For the complete documentation index, see llms.txt. Markdown versions of all docs pages are available by appending .md to any docs URL.
AgentgatewayPolicy
Use AgentgatewayPolicy to configure traffic manipulation, observability, security, and more.
Explore the configuration reference by clicking on a property name or expanding the property types. Use the in-field search bar to search for a property. The reference is also available as a table.- apiVersionstring
- kindstring
- metadataobject
- *spec
- backend
- ai
- defaults
- *fieldstring
- *valueobject
- modelAliasesobject
- overrides
- *fieldstring
- *valueobject
- prompt
- append
- *contentstring
- *rolestring
- prepend
- *contentstring
- *rolestring
- promptCaching
- cacheMessageOffsetinteger
- cacheMessagesboolean
- cacheSystemboolean
- cacheToolsboolean
- minTokensinteger
- promptGuard
- request
- bedrockGuardrails
- *identifierstring
- policies
- auth
- aws
- assumeRole
- *roleArnstring
- sessionNamestring
- sessionNameExpressionstring
- tags
- expressionstring
- *keystring
- valuestring
- regionstring
- secretRef
- groupstring
- kindstring
- *namestring
- serviceNamestring
- keystring
- location
- cookie
- *namestring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- http
- requestTimeoutstring
- versionstring
- tcp
- connectTimeoutstring
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- caCertificateRefs
- namestring
- insecureSkipVerifystring
- keyExchangeGroupsstring[]
- mtlsCertificateRef
- groupstring
- kindstring
- *namestring
- snistring
- verifySubjectAltNamesstring[]
- tunnel
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *regionstring
- *versionstring
- googleModelArmor
- locationstring
- policies
- auth
- gcp
- audiencestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- typestring
- http
- requestTimeoutstring
- versionstring
- tcp
- connectTimeoutstring
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- caCertificateRefs
- namestring
- insecureSkipVerifystring
- keyExchangeGroupsstring[]
- mtlsCertificateRef
- groupstring
- kindstring
- *namestring
- snistring
- verifySubjectAltNamesstring[]
- tunnel
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *projectIdstring
- *templateIdstring
- openAIModeration
- modelstring
- policies
- auth
- keystring
- location
- cookie
- *namestring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- http
- requestTimeoutstring
- versionstring
- tcp
- connectTimeoutstring
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- caCertificateRefs
- namestring
- insecureSkipVerifystring
- keyExchangeGroupsstring[]
- mtlsCertificateRef
- groupstring
- kindstring
- *namestring
- snistring
- verifySubjectAltNamesstring[]
- tunnel
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- regex
- actionstring
- builtinsstring[]
- matchesstring[]
- response
- messagestring
- statusCodeinteger
- webhook
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- failureModestring
- forwardHeaderMatches
- *namestring
- typestring
- *valuestring
- response
- bedrockGuardrails
- *identifierstring
- policies
- auth
- aws
- assumeRole
- *roleArnstring
- sessionNamestring
- sessionNameExpressionstring
- tags
- expressionstring
- *keystring
- valuestring
- regionstring
- secretRef
- groupstring
- kindstring
- *namestring
- serviceNamestring
- keystring
- location
- cookie
- *namestring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- http
- requestTimeoutstring
- versionstring
- tcp
- connectTimeoutstring
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- caCertificateRefs
- namestring
- insecureSkipVerifystring
- keyExchangeGroupsstring[]
- mtlsCertificateRef
- groupstring
- kindstring
- *namestring
- snistring
- verifySubjectAltNamesstring[]
- tunnel
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *regionstring
- *versionstring
- googleModelArmor
- locationstring
- policies
- auth
- gcp
- audiencestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- typestring
- http
- requestTimeoutstring
- versionstring
- tcp
- connectTimeoutstring
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- caCertificateRefs
- namestring
- insecureSkipVerifystring
- keyExchangeGroupsstring[]
- mtlsCertificateRef
- groupstring
- kindstring
- *namestring
- snistring
- verifySubjectAltNamesstring[]
- tunnel
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *projectIdstring
- *templateIdstring
- regex
- actionstring
- builtinsstring[]
- matchesstring[]
- response
- messagestring
- statusCodeinteger
- webhook
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- failureModestring
- forwardHeaderMatches
- *namestring
- typestring
- *valuestring
- streamingstring
- routesobject
- transformations
- *expressionstring
- *fieldstring
- auth
- aws
- assumeRole
- *roleArnstring
- sessionNamestring
- sessionNameExpressionstring
- tags
- expressionstring
- *keystring
- valuestring
- regionstring
- secretRef
- groupstring
- kindstring
- *namestring
- serviceNamestring
- azure
- managedIdentity
- *clientIdstring
- *objectIdstring
- *resourceIdstring
- secretRef
- groupstring
- kindstring
- *namestring
- workloadIdentityobject
- crossAppAccess
- *audiencestring
- cache
- inMemory
- defaultTtlstring
- maxEntriesinteger
- *identityProvider
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *clientAuth
- *clientIdstring
- methodstring
- privateKeyJwt
- algstring
- *assertionAudiencestring
- kidstring
- *signingKeyRef
- groupstring
- keystring
- kindstring
- *namestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- pathstring
- *resourceAuthorizationServer
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *clientAuth
- *clientIdstring
- methodstring
- privateKeyJwt
- algstring
- *assertionAudiencestring
- kidstring
- *signingKeyRef
- groupstring
- keystring
- kindstring
- *namestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- pathstring
- resourcesstring[]
- scopesstring[]
- subjectToken
- source
- cookie
- *namestring
- expressionstring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- gcp
- audiencestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- typestring
- keystring
- location
- cookie
- *namestring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- oauthTokenExchange
- actorToken
- mayActstring
- *source
- cookie
- *namestring
- expressionstring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- tokenTypestring
- additionalParamsobject
- audiencesstring[]
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- cache
- inMemory
- defaultTtlstring
- maxEntriesinteger
- clientAuth
- *clientIdstring
- methodstring
- privateKeyJwt
- algstring
- *assertionAudiencestring
- kidstring
- *signingKeyRef
- groupstring
- keystring
- kindstring
- *namestring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- grantTypestring
- location
- cookie
- *namestring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- pathstring
- requestedTokenTypestring
- resourcesstring[]
- scopesstring[]
- subjectToken
- source
- cookie
- *namestring
- expressionstring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- tokenTypestring
- passthroughobject
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- extAuth
- backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- cache
- *keystring[]
- maxEntriesinteger
- *ttlstring
- failureModestring
- forwardBody
- *maxSize
- grpc
- contextExtensionsobject
- requestMetadataobject
- http
- addRequestHeadersobject
- allowedRequestHeadersstring[]
- allowedResponseHeadersstring[]
- bodystring
- pathstring
- redirectstring
- responseMetadataobject
- health
- eviction
- consecutiveFailuresinteger
- durationstring
- healthThresholdinteger
- restoreHealthinteger
- unhealthyConditionstring
- http
- requestTimeoutstring
- versionstring
- mcp
- authentication
- audiencesstring[]
- clientIdstring
- clientSecretRef
- groupstring
- keystring
- kindstring
- *namestring
- issuerstring
- *jwks
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- cacheDurationstring
- *jwksPathstring
- modestring
- providerstring
- resourceMetadataobject
- authorization
- actionstring
- *policy
- *matchExpressionsstring[]
- guardrails
- *processors
- *methodsobject
- remote
- allowedRequestHeadersstring[]
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- disallowedRequestHeadersstring[]
- failureModestring
- metadataobject
- tcp
- connectTimeoutstring
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- caCertificateRefs
- namestring
- insecureSkipVerifystring
- keyExchangeGroupsstring[]
- mtlsCertificateRef
- groupstring
- kindstring
- *namestring
- snistring
- verifySubjectAltNamesstring[]
- transformation
- request
- add
- *namestring
- *valuestring
- bodystring
- metadataobject
- removestring[]
- set
- *namestring
- *valuestring
- response
- add
- *namestring
- *valuestring
- bodystring
- metadataobject
- removestring[]
- set
- *namestring
- *valuestring
- tunnel
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- frontend
- accessLog
- attributes
- add
- *expressionstring
- *namestring
- removestring[]
- filterstring
- otlp
- attributes
- add
- *expressionstring
- *namestring
- removestring[]
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- filterstring
- pathstring
- protocolstring
- connect
- *modestring
- http
- http1HeaderCasestring
- http1IdleTimeoutstring
- http1MaxHeadersinteger
- http2ConnectionWindowSize
- http2FrameSize
- http2KeepaliveIntervalstring
- http2KeepaliveTimeoutstring
- http2MaxHeaderSize
- http2WindowSize
- maxBufferSize
- maxConnectionDurationstring
- metrics
- *attributes
- add
- *expressionstring
- *namestring
- networkAuthorization
- actionstring
- *policy
- *matchExpressionsstring[]
- proxyProtocol
- modestring
- versionstring
- tcp
- keepalive
- intervalstring
- retriesinteger
- timestring
- tls
- alpnProtocolsstring[]
- cipherSuitesstring[]
- handshakeTimeoutstring
- keyExchangeGroupsstring[]
- maxProtocolVersionstring
- minProtocolVersionstring
- tracing
- attributes
- add
- *expressionstring
- *namestring
- removestring[]
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- clientSamplingstring
- filterstring
- pathstring
- protocolstring
- randomSamplingstring
- resources
- *expressionstring
- *namestring
- strategy
- inheritancestring
- targetRefs
- *groupstring
- *kindstring
- *namestring
- portinteger
- sectionNamestring
- targetSelectors
- *groupstring
- *kindstring
- *matchLabelsobject
- portinteger
- sectionNamestring
- traffic
- apiKeyAuthentication
- configMapSelector
- *matchLabelsobject
- location
- cookie
- *namestring
- expressionstring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- modestring
- secretRef
- groupstring
- kindstring
- *namestring
- secretSelector
- *matchLabelsobject
- authorization
- actionstring
- *policy
- *matchExpressionsstring[]
- basicAuthentication
- location
- cookie
- *namestring
- expressionstring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- modestring
- realmstring
- secretRef
- groupstring
- keystring
- kindstring
- *namestring
- usersstring[]
- buffer
- request
- failureModestring
- maxBytes
- response
- failureModestring
- maxBytes
- cors
- allowCredentialsboolean
- allowHeadersstring[]
- allowMethodsstring[]
- allowOriginsstring[]
- exposeHeadersstring[]
- maxAgeinteger
- csrf
- additionalOriginsstring[]
- delay
- *durationstring
- directResponse
- bodystring
- bodyExpressionstring
- conditional
- conditionstring
- *policy
- bodystring
- bodyExpressionstring
- headers
- *namestring
- *valuestring
- statusinteger
- headers
- *namestring
- *valuestring
- statusinteger
- extAuth
- backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- cache
- *keystring[]
- maxEntriesinteger
- *ttlstring
- conditional
- conditionstring
- *policy
- backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- cache
- *keystring[]
- maxEntriesinteger
- *ttlstring
- failureModestring
- forwardBody
- *maxSize
- grpc
- contextExtensionsobject
- requestMetadataobject
- http
- addRequestHeadersobject
- allowedRequestHeadersstring[]
- allowedResponseHeadersstring[]
- bodystring
- pathstring
- redirectstring
- responseMetadataobject
- failureModestring
- forwardBody
- *maxSize
- grpc
- contextExtensionsobject
- requestMetadataobject
- http
- addRequestHeadersobject
- allowedRequestHeadersstring[]
- allowedResponseHeadersstring[]
- bodystring
- pathstring
- redirectstring
- responseMetadataobject
- extProc
- backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- conditional
- conditionstring
- *policy
- backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- failureModestring
- metadataContextobject
- processingOptions
- allowModeOverrideboolean
- requestBodyModestring
- requestHeaderModestring
- requestTrailerModestring
- responseBodyModestring
- responseHeaderModestring
- responseTrailerModestring
- requestAttributesobject
- responseAttributesobject
- failureModestring
- metadataContextobject
- processingOptions
- allowModeOverrideboolean
- requestBodyModestring
- requestHeaderModestring
- requestTrailerModestring
- responseBodyModestring
- responseHeaderModestring
- responseTrailerModestring
- requestAttributesobject
- responseAttributesobject
- headerModifiers
- request
- add
- *namestring
- *valuestring
- removestring[]
- set
- *namestring
- *valuestring
- response
- add
- *namestring
- *valuestring
- removestring[]
- set
- *namestring
- *valuestring
- hostRewrite
- *modestring
- jwtAuthentication
- location
- cookie
- *namestring
- expressionstring
- header
- *namestring
- prefixstring
- queryParameter
- *namestring
- mcp
- clientIdstring
- providerstring
- resourceMetadataobject
- modestring
- *providers
- audiencesstring[]
- *issuerstring
- *jwks
- inlinestring
- remote
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- cacheDurationstring
- *jwksPathstring
- phasestring
- rateLimit
- conditional
- conditionstring
- *policy
- global
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *descriptors
- coststring
- *entries
- *expressionstring
- *namestring
- unitstring
- *domainstring
- failureModestring
- local
- burstinteger
- requestsinteger
- tokensinteger
- *unitstring
- global
- *backendRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- *descriptors
- coststring
- *entries
- *expressionstring
- *namestring
- unitstring
- *domainstring
- failureModestring
- local
- burstinteger
- requestsinteger
- tokensinteger
- *unitstring
- retry
- attemptsinteger
- backoffstring
- codesinteger[]
- conditionstring
- preconditionstring
- timeouts
- requeststring
- transformation
- conditional
- conditionstring
- *policy
- request
- add
- *namestring
- *valuestring
- bodystring
- metadataobject
- removestring[]
- set
- *namestring
- *valuestring
- response
- add
- *namestring
- *valuestring
- bodystring
- metadataobject
- removestring[]
- set
- *namestring
- *valuestring
- request
- add
- *namestring
- *valuestring
- bodystring
- metadataobject
- removestring[]
- set
- *namestring
- *valuestring
- response
- add
- *namestring
- *valuestring
- bodystring
- metadataobject
- removestring[]
- set
- *namestring
- *valuestring
- status
- *ancestors
- *ancestorRef
- groupstring
- kindstring
- *namestring
- namespacestring
- portinteger
- sectionNamestring
- *conditions
- *lastTransitionTimestring
- *messagestring
- observedGenerationinteger
- *reasonstring
- *statusstring
- *typestring
- *controllerNamestring
Servers should convert recognized schemas to the latest internal value, and
may reject unrecognized values.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#resources
Servers may infer this from the endpoint the client submits requests to.
Cannot be updated.
In CamelCase.
More info: https://git.k8s.io/community/contributors/devel/sig-architecture/api-conventions.md#types-kinds
Validation
Gateway (optionally, with asectionName indicating the listener), ListenerSet, Route(optionally, with a
sectionName indicating the route rule), or aService or Backend (optionally, with a sectionName indicating theport for
Service, or sub-backend for Backend).resource, like
Gateway, is just a way to easily apply a policy to agroup of backends.
merge. Precedence is given to more precise policies:
Gateway <Listener < Route < Route Rule < Backend or Service. Forexample, if a
Gateway policy sets tcp and tls, and a Backendpolicy sets
tls, the effective policy would be tcp from theGateway, and tls from the Backend.Validation
Documentation References (22)
connecting to a
Backend of type ai.Validation
Documentation References (13)
Validation
Validation
Validation
Example:
{"fast": "gpt-3.5-turbo", "smart": "gpt-4-turbo"}.Note: This field is only applicable when using the agentgateway data plane.
Validation
Validation
Validation
Validation
LLM providers that use the
CHAT or CHAT_STREAMING API route type.Documentation References (2)
Documentation References (1)
Documentation References (1)
LLM provider model, such as
SYSTEM or USER in the OpenAI API.Documentation References (1)
Documentation References (2)
Documentation References (2)
LLM provider model, such as
SYSTEM or USER in the OpenAI API.Documentation References (2)
providers, currently AWS Bedrock.
Reduces API costs by caching static content like system prompts and tool definitions.
Only applicable for Bedrock Claude 3+ and Nova models.
Documentation References (1)
conversation. 0 (default) places it at the second-to-last message.
Higher values move it N additional messages towards the start, clamped
to bounds.
Validation
Caches all messages in the conversation for cost savings.
Validation
Documentation References (1)
Inserts a cache point after all system messages.
Validation
Documentation References (1)
Inserts a cache point after all tool specifications.
Validation
Documentation References (1)
before caching is enabled. Uses rough heuristic (word count × 1.3) to estimate tokens.
Bedrock requires at least 1,024 tokens for caching to be effective.
Validation
Documentation References (1)
Validation
Validation
guarding.
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
aws: {} fordefault AWS SDK credential discovery.
Validation
Documentation References (1)
Ambient AWS credentials are used as the source credentials for STS.
Validation
Validation
Cost & Usage Report attribution. If unset, AWS generates a random name.
Validation
to produce the session name (RoleSessionName), for example
jwt.sub orrequest.headers["x-team"]. If the expression does not produce a validsession name at request time, the request is rejected.
Validation
& Usage Report, once activated. STS allows at most 50 per role session.
Validation
for example
jwt.sub or request.headers["x-app"]. Requests with invalidtag values are rejected.
Validation
Validation
Validation
us-east-1. Set this when thetarget AWS service is in a different region than the gateway. If unset,
typed AWS backends may provide this automatically; otherwise the ambient
AWS region is used.
Validation
Secret.The default Secret resolver expects
accessKey, secretKey, and optionalsessionToken keys.Validation
Documentation References (1)
SecretValidation
Documentation References (1)
bedrock, bedrock-agentcore, or execute-api). If unset, typed AWSbackends may provide this automatically.
Validation
Authorization header.This option is the least secure; usage of a
Secret is preferred.Validation
Authorization header withthe
Bearer prefix. Applies to key and secretRef.Validation
Validation
:) are not supportedValidation
Validation
Validation
Secret.By default, the value is read from the
Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromthe default
Authorization key.Validation
Validation
SecretValidation
Validation
Service appProtocol, HTTP2 for gRPC, the original protocol forplaintext HTTP, or
HTTP1 for HTTPS because clients often upgrade HTTPSto HTTP/2 even when the backend does not support it.
Validation
the destination.
Validation
connection.
If unset, this defaults to 180s.
Validation
If unset, this defaults to 9.
Validation
If unset, this defaults to 180s.
Validation
certificates, and SNI is inferred from the destination.
Validation
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
ConfigMap to use toverify the server certificate.
If unset, the system's trusted certificates are used.
Validation
WARNING: insecure; only use if the risks are understood
*
All disables all TLS verification*
Hostname trusts the CA certificate but ignores hostname/SAN mismatches.Still insecure; prefer
verifySubjectAltNames where possible.Validation
For example:
X25519_MLKEM768,X25519.tls.key and tls.crt from thereferenced credential source (defaulting to a Kubernetes
Secret). Anoptional
ca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateis used.
Validation
SecretValidation
SNI) to use in the TLShandshake. If unset, the
SNI is automatically set based on thedestination hostname.
Validation
SAN)to verify in the server certificate.
If not present, the destination hostname is automatically used.
Validation
HTTPS_PROXYSupported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
us-west-2).Validation
Documentation References (1)
Validation
Documentation References (1)
Documentation References (1)
us-central1.Defaults to
us-central1 if not specified.Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
gcp: {} for defaultGoogle credential discovery.
Validation
Documentation References (1)
aud value for the ID token. Onlyvalid with
IdToken type. If not set, the aud is automaticallyderived from the backend hostname.
Validation
a Kubernetes
Secret. By default, the value is read fromcredentials.json; set secretRef.key to override it. When omitted,ambient credentials are used.
Validation
Validation
SecretValidation
generally an
AccessToken is used. To authenticate to Cloud Run, anIdToken is used.Validation
Documentation References (1)
Validation
Service appProtocol, HTTP2 for gRPC, the original protocol forplaintext HTTP, or
HTTP1 for HTTPS because clients often upgrade HTTPSto HTTP/2 even when the backend does not support it.
Validation
the destination.
Validation
connection.
If unset, this defaults to 180s.
Validation
If unset, this defaults to 9.
Validation
If unset, this defaults to 180s.
Validation
certificates, and SNI is inferred from the destination.
Validation
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
ConfigMap to use toverify the server certificate.
If unset, the system's trusted certificates are used.
Validation
WARNING: insecure; only use if the risks are understood
*
All disables all TLS verification*
Hostname trusts the CA certificate but ignores hostname/SAN mismatches.Still insecure; prefer
verifySubjectAltNames where possible.Validation
For example:
X25519_MLKEM768,X25519.tls.key and tls.crt from thereferenced credential source (defaulting to a Kubernetes
Secret). Anoptional
ca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateis used.
Validation
SecretValidation
SNI) to use in the TLShandshake. If unset, the
SNI is automatically set based on thedestination hostname.
Validation
SAN)to verify in the server certificate.
If not present, the destination hostname is automatically used.
Validation
HTTPS_PROXYSupported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Validation
Documentation References (1)
Validation
Documentation References (1)
endpoint.
See https://developers.openai.com/api/reference/resources/moderations for more information.
Documentation References (2)
omni-moderation.Documentation References (2)
Validation
Documentation References (2)
Validation
Documentation References (2)
Authorization header. This option is the least secure; usage of aSecret is preferred.Validation
Authorizationheader with the
Bearer prefix. Applies to key and secretRef.Validation
Validation
:) are not supportedValidation
Validation
Validation
Secret. By default, the value is read from the Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromthe default
Authorization key.Validation
Documentation References (2)
Validation
SecretValidation
Documentation References (2)
Validation
Service appProtocol, HTTP2 for gRPC, the original protocol forplaintext HTTP, or
HTTP1 for HTTPS because clients often upgrade HTTPSto HTTP/2 even when the backend does not support it.
Validation
the destination.
Validation
connection.
If unset, this defaults to 180s.
Validation
If unset, this defaults to 9.
Validation
If unset, this defaults to 180s.
Validation
certificates, and SNI is inferred from the destination.
Validation
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
ConfigMap to use toverify the server certificate.
If unset, the system's trusted certificates are used.
Validation
WARNING: insecure; only use if the risks are understood
*
All disables all TLS verification*
Hostname trusts the CA certificate but ignores hostname/SAN mismatches.Still insecure; prefer
verifySubjectAltNames where possible.Validation
For example:
X25519_MLKEM768,X25519.tls.key and tls.crt from thereferenced credential source (defaulting to a Kubernetes
Secret). Anoptional
ca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateis used.
Validation
SecretValidation
SNI) to use in the TLShandshake. If unset, the
SNI is automatically set based on thedestination hostname.
Validation
SAN)to verify in the server certificate.
If not present, the destination hostname is automatically used.
Validation
HTTPS_PROXYSupported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Documentation References (3)
This setting applies only to request matches.
PromptguardResponsematches are always masked by default.
Defaults to
Mask.Validation
Documentation References (3)
Matches and built-ins are additive.
Documentation References (2)
Matches and built-ins are additive.
Documentation References (2)
The request was rejected due to inappropriate content.Validation
Documentation References (4)
The request was rejected due to inappropriate content.Validation
Documentation References (4)
Validation
Documentation References (1)
Documentation References (2)
Validation
Documentation References (2)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Documentation References (2)
Validation
Documentation References (2)
Validation
ServiceValidation
Documentation References (2)
or returns an error.
FailOpen allows the request to continue.FailClosed (default) rejects the request.Validation
Request headers are used when forwarding requests and response headers
are used when forwarding responses.
By default, no headers are forwarded.
Validation
Exact (default) or RegularExpression. The regex dialect is implementation-specificValidation
Validation
Validation
guarding.
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
aws: {} fordefault AWS SDK credential discovery.
Validation
Documentation References (1)
Ambient AWS credentials are used as the source credentials for STS.
Validation
Validation
Cost & Usage Report attribution. If unset, AWS generates a random name.
Validation
to produce the session name (RoleSessionName), for example
jwt.sub orrequest.headers["x-team"]. If the expression does not produce a validsession name at request time, the request is rejected.
Validation
& Usage Report, once activated. STS allows at most 50 per role session.
Validation
for example
jwt.sub or request.headers["x-app"]. Requests with invalidtag values are rejected.
Validation
Validation
Validation
us-east-1. Set this when thetarget AWS service is in a different region than the gateway. If unset,
typed AWS backends may provide this automatically; otherwise the ambient
AWS region is used.
Validation
Secret.The default Secret resolver expects
accessKey, secretKey, and optionalsessionToken keys.Validation
Documentation References (1)
SecretValidation
Documentation References (1)
bedrock, bedrock-agentcore, or execute-api). If unset, typed AWSbackends may provide this automatically.
Validation
Authorization header.This option is the least secure; usage of a
Secret is preferred.Validation
Authorization header withthe
Bearer prefix. Applies to key and secretRef.Validation
Validation
:) are not supportedValidation
Validation
Validation
Secret.By default, the value is read from the
Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromthe default
Authorization key.Validation
Validation
SecretValidation
Validation
Service appProtocol, HTTP2 for gRPC, the original protocol forplaintext HTTP, or
HTTP1 for HTTPS because clients often upgrade HTTPSto HTTP/2 even when the backend does not support it.
Validation
the destination.
Validation
connection.
If unset, this defaults to 180s.
Validation
If unset, this defaults to 9.
Validation
If unset, this defaults to 180s.
Validation
certificates, and SNI is inferred from the destination.
Validation
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
ConfigMap to use toverify the server certificate.
If unset, the system's trusted certificates are used.
Validation
WARNING: insecure; only use if the risks are understood
*
All disables all TLS verification*
Hostname trusts the CA certificate but ignores hostname/SAN mismatches.Still insecure; prefer
verifySubjectAltNames where possible.Validation
For example:
X25519_MLKEM768,X25519.tls.key and tls.crt from thereferenced credential source (defaulting to a Kubernetes
Secret). Anoptional
ca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateis used.
Validation
SecretValidation
SNI) to use in the TLShandshake. If unset, the
SNI is automatically set based on thedestination hostname.
Validation
SAN)to verify in the server certificate.
If not present, the destination hostname is automatically used.
Validation
HTTPS_PROXYSupported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
us-west-2).Validation
Documentation References (1)
Validation
Documentation References (1)
Documentation References (1)
us-central1.Defaults to
us-central1 if not specified.Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
gcp: {} for defaultGoogle credential discovery.
Validation
Documentation References (1)
aud value for the ID token. Onlyvalid with
IdToken type. If not set, the aud is automaticallyderived from the backend hostname.
Validation
a Kubernetes
Secret. By default, the value is read fromcredentials.json; set secretRef.key to override it. When omitted,ambient credentials are used.
Validation
Validation
SecretValidation
generally an
AccessToken is used. To authenticate to Cloud Run, anIdToken is used.Validation
Documentation References (1)
Validation
Service appProtocol, HTTP2 for gRPC, the original protocol forplaintext HTTP, or
HTTP1 for HTTPS because clients often upgrade HTTPSto HTTP/2 even when the backend does not support it.
Validation
the destination.
Validation
connection.
If unset, this defaults to 180s.
Validation
If unset, this defaults to 9.
Validation
If unset, this defaults to 180s.
Validation
certificates, and SNI is inferred from the destination.
Validation
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
ConfigMap to use toverify the server certificate.
If unset, the system's trusted certificates are used.
Validation
WARNING: insecure; only use if the risks are understood
*
All disables all TLS verification*
Hostname trusts the CA certificate but ignores hostname/SAN mismatches.Still insecure; prefer
verifySubjectAltNames where possible.Validation
For example:
X25519_MLKEM768,X25519.tls.key and tls.crt from thereferenced credential source (defaulting to a Kubernetes
Secret). Anoptional
ca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateis used.
Validation
SecretValidation
SNI) to use in the TLShandshake. If unset, the
SNI is automatically set based on thedestination hostname.
Validation
SAN)to verify in the server certificate.
If not present, the destination hostname is automatically used.
Validation
HTTPS_PROXYSupported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Validation
Documentation References (1)
Validation
Documentation References (1)
Documentation References (2)
This setting applies only to request matches.
PromptguardResponsematches are always masked by default.
Defaults to
Mask.Validation
Documentation References (2)
Matches and built-ins are additive.
Documentation References (2)
Matches and built-ins are additive.
The response was rejected due to inappropriate content.Validation
The request was rejected due to inappropriate content.Validation
Validation
Documentation References (2)
Validation
Documentation References (2)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Documentation References (2)
Validation
Documentation References (2)
Validation
ServiceValidation
Documentation References (2)
or returns an error.
FailOpen allows the request to continue.FailClosed (default) rejects the request.Validation
Request headers are used when forwarding requests and response headers
are used when forwarding responses.
By default, no headers are forwarded.
Validation
Exact (default) or RegularExpression. The regex dialect is implementation-specificValidation
Validation
Defaults to disabled to preserve streaming throughput unless explicitly enabled.
Validation
The keys are URL path suffixes matched using ends-with comparison, for
example
"/v1/chat/completions".The special
* wildcard matches any path.If not specified, all traffic defaults to
completions type.Documentation References (1)
The expression result overwrites any existing value for that field.
This has a higher priority than
overrides if both are set for the samekey.
Validation
Documentation References (2)
Validation
Documentation References (2)
Validation
Documentation References (2)
Validation
Documentation References (2)
When omitted, default AWS SDK credential discovery is used.
Validation
Ambient AWS credentials are used as the source credentials for STS.
Validation
Validation
Cost & Usage Report attribution. If unset, AWS generates a random name.
Validation
to produce the session name (RoleSessionName), for example
jwt.sub orrequest.headers["x-team"]. If the expression does not produce a validsession name at request time, the request is rejected.
Validation
& Usage Report, once activated. STS allows at most 50 per role session.
Validation
for example
jwt.sub or request.headers["x-app"]. Requests with invalidtag values are rejected.
Validation
Validation
Validation
us-east-1. Set this when thetarget AWS service is in a different region than the gateway. If unset,
typed AWS backends may provide this automatically; otherwise the ambient
AWS region is used.
Validation
Secret.The default Secret resolver expects
accessKey, secretKey, and optionalsessionToken keys.Validation
SecretValidation
bedrock, bedrock-agentcore, or execute-api). If unset, typed AWSbackends may provide this automatically.
Validation
Validation
Secret. The default Secret resolver expects clientID, tenantID, andclientSecret keys.Validation
SecretValidation
Azure env vars projected into the data plane pod. Recommended on AKS with
Workload Identity enabled.
Validation
Validation
Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Validation
Validation
Validation
Validation
Validation
signingKey key by default with a PEM-encoded RSAor EC private key; override the key name via
signingKeyRef.key.Validation
Validation
SecretValidation
clientSecret key by default; override viasecretRef.key. When omitted, client_id is sent without a secret, whichis only valid with ClientSecretPost.
Validation
Validation
SecretValidation
Validation
Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Validation
Validation
Validation
Validation
Validation
signingKey key by default with a PEM-encoded RSAor EC private key; override the key name via
signingKeyRef.key.Validation
Validation
SecretValidation
clientSecret key by default; override viasecretRef.key. When omitted, client_id is sent without a secret, whichis only valid with ClientSecretPost.
Validation
Validation
SecretValidation
Validation
Validation
Validation
ID token read from the Authorization Bearer header.
Validation
Validation
Validation
:) are not supportedValidation
Validation
Validation
When omitted, default Google credential discovery is used.
Validation
Documentation References (1)
aud value for the ID token. Onlyvalid with
IdToken type. If not set, the aud is automaticallyderived from the backend hostname.
Validation
Documentation References (1)
a Kubernetes
Secret. By default, the value is read fromcredentials.json; set secretRef.key to override it. When omitted,ambient credentials are used.
Validation
Validation
SecretValidation
generally an
AccessToken is used. To authenticate to Cloud Run, anIdToken is used.Validation
Documentation References (1)
Authorization header. This option is the least secure; usage of aSecret is preferred.Validation
Authorizationheader with the
Bearer prefix. Applies to key, secretRef, andpassthrough.Validation
Validation
:) are not supportedValidation
Validation
Validation
Validation
Documentation References (1)
Validation
Validation
Validation
Validation
Validation
:) are not supportedValidation
Validation
Validation
are supported for actor tokens.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Documentation References (1)
Service. Defaults to ServiceValidation
Documentation References (1)
Validation
Documentation References (1)
Validation
ServiceValidation
Validation
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Validation
signingKey key by default with a PEM-encoded RSAor EC private key; override the key name via
signingKeyRef.key.Validation
Validation
SecretValidation
clientSecret key by default; override viasecretRef.key. When omitted, client_id is sent without a secret, whichis only valid with ClientSecretPost.
Validation
Documentation References (1)
Validation
SecretValidation
Documentation References (1)
Validation
Documentation References (1)
Defaults to Authorization: Bearer.
Validation
Validation
:) are not supportedValidation
Validation
Validation
Validation
Documentation References (1)
built-in values may be requested; custom URIs are not supported here.
Validation
Validation
Validation
Documentation References (1)
The token type may be a built-in value or a custom absolute URI for providers
that support custom token exchange profiles.
expression variant is permitted.Validation
Validation
Validation
:) are not supportedValidation
Validation
Validation
are supported for subject tokens.
may strip client credentials; passthrough adds the original token back to
the backend request. Without client auth policies, this has no effect.
Secret. By default, the value is read from the Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromthe default
Authorization key.Validation
Validation
SecretValidation
sent to this backend.
Validation
Documentation References (1)
Service and Backend.Validation
Documentation References (1)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (1)
Validation
ServiceValidation
Documentation References (1)
capturing every request property that the authorization service uses to
make a decision. For example, if the service returns different results
based on both path and authorization header, both must be included in
key; otherwise, one request may incorrectly reuse another request'sauthorization result.
the request is still sent to the authorization service, but its result is
not read from or written to the cache.
Documentation References (1)
to construct the cache key.
Validation
Documentation References (1)
the cache. If unset, this defaults to 10000.
Validation
Documentation References (1)
5m, or a CEL expression thatreturns the duration that cached authorization results may be reused, or a
timestamp when the cached authorization result expires. The expression is
evaluated after the authorization response has been applied to the request.
Validation
Documentation References (1)
unavailable or returns an error. "FailOpen" allows the request to continue.
"FailClosed" (default) denies the request.
Validation
If enabled, the request body will be buffered.
and sent to the authorization server. If the body size is larger than
maxSize, then the request will be rejected with a response.Validation
[protocol](https://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto) should be used.
Documentation References (1)
send to the authorization server in the
context_extensions field.Validation
server. This maps to the
metadata_context.filter_metadata field of therequest, and allows dynamic CEL expressions. If unset, by default the
envoy.filters.http.jwt_authn key is set if the JWT policy is used aswell, for compatibility.
Validation
the authorization server. The authorization server must return a
200status code, otherwise the request is considered an authorization
failure.
request to the authorization server. While
allowedRequestHeaders justpasses the original headers through,
addRequestHeaders allows definingcustom headers based on CEL expressions.
Validation
will be sent to the authorization server.
Authorization.Validation
will be copied into the request to the backend.
Validation
Strings and bytes are used directly; other values are JSON-encoded.
Validation
unset, this defaults to the original request path.
This is a CEL expression, which allows customizing the path based on the
incoming request. For example, to add a prefix, use
"/prefix/" + request.path.Validation
redirect to on authorization failure. This is useful to redirect to a
sign-in page.
Validation
from the authorization response. These will be included under the
extauthz variable in future CEL expressions. Setting this is usefulfor things like logging usernames, without needing to include them as
headers to the backend, as
allowedResponseHeaders would.Validation
Documentation References (2)
Documentation References (2)
For example, a value of 5 means the backend must receive 5 unhealthy responses in a row before being evicted.
When both consecutiveFailures and healthThreshold are set, the backend is evicted when either condition is met.
When neither is set, a single unhealthy response can trigger eviction.
Validation
Documentation References (2)
Subsequent evictions use multiplicative backoff (duration * times_evicted).
If all endpoints are evicted, the load balancer falls back to returning evicted endpoints
rather than failing entirely.
If unset, defaults to
3s.Validation
Documentation References (2)
only if its computed health drops below this value after an unhealthy
response (e.g. 50 evicts when EWMA health falls below 50%). Unlike
consecutiveFailures, this sliding-window average lets a single success delay
eviction. If both are set, either condition evicts; if neither, a single
unhealthy response evicts.
Validation
For gradual recovery, set below 100; for full recovery immediately, set 100.
If unset, the backend resumes with the health it had when evicted.
Validation
Documentation References (1)
When the expression evaluates to true, the backend is considered unhealthy and may be evicted.
response.code >= 500.This default lowers the backend's health score but does not trigger eviction on its own.
Validation
Documentation References (2)
Documentation References (1)
Validation
Documentation References (1)
Service appProtocol, HTTP2 for gRPC, the original protocol forplaintext HTTP, or
HTTP1 for HTTPS because clients often upgrade HTTPSto HTTP/2 even when the backend does not support it.
Validation
connecting to a
Backend of type mcp.Validation
Documentation References (3)
jwtAuthentication.mcp, which ensures authentication runs beforeother policies such as transformation and rate limiting.
access. This corresponds to the
aud claim([RFC 7519 §4.1.3](https://datatracker.ietf.org/doc/html/rfc7519#section-4.1.3)).
If unset, any audience is allowed.
Validation
If set, the gateway will not proxy registration requests to the IDP and instead return this client ID.
registration identified by
clientId (for example Entra ID confidential clients,which require the secret at the token endpoint). The gateway injects it into the
token requests it proxies to the provider. Defaults to the
clientSecret key;override via
clientSecretRef.key.Validation
Validation
SecretValidation
iss claim ([RFC 7519 §4.1.1](https://tools.ietf.org/html/rfc7519#section-4.1.1)).Validation
the JWT.
Supported types are
Service and static Backend. AnAgentgatewayPolicy containing backend TLS config can then be attachedto the
Service or Backend in order to set TLS options for aconnection to the remote
jwks source.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Validation
jwks endpoint, relative to the root, commonly".well-known/jwks.json".Validation
Validation
Validation
unauthorized requests with a
403 error, this policy works at theMCPBackend level.list_tools, will have each item evaluated.Items that do not meet the rule will be filtered.
call_tool, will evaluate the specificitem and reject requests that do not meet the rule.
Documentation References (1)
If unspecified, defaults to
Allow.Require rules are cumulative: all require rules must match.Validation
Documentation References (1)
Allow: any matching allow rule allows the request.*
Require: every require rule must match for the request to be allowed.*
Deny: any matching deny rule denies the request.Requirefor deny-by-default behavior.
Allow rule is configured, requests are denied unless atleast one allow rule matches.
Documentation References (1)
Validation
Documentation References (1)
guardrails routes selected JSON-RPC methods through a remote policy server.Documentation References (2)
processors is the ordered list of policy processors applied to matchedmethods. Processors run in the order listed; the first to reject a request
short-circuits the chain.
Validation
Documentation References (2)
methods is the allowlist of JSON-RPC methods (e.g. tools/call,tools/list) routed through this processor, keyed by method name with thephase it runs in. Keys may be exact, a prefix wildcard (
tools/*), a suffixwildcard (
*/list), or * for all methods; the most specific match wins.Methods matching no key, including unknown ones, bypass this processor.
Validation
Documentation References (2)
remote configures a gRPC policy server.Documentation References (2)
allowedRequestHeaders lists the incoming request headers forwarded tothe policy server in
McpRequest.headers. If empty, all headers andpseudo-headers (
:authority, :method, ...) are forwarded. Matching iscase-insensitive.
Validation
backendRef references the remote guardrails policy server.Supported types:
Service and Backend.Validation
Documentation References (2)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (2)
Validation
ServiceValidation
Documentation References (2)
disallowedRequestHeaders lists header names never forwarded to thepolicy server, even if listed in
allowedRequestHeaders. Matching iscase-insensitive.
Validation
failureMode controls behavior when the policy server is unreachableor returns an error.
FailOpen allows the request; FailClosed(default) denies it.
Validation
Documentation References (2)
metadata is static or CEL-evaluated context surfaced to the policyserver as fields of the
metadata_context google.protobuf.Struct,keyed by config key. Values are CEL expressions.
Validation
the destination.
Validation
connection.
If unset, this defaults to 180s.
Validation
If unset, this defaults to 9.
Validation
If unset, this defaults to 180s.
Validation
certificates, and SNI is inferred from the destination.
Validation
Documentation References (1)
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
ConfigMap to use toverify the server certificate.
If unset, the system's trusted certificates are used.
Validation
WARNING: insecure; only use if the risks are understood
*
All disables all TLS verification*
Hostname trusts the CA certificate but ignores hostname/SAN mismatches.Still insecure; prefer
verifySubjectAltNames where possible.Validation
For example:
X25519_MLKEM768,X25519.tls.key and tls.crt from thereferenced credential source (defaulting to a Kubernetes
Secret). Anoptional
ca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateis used.
Validation
Documentation References (1)
SecretValidation
Documentation References (1)
SNI) to use in the TLShandshake. If unset, the
SNI is automatically set based on thedestination hostname.
Validation
Documentation References (1)
SAN)to verify in the server certificate.
If not present, the destination hostname is automatically used.
Validation
Validation
Validation
should be set to. If there is already a header with these values then
append the value as an extra entry.
Validation
Validation
the header.
Validation
Validation
metadata CEL variablefor subsequent policy evaluations.
metadata is evaluated before headeror body transformations.
Validation
response.
Validation
Validation
Validation
the header.
Validation
Validation
should be set to. If there is already a header with these values then
append the value as an extra entry.
Validation
Validation
the header.
Validation
Validation
metadata CEL variablefor subsequent policy evaluations.
metadata is evaluated before headeror body transformations.
Validation
response.
Validation
Validation
Validation
the header.
Validation
HTTPS_PROXYSupported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
Gateway. Listener andListenerSet are not valid targets.merge. For example, policy A sets
tcp and tls, and policy B setstls; the effective policy would be tcp from policy A, and tls frompolicy B.
Validation
Documentation References (2)
logged.
Validation
Documentation References (2)
The value is a CEL expression. If the CEL expression fails to evaluate,
the pair will be excluded.
Validation
Documentation References (2)
Validation
Documentation References (2)
Validation
Documentation References (2)
http.method.Validation
will only be emitted if the expression evaluates to
true.Validation
Documentation References (2)
OpenTelemetry-compatible backend.
Validation
If unset, the parent access log attributes are used.
Validation
The value is a CEL expression. If the CEL expression fails to evaluate,
the pair will be excluded.
Validation
Validation
Validation
http.method.Validation
Supported types:
Service and AgentgatewayBackend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
will only be exported if the expression evaluates to
true.If unset, the parent access log filter is used.
Validation
when
protocol is HTTP. If unset, this defaults to /v1/logs.Validation
Validation
Validation
Validation
Documentation References (4)
This only applies to
HTTP/1. If a request is HTTP/2 in either the incoming or outgoing request, this will be ignored.HTTP/2 requests are always lower case.
Validation
closed.
If unset, this defaults to 10 minutes.
Validation
Documentation References (1)
in
HTTP/1.1 requests.If unset, this defaults to 100.
Validation
Documentation References (1)
connection-level flow control for received data.
Validation
Documentation References (1)
If unset, this defaults to
16kb.Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
request headers.
If unset, this defaults to
16Ki.Validation
control for received data.
Validation
Documentation References (1)
into memory.
Bodies will only be buffered for policies which require buffering.
If unset, this defaults to
2mb.Validation
Documentation References (1)
After this duration, the connection is gracefully closed after the current in-flight request completes.
Useful for ensuring even traffic distribution behind load balancers during scaling events.
Validation
CEL expressions are evaluated per-request and added as labels to all
Prometheus metrics exposed by agentgateway.
Documentation References (1)
added to Prometheus metrics.
Validation
Documentation References (1)
to all Prometheus metrics. The value is a CEL expression evaluated
per-request. If the CEL expression fails to evaluate, the label value
is set to "unknown".
increase Prometheus storage and memory usage. Prefer low-cardinality
dimensions like team or environment.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
for example using
source.address with cidr(...).containsIP(...).If unspecified, defaults to
Allow.Require rules are cumulative: all require rules must match.Validation
Allow: any matching allow rule allows the request.*
Require: every require rule must match for the request to be allowed.*
Deny: any matching deny rule denies the request.Requirefor deny-by-default behavior.
Allow rule is configured, requests are denied unless atleast one allow rule matches.
Validation
normal protocol handling. This can also be configured to allow both
PROXY and non-PROXY traffic on the same listener.
Strict.Validation
V2.Validation
Validation
Documentation References (1)
Documentation References (1)
If unset, this defaults to 180s.
Validation
Documentation References (1)
If unset, this defaults to 9.
Validation
Documentation References (1)
If unset, this defaults to 180s.
Validation
Documentation References (1)
Validation
Documentation References (1)
ALPN)value to use in the TLS handshake.
["h2", "http/1.1"].Validation
Documentation References (1)
The value is a comma-separated list of cipher suites, for example
TLS13_AES_256_GCM_SHA384,TLS13_AES_128_GCM_SHA256.Use this in the TLS options field of a TLS listener.
Documentation References (1)
complete. If unset, this defaults to
15s.Validation
Documentation References (1)
For example:
X25519_MLKEM768,X25519.Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
included in the trace.
Validation
Documentation References (1)
The value is a CEL expression. If the CEL expression fails to evaluate,
the pair will be excluded.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
http.method.Validation
Supported types:
Service and AgentgatewayBackend.Validation
Documentation References (1)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (1)
Validation
Documentation References (1)
ServiceValidation
Documentation References (1)
sampling. Client sampling determines whether to initiate a new trace
span if the incoming request does have a trace already. This should
evaluate to a float between
0.0 and 1.0, or a boolean (true orfalse). If unspecified, client sampling is 100% enabled.Validation
Documentation References (1)
This uses keep semantics: spans are exported only when the expression
evaluates to
true. If unspecified, all sampled spans are exported.Validation
protocol is HTTP. If unset, this defaults to /v1/traces.Validation
Validation
Documentation References (1)
sampling. Random sampling will initiate a new trace span if the incoming
request does not have a trace initiated already. This should evaluate to
a float between
0.0 and 1.0, or a boolean (true or false). Ifunspecified, random sampling is disabled.
Validation
Documentation References (1)
resources to be included in the trace.
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
only be valid for specific policy kinds; for example, inheritance is only valid when this
policy contains traffic settings.
from contributing to the effective policy.
inheritance.
Default, traffic policy fields are merged by specificity, with more-specificattachment points such as routes and route rules able to override fields from less-specific
attachment points such as gateways and listeners.
In other words, this policy provides
Defaults that can be overridden. For example, you may provide a Defaulttimeout policy for the entire Gateway that is overridden by specific routes.
Override, this policy blocks traffic policies at more-specific attachment points frombeing included in the effective policy. This is useful when a gateway-level policy must remain
authoritative for all routes below it.
Validation
policy to.
Validation
For Kubernetes Gateway API resources, the group is
gateway.networking.k8s.io.Validation
Gateway or HTTPRoute.Validation
Validation
At most one of
sectionName or port may be set.Only valid on frontend policies targeting a
Gateway.Validation
Validation
Validation
For Kubernetes Gateway API resources, the group is
gateway.networking.k8s.io.Validation
Gateway or HTTPRoute.Validation
At most one of
sectionName or port may be set.Only valid on frontend policies targeting a
Gateway.Validation
Validation
Gateway (optionally, with asectionName indicating the listener), ListenerSet, or Route(optionally, with a
sectionName indicating the route rule).merge. Precedence is given to more precise policies:
Gateway <Listener < Route < Route Rule. For example, policy A setstimeouts and retries, and policy B sets retries; the effectivepolicy would be
timeouts from policy A, and retries from policy B.Validation
Documentation References (46)
key.
Validation
Documentation References (2)
ConfigMap resourcescontaining API keys. It is ConfigMap-only; use
secretRef orsecretSelector for Secret-backed credentials. If the same key isdefined in multiple ConfigMaps, the behavior is undefined.
ConfigMap must use
keyHash; a raw key value is rejected.ConfigMap data represents one API key. The key isan arbitrary identifier. The value must be a JSON object with
keyHash, plus optional metadata. keyHash contains a hashed APIkey in
sha256:<hex> format. metadata contains arbitrary JSONmetadata associated with the key, which may be used by other
policies. For example, you may write an authorization policy allowing
apiKey.group == 'sales'.apiVersion: v1
kind: ConfigMap
metadata:
name: api-key
data:
client1: |
{
"keyHash": "sha256:efa299afb8c12a36e47a790cbbf929caa06d13285950410463fb759af17d0dad",
"metadata": {
"group": "sales"
}
}If omitted, credentials are read from the
Authorization header with the Bearer prefix.Validation
Validation
Validation
:) are not supportedValidation
Validation
Validation
Validation
Documentation References (2)
Secret, storing a set of API keys. If many keys are needed,secretSelector or configMapSelector can be used instead.Note that ConfigMap-backed API keys only support
keyHash.arbitrary identifier. The value can either be:
* A string representing the API key.
* A JSON object with
key or keyHash, plus optional metadata.key contains the API key. keyHash contains a hashed API key insha256:<hex> format. metadata contains arbitrary JSON metadataassociated with the key, which may be used by other policies. For
example, you may write an authorization policy allowing
apiKey.group == 'sales'.apiVersion: v1
kind: Secret
metadata:
name: api-key
stringData:
client1: |
{
"key": "k-123",
"metadata": {
"group": "sales",
"created_at": "2024-10-01T12:00:00Z"
}
}
client2: "k-456"
client3: |
{
"keyHash": "sha256:efa299afb8c12a36e47a790cbbf929caa06d13285950410463fb759af17d0dad",
"metadata": {
"group": "engineering"
}
}Validation
Documentation References (1)
SecretValidation
Documentation References (1)
Secret resourcescontaining API keys. It is Secret-only; use
secretRef for othercredential kinds. If the same key is defined in multiple secrets, the
behavior is undefined.
Secret data represents one API key. The key is anarbitrary identifier. The value can either be:
* A string representing the API key.
* A JSON object with
key or keyHash, plus optional metadata.key contains the API key. keyHash contains a hashed API key insha256:<hex> format. metadata contains arbitrary JSON metadataassociated with the key, which may be used by other policies. For
example, you may write an authorization policy allowing
apiKey.group == 'sales'.apiVersion: v1
kind: Secret
metadata:
name: api-key
stringData:
client1: |
{
"key": "k-123",
"metadata": {
"group": "sales",
"created_at": "2024-10-01T12:00:00Z"
}
}
client2: "k-456"Documentation References (2)
Documentation References (2)
permissions.
If multiple authorization rules are applied across different policies, at the same or different attachment points,
all rules are merged.
Documentation References (3)
If unspecified, defaults to
Allow.Require rules are cumulative: all require rules must match.Validation
Documentation References (3)
Allow: any matching allow rule allows the request.*
Require: every require rule must match for the request to be allowed.*
Deny: any matching deny rule denies the request.Requirefor deny-by-default behavior.
Allow rule is configured, requests are denied unless atleast one allow rule matches.
Documentation References (3)
Validation
Documentation References (3)
Basicauthentication scheme (RFC 7617), where a username and password are
encoded in the request.
Validation
If omitted, credentials are read from the
Authorization header with the Basic prefix.Validation
Validation
Validation
:) are not supportedValidation
Validation
Validation
Validation
realm value to return in the WWW-Authenticateheader for failed authentication requests. If unset,
Restricted willbe used.
Secret, storing the .htaccess file. When using the default Secretresolver, the
Secret must have a key named .htaccess by default;override via
secretRef.key. The value should contain the complete.htaccess file.htpasswd or similar commandsto generate a hash. MD5, bcrypt, crypt, and SHA-1 are supported.
apiVersion: v1
kind: Secret
metadata:
name: basic-auth
stringData:
.htaccess: |
alice:$apr1$3zSE0Abt$IuETi4l5yO87MuOrbSE4V.
bob:$apr1$Ukb5LgRD$EPY2lIfY.A54jzLELNIId/Validation
Validation
SecretValidation
be accepted. Each entry represents one line of the
htpasswd format:https://httpd.apache.org/docs/2.4/programs/htpasswd.html.
htpasswd or similar commandsto generate a hash. MD5, bcrypt, crypt, and SHA-1 are supported.
users:
- "user1:$apr1$ivPt0D4C$DmRhnewfHRSrb3DQC.WHC."
- "user2:$2y$05$r3J4d3VepzFkedkd/q1vI.pBYIpSqjfN0qOARV3ScUHysatnS0cL2"Validation
by the proxy until completion before being forwarded. This changes the proxies default behavior, which streams bodies.
Validation
Documentation References (1)
Documentation References (1)
If unset, defaults to FailClosed, returning 413 for oversized requests and 502 for oversized responses.
Validation
If unset, defaults to the global proxy setting, which defaults to 2Mi.
Validation
Documentation References (1)
Documentation References (1)
If unset, defaults to FailClosed, returning 413 for oversized requests and 502 for oversized responses.
Validation
If unset, defaults to the global proxy setting, which defaults to 2Mi.
Validation
Documentation References (1)
Validation
Documentation References (1)
to include credentials.
Access-Control-Allow-Credentialsresponse header with value true (case-sensitive).
Access-Control-Allow-Credentials entirely (this is the standard CORSbehavior).
* for all. Sets Access-Control-Allow-Headers. Support: ExtendedValidation
Documentation References (1)
* for all. CORS-safelisted methods (GET, HEAD, POST) are always allowed. Sets Access-Control-Allow-Methods. Support: ExtendedValidation
Documentation References (1)
<scheme>://<host>(:<port>); the host may use the * wildcard, and a bare * allows all origins. Sets Access-Control-Allow-Origin. When credentials are allowed, a specific origin is echoed instead of *. Support: ExtendedValidation
Documentation References (1)
* for all. Sets Access-Control-Expose-Headers. Support: ExtendedValidation
results of a "preflight" request.
Access-Control-Allow-Methods andAccess-Control-Allow-Headers response headers can be cached by theclient until the time specified by
Access-Control-Max-Age elapses.Access-Control-Max-Age response header is 5(seconds).
MaxAge field is unspecified, the gateway sets the responseheader "Access-Control-Max-Age: 5" by default.
Validation
Documentation References (1)
* Safe methods (
GET, HEAD, OPTIONS) are automatically allowed.* Requests without
Sec-Fetch-Site or Origin headers are assumed tobe same-origin or non-browser requests and are allowed.
* Otherwise, the
Sec-Fetch-Site header is checked, with a fallback tocomparing the
Origin header to the Host header.Documentation References (1)
allowed in addition to the destination origin. The
Origin consists ofa scheme and a host, with an optional port, and takes the form
<scheme>://<host>(:<port>).Validation
Documentation References (1)
fault-injection testing.
as
2s, or a CEL expression evaluated against the request that returns a duration (e.g.duration("500ms")) or a number interpreted as milliseconds (e.g. random() < 0.1 ? 500 : 0for probabilistic delay, or
int(random() * 500) for jitter). A non-positive result injectsno delay.
Validation
client.
Validation
Documentation References (2)
The maximum length of the body is restricted to prevent excessively large responses.
If this field is omitted, no body is included in the response.
Validation
Documentation References (1)
Strings and bytes are written directly; other values are serialized as JSON.
If this field is omitted, no expression body is included in the response.
Validation
The first matching policy will be executed.
A single policy may be provided without a condition set; if so, it must be the last policy and will be the fallback
in case no conditions are met.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
The maximum length of the body is restricted to prevent excessively large responses.
If this field is omitted, no body is included in the response.
Validation
Documentation References (1)
Strings and bytes are written directly; other values are serialized as JSON.
If this field is omitted, no expression body is included in the response.
Validation
Validation
Validation
the header.
Validation
Validation
Documentation References (1)
Validation
Validation
the header.
Validation
Validation
Documentation References (1)
This selects the external server to send requests to for authentication.
conditional field.Validation
Documentation References (3)
Service and Backend.Validation
Documentation References (2)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (2)
Validation
Documentation References (2)
ServiceValidation
Documentation References (2)
capturing every request property that the authorization service uses to
make a decision. For example, if the service returns different results
based on both path and authorization header, both must be included in
key; otherwise, one request may incorrectly reuse another request'sauthorization result.
the request is still sent to the authorization service, but its result is
not read from or written to the cache.
Documentation References (1)
to construct the cache key.
Validation
Documentation References (1)
the cache. If unset, this defaults to 10000.
Validation
Documentation References (1)
5m, or a CEL expression thatreturns the duration that cached authorization results may be reused, or a
timestamp when the cached authorization result expires. The expression is
evaluated after the authorization response has been applied to the request.
Validation
Documentation References (1)
The first matching policy will be executed.
A single policy may be provided without a condition set; if so, it must be the last policy and will be the fallback
in case no conditions are met.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
Service and Backend.Validation
Documentation References (1)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (1)
Validation
ServiceValidation
Documentation References (1)
capturing every request property that the authorization service uses to
make a decision. For example, if the service returns different results
based on both path and authorization header, both must be included in
key; otherwise, one request may incorrectly reuse another request'sauthorization result.
the request is still sent to the authorization service, but its result is
not read from or written to the cache.
to construct the cache key.
Validation
the cache. If unset, this defaults to 10000.
Validation
5m, or a CEL expression thatreturns the duration that cached authorization results may be reused, or a
timestamp when the cached authorization result expires. The expression is
evaluated after the authorization response has been applied to the request.
Validation
unavailable or returns an error. "FailOpen" allows the request to continue.
"FailClosed" (default) denies the request.
Validation
Documentation References (1)
If enabled, the request body will be buffered.
and sent to the authorization server. If the body size is larger than
maxSize, then the request will be rejected with a response.Validation
[protocol](https://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto) should be used.
Documentation References (1)
send to the authorization server in the
context_extensions field.Validation
server. This maps to the
metadata_context.filter_metadata field of therequest, and allows dynamic CEL expressions. If unset, by default the
envoy.filters.http.jwt_authn key is set if the JWT policy is used aswell, for compatibility.
Validation
the authorization server. The authorization server must return a
200status code, otherwise the request is considered an authorization
failure.
request to the authorization server. While
allowedRequestHeaders justpasses the original headers through,
addRequestHeaders allows definingcustom headers based on CEL expressions.
Validation
will be sent to the authorization server.
Authorization.Validation
will be copied into the request to the backend.
Validation
Strings and bytes are used directly; other values are JSON-encoded.
Validation
unset, this defaults to the original request path.
This is a CEL expression, which allows customizing the path based on the
incoming request. For example, to add a prefix, use
"/prefix/" + request.path.Validation
redirect to on authorization failure. This is useful to redirect to a
sign-in page.
Validation
from the authorization response. These will be included under the
extauthz variable in future CEL expressions. Setting this is usefulfor things like logging usernames, without needing to include them as
headers to the backend, as
allowedResponseHeaders would.Validation
unavailable or returns an error. "FailOpen" allows the request to continue.
"FailClosed" (default) denies the request.
Validation
If enabled, the request body will be buffered.
and sent to the authorization server. If the body size is larger than
maxSize, then the request will be rejected with a response.Validation
[protocol](https://www.envoyproxy.io/docs/envoy/latest/api-v3/service/auth/v3/external_auth.proto) should be used.
Documentation References (1)
send to the authorization server in the
context_extensions field.Validation
server. This maps to the
metadata_context.filter_metadata field of therequest, and allows dynamic CEL expressions. If unset, by default the
envoy.filters.http.jwt_authn key is set if the JWT policy is used aswell, for compatibility.
Validation
the authorization server. The authorization server must return a
200status code, otherwise the request is considered an authorization
failure.
Documentation References (1)
request to the authorization server. While
allowedRequestHeaders justpasses the original headers through,
addRequestHeaders allows definingcustom headers based on CEL expressions.
Validation
will be sent to the authorization server.
Authorization.Validation
will be copied into the request to the backend.
Validation
Documentation References (1)
Strings and bytes are used directly; other values are JSON-encoded.
Validation
unset, this defaults to the original request path.
This is a CEL expression, which allows customizing the path based on the
incoming request. For example, to add a prefix, use
"/prefix/" + request.path.Validation
Documentation References (1)
redirect to on authorization failure. This is useful to redirect to a
sign-in page.
Validation
from the authorization response. These will be included under the
extauthz variable in future CEL expressions. Setting this is usefulfor things like logging usernames, without needing to include them as
headers to the backend, as
allowedResponseHeaders would.Validation
Validation
Documentation References (2)
Supported types:
Service and Backend.Validation
Documentation References (1)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (1)
Validation
Documentation References (1)
ServiceValidation
Documentation References (1)
The first matching policy will be executed.
A single policy may be provided without a condition set; if so, it must be the last policy and will be the fallback
in case no conditions are met.
Validation
Documentation References (2)
Validation
Documentation References (2)
Validation
Documentation References (2)
Supported types:
Service and Backend.Validation
Documentation References (2)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Documentation References (2)
Validation
Documentation References (1)
ServiceValidation
Documentation References (2)
"FailOpen" allows the request to continue, as long as the request body has not
been sent (or started streaming) to the ext_proc. Once the request body has
started streaming to the ext_proc, the request will fail closed on error.
"FailClosed" (default) rejects the request on any failure.
Validation
metadata_context.filter_metadata field of the ProcessingRequest.Keyed by metadata namespace, then by key within that namespace; values are
CEL expressions evaluated per request.
Validation
Documentation References (1)
mode_override values from matching header responses to updatesubsequent request/response processing phases for this exchange. Defaults to
false.Validation
Buffered buffers the full body and returns an error if it exceeds 8KB.BufferedPartial buffers up to 8KB and sends the buffered prefix if thebody exceeds that limit. Defaults to
FullDuplexStreamed.Validation
Documentation References (1)
Defaults to
Send.Validation
Defaults to
Send.Validation
Buffered buffers the full body and returns an error if it exceeds 8KB.BufferedPartial buffers up to 8KB and sends the buffered prefix if thebody exceeds that limit. Defaults to
FullDuplexStreamed.Validation
Documentation References (1)
Defaults to
Send.Validation
Defaults to
Send.Validation
attributes field of the ProcessingRequest. Values are CEL expressionsevaluated per request.
Validation
attributes field of the ProcessingRequest. Values are CEL expressionsevaluated per response.
Validation
"FailOpen" allows the request to continue, as long as the request body has not
been sent (or started streaming) to the ext_proc. Once the request body has
started streaming to the ext_proc, the request will fail closed on error.
"FailClosed" (default) rejects the request on any failure.
Validation
metadata_context.filter_metadata field of the ProcessingRequest.Keyed by metadata namespace, then by key within that namespace; values are
CEL expressions evaluated per request.
Validation
Documentation References (1)
mode_override values from matching header responses to updatesubsequent request/response processing phases for this exchange. Defaults to
false.Validation
Documentation References (1)
Buffered buffers the full body and returns an error if it exceeds 8KB.BufferedPartial buffers up to 8KB and sends the buffered prefix if thebody exceeds that limit. Defaults to
FullDuplexStreamed.Validation
Documentation References (1)
Defaults to
Send.Validation
Documentation References (1)
Defaults to
Send.Validation
Documentation References (1)
Buffered buffers the full body and returns an error if it exceeds 8KB.BufferedPartial buffers up to 8KB and sends the buffered prefix if thebody exceeds that limit. Defaults to
FullDuplexStreamed.Validation
Documentation References (1)
Defaults to
Send.Validation
Documentation References (1)
Defaults to
Send.Validation
Documentation References (1)
attributes field of the ProcessingRequest. Values are CEL expressionsevaluated per request.
Validation
attributes field of the ProcessingRequest. Values are CEL expressionsevaluated per response.
Validation
Validation
before the action. It appends to any existing values associated
with the header name.
GET /foo HTTP/1.1
my-header: foo
add:
- name: "my-header"
value: "bar,baz"
GET /foo HTTP/1.1
my-header: foo,bar,baz
Validation
Validation
Validation
value of Remove is a list of HTTP header names. Note that the header
names are case-insensitive (see
https://datatracker.ietf.org/doc/html/rfc2616#section-4.2).
GET /foo HTTP/1.1
my-header1: foo
my-header2: bar
my-header3: baz
remove: ["my-header1", "my-header3"]
GET /foo HTTP/1.1
my-header2: bar
Validation
before the action.
GET /foo HTTP/1.1
my-header: foo
set:
- name: "my-header"
value: "bar"
GET /foo HTTP/1.1
my-header: bar
Validation
Validation
Validation
before the action. It appends to any existing values associated
with the header name.
GET /foo HTTP/1.1
my-header: foo
add:
- name: "my-header"
value: "bar,baz"
GET /foo HTTP/1.1
my-header: foo,bar,baz
Validation
Validation
Validation
value of Remove is a list of HTTP header names. Note that the header
names are case-insensitive (see
https://datatracker.ietf.org/doc/html/rfc2616#section-4.2).
GET /foo HTTP/1.1
my-header1: foo
my-header2: bar
my-header3: baz
remove: ["my-header1", "my-header3"]
GET /foo HTTP/1.1
my-header2: bar
Validation
before the action.
GET /foo HTTP/1.1
my-header: foo
set:
- name: "my-header"
value: "bar"
GET /foo HTTP/1.1
my-header: bar
Validation
Validation
Validation
Host header for requests.HTTPRoute urlRewrite filter already specifies a host rewrite,this setting is ignored.
*
Auto: automatically set the Host header based on the destination.*
None: do not rewrite the Host header. The original Host headerwill be passed through.
Auto when connecting to hostname-basedBackend types, and None otherwise, for Service or IP-basedbackends.
Validation
Validation
Documentation References (4)
If omitted, credentials are read from the
Authorization header with the Bearer prefix.Validation
Validation
Validation
:) are not supportedValidation
Validation
Validation
and MCP-specific authentication behavior on top of standard JWT validation.
When set, the gateway will serve the MCP OAuth metadata discovery endpoints.
Documentation References (1)
If set, the gateway will not proxy registration requests to the IDP and instead return this client ID.
Validation
Documentation References (1)
served at the MCP OAuth metadata endpoints.
Documentation References (1)
Validation
Documentation References (4)
Validation
Documentation References (4)
access. This corresponds to the
aud claim([RFC 7519 §4.1.3](https://datatracker.ietf.org/doc/html/rfc7519#section-4.1.3)).
If unset, any audience is allowed.
Validation
Documentation References (2)
iss claim ([RFC 7519 §4.1.1](https://tools.ietf.org/html/rfc7519#section-4.1.1)).Validation
Documentation References (4)
JWT.
Validation
Documentation References (4)
signature of the JWT.
Validation
Documentation References (2)
address.
Documentation References (2)
Supported types are
Service and static Backend. AnAgentgatewayPolicy containing backend TLS config can then be attachedto the
Service or Backend in order to set TLS options for aconnection to the remote
jwks source.Validation
Documentation References (2)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Documentation References (1)
Service. Defaults to ServiceValidation
Documentation References (2)
Validation
Documentation References (2)
Validation
Documentation References (2)
ServiceValidation
Documentation References (2)
Validation
Documentation References (1)
jwks endpoint, relative to the root, commonly".well-known/jwks.json".Validation
Documentation References (2)
PreRouting,the
targetRef must be a Gateway or a Listener. PreRouting istypically used only when a policy needs to influence the routing
decision.
PostRouting mode, the policy can target theGateway or Listener. This is a helper for applying the policy to allroutes under that
Gateway or Listener, and follows the merging logicdescribed above.
PreRouting and PostRouting rules do not merge together. Theseare independent execution phases. That is, all
PreRouting rules willmerge and execute, then all
PostRouting rules will merge and execute.PostRouting.Validation
This limits the rate at which requests are processed.
Validation
The first matching policy will be executed.
A single policy may be provided without a condition set; if so, it must be the last policy and will be the fallback
in case no conditions are met.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
Supported types:
Service and Backend.Validation
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Validation
Validation
ServiceValidation
passed to the rate limit service which applies configured limits based
on them. Each descriptor represents a single rate limit rule with one or
more entries.
Validation
CEL) expression that determinesthe cost of the request for this descriptor. If unset,
Requests costsdefault to 1, and
Tokens costs default to the total token count.Tokens cost are evaluated after the request has completed. For non-streaming requests, request, llm, andresponse fields are all available; for streaming requests, response is not available (however, all LLMattributes are in
llm). For Requests, cost is computed during the request phase.Validation
Validation
CEL) expression thatdefines the value for the descriptor.
source.address.Validation
Validation
Requests is used.Validation
This is an arbitrary string that enables a rate limit server to distinguish between different applications.
Validation
unavailable or returns an error.
FailOpen allows the request to continue.FailClosed (default) denies the request.Validation
Validation
Documentation References (1)
that should be allowed within a short period of time.
Validation
are allowed. Requests exceeding this limit will fail with a
429error.
Validation
Documentation References (1)
allowed. Requests exceeding this limit will fail with a
429 error.result, token-based rate limits will apply to future requests only.
Validation
Validation
Documentation References (1)
Documentation References (3)
Supported types:
Service and Backend.Validation
Documentation References (3)
gateway.networking.k8s.io. Empty selects the core API groupValidation
Service. Defaults to ServiceValidation
Documentation References (2)
Validation
Documentation References (3)
Validation
Documentation References (2)
ServiceValidation
Documentation References (3)
passed to the rate limit service which applies configured limits based
on them. Each descriptor represents a single rate limit rule with one or
more entries.
Validation
Documentation References (3)
CEL) expression that determinesthe cost of the request for this descriptor. If unset,
Requests costsdefault to 1, and
Tokens costs default to the total token count.Tokens cost are evaluated after the request has completed. For non-streaming requests, request, llm, andresponse fields are all available; for streaming requests, response is not available (however, all LLMattributes are in
llm). For Requests, cost is computed during the request phase.Validation
Documentation References (1)
Validation
Documentation References (3)
CEL) expression thatdefines the value for the descriptor.
source.address.Validation
Documentation References (3)
Validation
Documentation References (3)
Requests is used.Validation
Documentation References (2)
This is an arbitrary string that enables a rate limit server to distinguish between different applications.
Validation
Documentation References (3)
unavailable or returns an error.
FailOpen allows the request to continue.FailClosed (default) denies the request.Validation
Validation
that should be allowed within a short period of time.
Validation
Documentation References (4)
are allowed. Requests exceeding this limit will fail with a
429error.
Validation
allowed. Requests exceeding this limit will fail with a
429 error.result, token-based rate limits will apply to future requests only.
Validation
Documentation References (4)
Validation
Documentation References (2)
from the gateway to a backend should be retried.
response from the backend, the Gateway MUST return an error.
a backend request is implementation-specific.
Validation
Documentation References (2)
Validation
Documentation References (2)
should be retried.
Validation
Documentation References (2)
condition is a CEL expression evaluated against each response to decidewhether to retry. A response is retried when its status code is in
codes orthis expression evaluates to
true.Validation
precondition is a CEL expression evaluated against the request before anyattempt is made. When it evaluates to
false, retries are disabled and onlythe initial attempt is made, for example
request.method == "GET".Retrying requires buffering the request body in memory for replay, so this lets
us skip that cost when the request is known to be non-retriable (for example
streaming uploads or long-lived connections like websockets).
Validation
It is applicable to
HTTPRoute resources and ignored for other targetedkinds.
Documentation References (2)
the request first starts being sent from the gateway to when the full response has been received from the backend.
Validation
Documentation References (2)
before forwarding them to the destination.
Validation
Documentation References (22)
The first matching policy will be executed.
A single policy may be provided without a condition set; if so, it must be the last policy and will be the fallback
in case no conditions are met.
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
Validation
Documentation References (1)
should be set to. If there is already a header with these values then
append the value as an extra entry.
Validation
Documentation References (1)
Validation
Documentation References (1)
the header.
Validation
Documentation References (1)
Validation
metadata CEL variablefor subsequent policy evaluations.
metadata is evaluated before headeror body transformations.
Validation
response.
Validation
Validation
Validation
the header.
Validation
Validation
should be set to. If there is already a header with these values then
append the value as an extra entry.
Validation
Validation
the header.
Validation
Validation
metadata CEL variablefor subsequent policy evaluations.
metadata is evaluated before headeror body transformations.
Validation
response.
Validation
Validation
Validation
the header.
Validation
Validation
Documentation References (14)
should be set to. If there is already a header with these values then
append the value as an extra entry.
Validation
Validation
the header.
Validation
Validation
metadata CEL variablefor subsequent policy evaluations.
metadata is evaluated before headeror body transformations.
Validation
response.
Validation
Validation
Documentation References (9)
Validation
Documentation References (9)
the header.
Validation
Documentation References (9)
Validation
Documentation References (7)
should be set to. If there is already a header with these values then
append the value as an extra entry.
Validation
Documentation References (1)
Validation
Documentation References (1)
the header.
Validation
Documentation References (1)
Validation
Documentation References (1)
metadata CEL variablefor subsequent policy evaluations.
metadata is evaluated before headeror body transformations.
Validation
response.
Validation
Documentation References (1)
Validation
Validation
the header.
Validation
Validation
PolicyAncestorStatus struct describes the status of.
When unspecified, "gateway.networking.k8s.io" is inferred.
To set the core API group (such as for a "Service" kind referent),
Group must be explicitly set to "" (empty string).
Validation
* Service (Mesh conformance profile, ClusterIP Services only)
Validation
Validation
Validation
Validation
Validation
Validation
This should be when the underlying condition changed. If that is not known, then using the time when the API field changed is acceptable.
Validation
This may be an empty string.
Validation
For instance, if .metadata.generation is currently 12, but the .status.conditions[x].observedGeneration is 9, the condition is out of date
with respect to the current state of the instance.
Validation
Producers of specific condition types may define expected values and meanings for this field,
and whether the values are considered a guaranteed API.
The value should be a CamelCase string.
This field may not be empty.
Validation
Validation
Validation
controller that wrote this status. This corresponds with the
controllerName field on GatewayClass.
valid Kubernetes names
(https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names).
entries to status populated with their ControllerName are cleaned up when they are no
longer necessary.