SecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use to3s.3s.response.code >= 500.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use to3s.3s.response.code >= 500.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSBackend of type mcp.jwtAuthentication.mcp, which ensures authentication runs beforeServicejwks endpoint, relative to the root, commonly".well-known/jwks.json".403 error, this policy works at theMCPBackend level.list_tools, will have each item evaluated.call_tool, will evaluate the specificAllow.Require rules are cumulative: all require rules must match.Allow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.RequireAllow rule is configured, requests are denied unless atAllow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.Deny is not recommended because expression failures fail to deny; preferAllow or Require. If used, design expressions defensively against evaluation errors.Allow rule is configured, requests are denied unless atguardrails routes selected JSON-RPC methods through a remote policy server.processors is the ordered list of policy processors applied to matchedfailureMode controls behavior when the policy server is unreachableFailOpen allows the request; FailClosedmetadata is static or CEL-evaluated context surfaced to the policymetadata_context google.protobuf.Struct,ALPN)["h2", "http/1.1"].ConfigMap to use tov1.resourceType is Foundry.us-east-1 if not specified.backendRef may target only a namespace-local Service or InferencePool.gateway.networking.k8s.io.Service.gpt-*, a prefix wildcard such as *-latest, or *.jwt.sub orrequest.headers["x-team"]. If the expression does not produce a validjwt.sub or request.headers["x-app"]. Requests with invalidus-east-1. Set this when theSecret.accessKey, secretKey, and optionalsessionToken keys.Secretbedrock, bedrock-agentcore, or execute-api). If unset, typed AWSSecret. The default Secret resolver expects clientID, tenantID, andclientSecret keys.Secretcredentials is independent of the primarykey/secretRef/passthrough mechanism and may be set on its own or:) are not supportedAuthorization,secretRef.Secretaud value for the ID token. OnlyIdToken type. If not set, the aud is automaticallySecret. By default, the value is read fromcredentials.json; set secretRef.key to override it. When omitted,SecretAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Authorization header. This optionSecret is preferred.Authorization header with the Bearer prefix. Thiskey, secretRef, and passthrough. Entries incredentials carry their own location.:) are not supported:) are not supportedgateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServicesigningKey key by default with a PEM-encoded RSAsigningKeyRef.key.SecretclientSecret key by default; override viasecretRef.key. When omitted, client_id is sent without a secret, whichSecret:) are not supportedexpression variant is permitted.:) are not supportedSecret. By default, the value is read from the Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromAuthorization key.SecretAllow.Require rules are cumulative: all require rules must match.Allow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.Deny is not recommended because expression failures fail to deny; preferAllow or Require. If used, design expressions defensively against evaluation errors.Allow rule is configured, requests are denied unless at3s.response.code >= 500.aws: {} forjwt.sub orrequest.headers["x-team"]. If the expression does not produce a validjwt.sub or request.headers["x-app"]. Requests with invalidus-east-1. Set this when theSecret.accessKey, secretKey, and optionalsessionToken keys.Secretbedrock, bedrock-agentcore, or execute-api). If unset, typed AWSAuthorization header.Secret is preferred.Authorization header withBearer prefix. Applies to key and secretRef.:) are not supportedSecret.Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromAuthorization key.SecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAll disables all TLS verificationHostname trusts the CA certificate but ignores hostname/SAN mismatches.verifySubjectAltNames where possible.X25519_MLKEM768,X25519.tls.key and tls.crt from theSecret). Anca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateSecretSNI) to use in the TLSSNI is automatically set based on theSAN)HTTPS_PROXYService and Backend.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServiceus-west-2).us-central1.us-central1 if not specified.gcp: {} for defaultaud value for the ID token. OnlyIdToken type. If not set, the aud is automaticallySecret. By default, the value is read fromcredentials.json; set secretRef.key to override it. When omitted,SecretAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAll disables all TLS verificationHostname trusts the CA certificate but ignores hostname/SAN mismatches.verifySubjectAltNames where possible.X25519_MLKEM768,X25519.tls.key and tls.crt from theSecret). Anca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateSecretSNI) to use in the TLSSNI is automatically set based on theSAN)HTTPS_PROXYService and Backend.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServiceomni-moderation.Authorization header. This option is the least secure; usage of aSecret is preferred.AuthorizationBearer prefix. Applies to key and secretRef.:) are not supportedSecret. By default, the value is read from the Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromAuthorization key.SecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAll disables all TLS verificationHostname trusts the CA certificate but ignores hostname/SAN mismatches.verifySubjectAltNames where possible.X25519_MLKEM768,X25519.tls.key and tls.crt from theSecret). Anca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateSecretSNI) to use in the TLSSNI is automatically set based on theSAN)HTTPS_PROXYService and Backend.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServicePromptguardResponseMask.The request was rejected due to inappropriate content.The request was rejected due to inappropriate content.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServiceFailOpen allows the request to continue.FailClosed (default) rejects the request.Exact (default) or RegularExpression. The regex dialect is implementation-specificaws: {} forjwt.sub orrequest.headers["x-team"]. If the expression does not produce a validjwt.sub or request.headers["x-app"]. Requests with invalidus-east-1. Set this when theSecret.accessKey, secretKey, and optionalsessionToken keys.Secretbedrock, bedrock-agentcore, or execute-api). If unset, typed AWSAuthorization header.Secret is preferred.Authorization header withBearer prefix. Applies to key and secretRef.:) are not supportedSecret.Authorization key; setsecretRef.key to override it. A Bearer prefix is stripped only fromAuthorization key.SecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAll disables all TLS verificationHostname trusts the CA certificate but ignores hostname/SAN mismatches.verifySubjectAltNames where possible.X25519_MLKEM768,X25519.tls.key and tls.crt from theSecret). Anca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateSecretSNI) to use in the TLSSNI is automatically set based on theSAN)HTTPS_PROXYService and Backend.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServiceus-west-2).us-central1.us-central1 if not specified.gcp: {} for defaultaud value for the ID token. OnlyIdToken type. If not set, the aud is automaticallySecret. By default, the value is read fromcredentials.json; set secretRef.key to override it. When omitted,SecretAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAll disables all TLS verificationHostname trusts the CA certificate but ignores hostname/SAN mismatches.verifySubjectAltNames where possible.X25519_MLKEM768,X25519.tls.key and tls.crt from theSecret). Anca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateSecretSNI) to use in the TLSSNI is automatically set based on theSAN)HTTPS_PROXYService and Backend.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServicePromptguardResponseMask.The response was rejected due to inappropriate content.The request was rejected due to inappropriate content.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServiceFailOpen allows the request to continue.FailClosed (default) rejects the request.Exact (default) or RegularExpression. The regex dialect is implementation-specificALPN)["h2", "http/1.1"].ConfigMap to use toAll disables all TLS verificationHostname trusts the CA certificate but ignores hostname/SAN mismatches.verifySubjectAltNames where possible.X25519_MLKEM768,X25519.tls.key and tls.crt from theSecret). Anca.cert, if present, verifies the server certificate, butcaCertificateRefs takes priority. If unspecified, no client certificateSecretSNI) to use in the TLSSNI is automatically set based on theSAN)Service and Backend.gateway.networking.k8s.io. Empty selects the core API groupService. Defaults to ServiceServiceglobal uses the global endpoint, while us and eu use restrictedglobal if not specified.map, which means that they function like atype field _in the k8s apiserver_.special.io/SomeField, it MUST NOT remove, change or update thatobservedGeneration field of themetadata.generation of the Gateway at the time of update creation.observedGeneration of a Condition is _greater than_ the value theSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toSecretService appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use toAccessToken is used. To authenticate to Cloud Run, anIdToken is used.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSALPN)["h2", "http/1.1"].ConfigMap to use to3s.3s.response.code >= 500.Service appProtocol, HTTP2 for gRPC, the original protocol forHTTP1 for HTTPS because clients often upgrade HTTPSBackend of type mcp.jwtAuthentication.mcp, which ensures authentication runs beforeServicejwks endpoint, relative to the root, commonly".well-known/jwks.json".403 error, this policy works at theMCPBackend level.list_tools, will have each item evaluated.call_tool, will evaluate the specificAllow.Require rules are cumulative: all require rules must match.Allow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.RequireAllow rule is configured, requests are denied unless atAllow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.Deny is not recommended because expression failures fail to deny; preferAllow or Require. If used, design expressions defensively against evaluation errors.Allow rule is configured, requests are denied unless atguardrails routes selected JSON-RPC methods through a remote policy server.processors is the ordered list of policy processors applied to matchedfailureMode controls behavior when the policy server is unreachableFailOpen allows the request; FailClosedmetadata is static or CEL-evaluated context surfaced to the policymetadata_context google.protobuf.Struct,ALPN)["h2", "http/1.1"].ConfigMap to use toHTTP/1. If a request is HTTP/2 in either the incoming or outgoing request, this will be ignored.HTTP/1.1 requests.16kb.16Ki.2mb.source.address with cidr(...).containsIP(...).Allow.Require rules are cumulative: all require rules must match.Allow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.RequireAllow rule is configured, requests are denied unless atAllow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.Deny is not recommended because expression failures fail to deny; preferAllow or Require. If used, design expressions defensively against evaluation errors.Allow rule is configured, requests are denied unless atStrict.V2.ALPN)["h2", "http/1.1"].TLS13_AES_256_GCM_SHA384,TLS13_AES_128_GCM_SHA256.15s.15s.X25519_MLKEM768,X25519.Allow.Require rules are cumulative: all require rules must match.Allow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.RequireAllow rule is configured, requests are denied unless atAllow: any matching allow rule allows the request.Require: every require rule must match for the request to be allowed.Deny: any matching deny rule denies the request.Deny is not recommended because expression failures fail to deny; preferAllow or Require. If used, design expressions defensively against evaluation errors.Allow rule is configured, requests are denied unless atBasicAuthorization header with the Basic prefix.Servicejwks endpoint, relative to the root, commonly".well-known/jwks.json".PreRouting,targetRef must be a Gateway or a Listener. PreRouting isPostRouting mode, the policy can target theGateway or Listener. This is a helper for applying the policy to allGateway or Listener, and follows the merging logicPreRouting and PostRouting rules do not merge together. ThesePreRouting rules willPostRouting rules will merge and execute.PostRouting.condition is a CEL expression evaluated against each response to decidecodes ortrue.precondition is a CEL expression evaluated against the request before anyfalse, retries are disabled and onlyrequest.method == "GET".HTTPRoute resources and ignored for other targetedHTTP/1.1.maxBufferSize. If the body exceeds the max buffer size,response contains attributes about the HTTP responsemaxBufferSize. If the body exceeds the max buffer size,proxy contains proxy timing information for the request.env contains selected process environment attributes exposed to CEL.jwt contains the claims from a verified JWT token. This is only present if the JWT policy is enabled.jwt.rawToken.unredacted() to access the actual value.apiKey contains the claims from a verified API Key. This is only present if the API Key policy is enabled.apiKey.key.unredacted() to access the actual value.basicAuth contains the claims from a verified basic authentication Key. This is only present if the Basic authentication policy is enabled.basicAuth contains the claims from a verified basic authentication Key. This is only present if the Basic authentication policy is enabled.llm contains attributes about an LLM request or response. This is only present when using an ai backend.llmRequest contains the raw LLM request before processing. This is only present *during* LLM policies;source contains attributes about the source of the request.address when using tunneling protocols like PROXY.port when using tunneling protocols like PROXY.unverified to signal that they are derivedsource.identity.* for trust-sensitive checks.source.connectHeaders, whichrequest.headers (indexing, join(),split(), etc.).destination contains attributes about the downstream request destination at agentgateway.mcp contains attributes about the MCP request.tool, prompt, or resource.methodName, sessionId, and tool payloads.backend contains information about the backend being used.my-service or service/my-namespace/my-service:8080.extauthz contains dynamic metadata from ext_authz filtersextproc contains dynamic metadata from ext_proc filtersmcpGuardrails contains dynamic metadata returned by mcpGuardrails policy processors.metadata contains values set by transformation metadata expressions.maxBufferSize. If the complete body exceeds the limit,maxBufferSize bytes.response contains attributes about the HTTP responsemaxBufferSize. If the body exceeds the max buffer size,maxBufferSize. If the complete body exceeds the limit,maxBufferSize bytes.proxy contains proxy timing information for the request.env contains selected process environment attributes exposed to CEL.jwt contains the claims from a verified JWT token. This is only present if the JWT policy is enabled.jwt.rawToken.unredacted() to access the actual value.apiKey contains the claims from a verified API Key. This is only present if the API Key policy is enabled.apiKey.key.unredacted() to access the actual value.basicAuth contains the claims from a verified basic authentication Key. This is only present if the Basic authentication policy is enabled.basicAuth contains the claims from a verified basic authentication Key. This is only present if the Basic authentication policy is enabled.llm contains attributes about an LLM request or response. This is only present when using an ai backend.llmRequest contains the raw LLM request before processing. This is only present *during* LLM policies;source contains attributes about the source of the request.address when using tunneling protocols like PROXY.port when using tunneling protocols like PROXY.unverified to signal that they are derivedsource.identity.* for trust-sensitive checks.source.connectHeaders, whichrequest.headers (indexing, join(),split(), etc.).destination contains attributes about the downstream request destination at agentgateway.mcp contains attributes about the MCP request.tool, prompt, or resource.methodName, sessionId, and tool payloads.backend contains information about the backend being used.my-service or service/my-namespace/my-service:8080.extauthz contains dynamic metadata from ext_authz filtersextproc contains dynamic metadata from ext_proc filtersmcpGuardrails contains dynamic metadata returned by mcpGuardrails policy processors.metadata contains values set by transformation metadata expressions.