactively evict dead connections from the pool.
Disabled by default ("0s"). Note: many gRPC servers enforce a minimum ping interval
and will reject connections that ping more frequently.
Validation
Only applies when h2_keepalive_interval is set. Defaults to 5s.
Validation
Validation
Validation
Validation
Validation
Validation
Defaults to 2 MiB, or 32 MiB once the request enters LLM processing.
Validation
performance degradation, even when set lower than the default of 100.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
closed after the current in-flight request completes. Useful for even traffic distribution
behind load balancers during scaling events.
Validation
and HTTP/2 streams. Requests over the limit are rejected immediately.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
are closed immediately.
Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
services list.Validation
Validation
services list.Validation
version matching and whether PROXY headers are required or optional.
Validation
Validation
Validation
version matching and whether PROXY headers are required or optional.
Validation
Validation
Validation
Validation
Validation
Validation
If unset, human-oriented legacy fields are used.
Validation
Validation
services list.Validation
metadata stores request metadata, usage, timing, andcost without prompt or completion content in the dedicated payload table.
fulladditionally captures and stores prompt and completion content there. When omitted, legacy
behavior is preserved: content captured by CEL expressions is also stored in the payload.
Validation
Validation
If unset, human-oriented legacy fields are used.
Validation
Validation
services list.Validation
metadata stores request metadata, usage, timing, andcost without prompt or completion content in the dedicated payload table.
fulladditionally captures and stores prompt and completion content there. When omitted, legacy
behavior is preserved: content captured by CEL expressions is also stored in the payload.
Validation
Validation
services list.Validation
Each bind represents a single port the proxy listens on, as well as the full set of configuration
(listeners, routes, backends) for that port.
Deprecated; usage of
gateways and routes is recommended instead.via in-process routing). A numeric port is required unless
mode is internal.Validation
Validation
gateways: gateway-name/listener-name.Validation
Validation
Validation
mode uses cert/key as a CA for on-demand SNI leaf certificate issuance.
Unused when
spiffe is set.Validation
Required unless
spiffe is set.Omit for one-way server TLS. Not used when
spiffe is set.Mutually exclusive with
cert/key/root.Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
:method) to match.Validation
Validation
Validation
Validation
http or https.Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.iss claim.aud claim.If unset, audience validation is disabled.
If omitted, the JWKS URL is derived from the issuer and provider.
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Currently used by the
entra provider, whose Web-platform app registrations require aclient secret at the token endpoint.
Validation
Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
services list.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
services list.Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
are received. The response body is not included; use
responseIdleTimeout to bound gapsbetween body frames.
the total time a response may take. It is what terminates a backend that stops producing
data mid-stream without capping how long a legitimately long response may run.
requestTimeout andbackendRequestTimeout stop applying once the response headers arrive, so neither placesany bound on how long the response body may take, and neither can distinguish a stalled
stream from a slow one.
responses that switch protocols, so upgraded WebSocket and CONNECT tunnels are never
terminated by it.
Validation
Validation
false,retries are disabled (only the initial attempt is made), e.g.
request.method == "GET".Retrying requires buffering the request body in memory for replay, so this lets us skip
that cost when the request is known to be non-retriable (e.g. streaming or websockets).
is retried when its status code is in
codes *or* this expression evaluates to true.Validation
string such as
2s, or a CEL expression evaluated against the request that returns a duration(e.g.
duration("500ms")) or a number interpreted as milliseconds (e.g.random() < 0.1 ? 500 : 0 for probabilistic delay, or int(random() * 500) for jitter). Anon-positive result injects no delay.
services list.services list.Validation
Validation
target (e.g.
extproc.workerPodIp + ":" + string(extproc.workerPodPort)to read dynamic metadata an extProc policy already set). Must
evaluate to a
host:port string. The expression and any policy thatsupplies its dynamic metadata are trusted to select the dial target.
If unset, the target is read from the request's own :authority/URI, as
today.
https://example.com or example.com:443.https://example.com or example.com:443.Validation
always prefix with the target name, or only prefix when needed (conditional).Validation
Defaults to
failClosed.Validation
Off by default; see https://github.com/agentgateway/agentgateway/issues/1855.
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedservices list.Validation
host:port dial target. Available fields include source.* anddestination.*; for TLS, destination.hostname is the sniffed SNI.${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
standard (binds the port).Set to
internal to create a routing-only bind that does not bind a socket.Validation
served under the attached
gateways using the standard serving paths (/v1/models, /v1/chat/completions, etc).<gateway-name> or <gateway-name>/<listener-name> to attach to a specific listener within a gateway.When omitted and a gateway named
default exists, the LLM API routes attach to it unless port is set.Validation
gateways instead.Validation
port. Deprecated; use gateways instead.mode uses cert/key as a CA for on-demand SNI leaf certificate issuance.
Unused when
spiffe is set.Validation
Required unless
spiffe is set.Omit for one-way server TLS. Not used when
spiffe is set.Mutually exclusive with
cert/key/root.Validation
Validation
Validation
Validation
If unset, the same model will be used from the request.
Validation
If unset this will be automatically detected from the environment.
Validation
The URL path is the upstream base path and defaults to / when omitted.
Provider-specific endpoint paths are appended to this base path.
For example, https://api.openai.com/v1 sends completions to /v1/chat/completions,
while https://api.openai.com sends them to /chat/completions.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedtrue marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
model in the users request that is matched; the model sent to the actual LLM can be overridden
on a per-model basis.
will be used in the request to the LLM provider. If not, the incoming model is used.
virtualModel).Validation
If unset, the same model will be used from the request.
Validation
If unset this will be automatically detected from the environment.
Validation
The URL path is the upstream base path and defaults to / when omitted.
Provider-specific endpoint paths are appended to this base path.
For example, https://api.openai.com/v1 sends completions to /v1/chat/completions,
while https://api.openai.com sends them to /chat/completions.
Validation
Validation
Validation
Validation
Validation
By default, requests will be parsed and translated as needed.
With passthrough, they will be unmodified and optionally inspected (with
detect).In this mode, requests must be sent in the native format of the provider.
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.To override even when set, use
overrides.Occurs after conversion of the request to the provider format, allowing for provider-specific transformations.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedtrue marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
Validation
Validation
Validation
:method) to match.model in the users request that is matched. However, unlike the
models field, virtual models willdynamically route to a specific model (configured in
models) based on the configured logic.Validation
Within a priority level, the best provider is selected by a composite score factoring in health
and latency.
If all models within a priority level are degraded, requests will move onto the next priority group.
Validation
in order until the best match is found.
Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
are received. The response body is not included; use
responseIdleTimeout to bound gapsbetween body frames.
the total time a response may take. It is what terminates a backend that stops producing
data mid-stream without capping how long a legitimately long response may run.
requestTimeout andbackendRequestTimeout stop applying once the response headers arrive, so neither placesany bound on how long the response body may take, and neither can distinguish a stalled
stream from a slow one.
responses that switch protocols, so upgraded WebSocket and CONNECT tunnels are never
terminated by it.
served under the attached
gateways at /mcp and /sse.All MCP servers listed will be served as a single virtual MCP server.
<gateway-name> or <gateway-name>/<listener-name> to attach to a specific listener within a gateway.When omitted and a gateway named
default exists, the MCP routes attach to it unless port is set.Validation
gateways instead.Validation
https://example.com or example.com:443.https://example.com or example.com:443.Validation
always prefix with the target name, or only prefix when needed (conditional).Validation
Defaults to
failClosed.Validation
Off by default; see https://github.com/agentgateway/agentgateway/issues/1855.
Validation
Validation
Validation
http or https.Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.iss claim.aud claim.If unset, audience validation is disabled.
If omitted, the JWKS URL is derived from the issuer and provider.
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Currently used by the
entra provider, whose Web-platform app registrations require aclient secret at the token endpoint.
Validation
Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
services list.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
services list.Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
are received. The response body is not included; use
responseIdleTimeout to bound gapsbetween body frames.
the total time a response may take. It is what terminates a backend that stops producing
data mid-stream without capping how long a legitimately long response may run.
requestTimeout andbackendRequestTimeout stop applying once the response headers arrive, so neither placesany bound on how long the response body may take, and neither can distinguish a stalled
stream from a slow one.
responses that switch protocols, so upgraded WebSocket and CONNECT tunnels are never
terminated by it.
Validation
Validation
false,retries are disabled (only the initial attempt is made), e.g.
request.method == "GET".Retrying requires buffering the request body in memory for replay, so this lets us skip
that cost when the request is known to be non-retriable (e.g. streaming or websockets).
is retried when its status code is in
codes *or* this expression evaluates to true.Validation
string such as
2s, or a CEL expression evaluated against the request that returns a duration(e.g.
duration("500ms")) or a number interpreted as milliseconds (e.g.random() < 0.1 ? 500 : 0 for probabilistic delay, or int(random() * 500) for jitter). Anon-positive result injects no delay.
This is an advanced feature; users should typically use the inline
policies field under route/gateway.namespace/name references.Validation
namespace/name references.Use route policies by default unless the policy needs to affect route selection.
Validation
Validation
Validation
Validation
http or https.Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.iss claim.aud claim.If unset, audience validation is disabled.
If omitted, the JWKS URL is derived from the issuer and provider.
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Currently used by the
entra provider, whose Web-platform app registrations require aclient secret at the token endpoint.
Validation
Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
services list.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
services list.Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
are received. The response body is not included; use
responseIdleTimeout to bound gapsbetween body frames.
the total time a response may take. It is what terminates a backend that stops producing
data mid-stream without capping how long a legitimately long response may run.
requestTimeout andbackendRequestTimeout stop applying once the response headers arrive, so neither placesany bound on how long the response body may take, and neither can distinguish a stalled
stream from a slow one.
responses that switch protocols, so upgraded WebSocket and CONNECT tunnels are never
terminated by it.
Validation
Validation
false,retries are disabled (only the initial attempt is made), e.g.
request.method == "GET".Retrying requires buffering the request body in memory for replay, so this lets us skip
that cost when the request is known to be non-retriable (e.g. streaming or websockets).
is retried when its status code is in
codes *or* this expression evaluates to true.Validation
string such as
2s, or a CEL expression evaluated against the request that returns a duration(e.g.
duration("500ms")) or a number interpreted as milliseconds (e.g.random() < 0.1 ? 500 : 0 for probabilistic delay, or int(random() * 500) for jitter). Anon-positive result injects no delay.
services.This is an advanced feature that is mostly for testing; usage of inline
backends on routes andpolicies is typically preferred.
Validation
workloads.This is an advanced feature that is mostly for testing; usage of inline
backends on routes andpolicies is typically preferred.
Validation
Typically, inline backends are used on the routes/policies, but this allows re-using the same backend
across different configurations.
Validation
https://example.com or example.com:443.https://example.com or example.com:443.Validation
always prefix with the target name, or only prefix when needed (conditional).Validation
Defaults to
failClosed.Validation
Off by default; see https://github.com/agentgateway/agentgateway/issues/1855.
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
primarily used for testing.
Validation
Validation
Validation
Validation
:method) to match.Validation
Validation
Validation
Validation
http or https.Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.iss claim.aud claim.If unset, audience validation is disabled.
If omitted, the JWKS URL is derived from the issuer and provider.
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Currently used by the
entra provider, whose Web-platform app registrations require aclient secret at the token endpoint.
Validation
Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
services list.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
services list.Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
are received. The response body is not included; use
responseIdleTimeout to bound gapsbetween body frames.
the total time a response may take. It is what terminates a backend that stops producing
data mid-stream without capping how long a legitimately long response may run.
requestTimeout andbackendRequestTimeout stop applying once the response headers arrive, so neither placesany bound on how long the response body may take, and neither can distinguish a stalled
stream from a slow one.
responses that switch protocols, so upgraded WebSocket and CONNECT tunnels are never
terminated by it.
Validation
Validation
false,retries are disabled (only the initial attempt is made), e.g.
request.method == "GET".Retrying requires buffering the request body in memory for replay, so this lets us skip
that cost when the request is known to be non-retriable (e.g. streaming or websockets).
is retried when its status code is in
codes *or* this expression evaluates to true.Validation
string such as
2s, or a CEL expression evaluated against the request that returns a duration(e.g.
duration("500ms")) or a number interpreted as milliseconds (e.g.random() < 0.1 ? 500 : 0 for probabilistic delay, or int(random() * 500) for jitter). Anon-positive result injects no delay.
services list.services list.Validation
Validation
target (e.g.
extproc.workerPodIp + ":" + string(extproc.workerPodPort)to read dynamic metadata an extProc policy already set). Must
evaluate to a
host:port string. The expression and any policy thatsupplies its dynamic metadata are trusted to select the dial target.
If unset, the target is read from the request's own :authority/URI, as
today.
https://example.com or example.com:443.https://example.com or example.com:443.Validation
always prefix with the target name, or only prefix when needed (conditional).Validation
Defaults to
failClosed.Validation
Off by default; see https://github.com/agentgateway/agentgateway/issues/1855.
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Each gateway defines a port that proxy will listen on, and optionally TLS settings for that port.
This can take the form of
<gateway-name> or <gateway-name>/<listener-name> to attach to a specific listener within a gateway.If unset, the 'default' gateway will be used.
Validation
Validation
Validation
Validation
Validation
:method) to match.Validation
Validation
Validation
Validation
http or https.Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.iss claim.aud claim.If unset, audience validation is disabled.
If omitted, the JWKS URL is derived from the issuer and provider.
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Currently used by the
entra provider, whose Web-platform app registrations require aclient secret at the token endpoint.
Validation
Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
services list.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
services list.Validation
services list.Validation
services list.Validation
services list.Validation
Validation
services list.Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
are received. The response body is not included; use
responseIdleTimeout to bound gapsbetween body frames.
the total time a response may take. It is what terminates a backend that stops producing
data mid-stream without capping how long a legitimately long response may run.
requestTimeout andbackendRequestTimeout stop applying once the response headers arrive, so neither placesany bound on how long the response body may take, and neither can distinguish a stalled
stream from a slow one.
responses that switch protocols, so upgraded WebSocket and CONNECT tunnels are never
terminated by it.
Validation
Validation
false,retries are disabled (only the initial attempt is made), e.g.
request.method == "GET".Retrying requires buffering the request body in memory for replay, so this lets us skip
that cost when the request is known to be non-retriable (e.g. streaming or websockets).
is retried when its status code is in
codes *or* this expression evaluates to true.Validation
string such as
2s, or a CEL expression evaluated against the request that returns a duration(e.g.
duration("500ms")) or a number interpreted as milliseconds (e.g.random() < 0.1 ? 500 : 0 for probabilistic delay, or int(random() * 500) for jitter). Anon-positive result injects no delay.
services list.services list.Validation
Validation
target (e.g.
extproc.workerPodIp + ":" + string(extproc.workerPodPort)to read dynamic metadata an extProc policy already set). Must
evaluate to a
host:port string. The expression and any policy thatsupplies its dynamic metadata are trusted to select the dial target.
If unset, the target is read from the request's own :authority/URI, as
today.
https://example.com or example.com:443.https://example.com or example.com:443.Validation
always prefix with the target name, or only prefix when needed (conditional).Validation
Defaults to
failClosed.Validation
Off by default; see https://github.com/agentgateway/agentgateway/issues/1855.
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
llm.models[].provider.omni-moderation-latest.Validation
Validation
Validation
global uses the global endpoint, while us and euuse restricted multi-region endpoints. Other values are treated as regional locations.
Validation
resourceType is foundry.Used to construct paths:
/api/projects/{projectName}/openai/v1/....This is distinct from
resourceName which is used for the host.(cohere, mistral, ...) set this so their cost resolves under the right catalog key;
a bare custom provider may set it to match a catalog entry. Falls back to "custom".
Validation
since we know (part of) the cost of the request upfront.
This comes with the cost of an expensive operation.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
http or https.Validation
true marks the backend response as unhealthy.When unset, any 5xx response or connection failure is treated as unhealthy.
Validation
Validation
Validation
Validation
services list.Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.Validation
to reject a request short-circuits the chain. Processors may run on the
request or response side, or both; see
Processor.methods.services list.Validation
Validation
Validation
services list.Validation
Validation
Requests with the same value are consistently load balanced to the same healthy service
endpoint or AI provider, but may be remapped when the available backends change.
Validation
Examples:
request.headers["x-session-id"] or string(source.address).Validation
Validation
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
omni-moderation-latest.Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
Validation
Validation
services list.Validation
Keys may be header names or the
:path, :method, and :authority pseudo-headers;setting
:path replaces the default /request / /response path.Expressions are evaluated against the original incoming request (like the
transformation policy), so request.* and jwt.* refer to the client's request.:method) to match.Defaults to
failClosed.Validation
Defaults to
reject (enforce).Validation
reject (the default) enforces the guardrail: a BLOCKED assessmentrejects the request/response and an
ANONYMIZED assessment masks thematched content, exactly as before.
audit records successful assessments without enforcing their verdict.audit guarantees non-enforcement gateway-side even when the AWS resourceis configured to
BLOCK/ANONYMIZE.Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
Defaults to
reject (enforce).Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
The expression must evaluate to a map of header name to value (a string, or a list of
strings for a repeated header). Pseudo-headers (
:method, :path, etc.) are ignored;set those explicitly with
set/add. replace is applied before add/set/remove,so those still operate on top of the replaced headers.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedValidation
Validation
not reused for new requests; a fresh connection is established instead, while in-flight
requests are not interrupted.
Validation
Validation
Validation
Validation
Validation
Validation
services list.Validation
Validation
(Hate, SelfHarm, Sexual, Violence) and blocklist matches.
Validation
Only applicable to request guards.
These are applied after conversion to the provider's request format.
Validation
Validation
Validation
Validation
Validation
This can take the form of
<gateway-name> or <gateway-name>/<listener-name> to attach to a specific listener within a gateway.If unset, the 'default' gateway will be used.
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Validation
Mutually exclusive with
cert/key/root/insecure/insecureHost.Pin specific upstream SPIFFE IDs via
subjectAltNames (e.g. spiffe://td/ns/foo/sa/bar);If
subjectAltNames is omitted, any SVID chaining to the SPIFFE trust bundle is acceptedservices list.Validation
host:port dial target. Available fields include source.* anddestination.*; for TLS, destination.hostname is the sniffed SNI.on the admin interface (typically localhost:15000). This setting allows attaching to
gatewaysto serve externally, as well as attaching policies to UI traffic.
It is strongly recommended to utilize authentication (typically OIDC) when exposing the UI externally.
<gateway-name> or <gateway-name>/<listener-name> to attach to a specific listener within a gateway.When omitted and a gateway named
default exists, the UI routes attach to it.Validation
Validation
Access-Control-Allow-Credentials: true on allowed CORS responses.Validation
Access-Control-Allow-Headers for allowed preflight requests.Validation
Access-Control-Allow-Methods for allowed preflight requests.Validation
* to match any origin.Validation
Access-Control-Expose-Headers for allowed CORS responses.Validation
Access-Control-Max-Age for allowed preflight requests.Validation
${issuer}/.well-known/openid-configuration.Validation
Validation
clientSecretBasic when omitted.Validation
This policy always redirects unauthenticated non-callback requests back through this login
flow.
openid is always included.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Validation
iss claim is required and must match.aud claim.Only "exp", "nbf", "aud", "iss", "sub" are enforced; others
(including "iat" and "jti") are ignored.
Defaults to ["exp"]. Use an empty list to add no claim requirements beyond
those implied by the configured issuer and audiences.
Validation
Validation
recommended because expression failures fail to deny; prefer
Allow orRequire. If used, design expressions defensively against evaluation errors.services list.Validation
services list.Validation
WWW-Authenticate response header when credentials are missing or invalid.Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.
Omitted means no additional constraint; an empty list denies all models.
Validation
does not report the usage or cost required by the budget unit.
Validation
Validation
1h, 24h, or 30d.Windows are aligned to the Unix epoch rather than starting with the first request:
1hfollows UTC clock hours,
24h starts at midnight UTC, and 30d uses consecutive 30-dayperiods rather than calendar months.
Validation
Validation
Validation
Bearer or Basic .CEL expression that returns the credential string. This location can extract credentials but cannot insert them.