[Automated] Draft docs (agentgateway): feat(controller): select the CA bundle key in AgentgatewayPolicy CA refs (+2 related) - #1111
Merged
Conversation
…A bundle key in AgentgatewayPolicy CA refs (+2 related) Signed-off-by: GitHub Action <action@github.com>
kristin-kronstain-brown
approved these changes
Sep 25, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Feature clusters
These pull requests document one feature between them:
content/docs/kubernetes/main/documentation/operations/debug.md, the only page a code-path rule names for one of them, so separate pull requests would conflictWorked in another repository as well. This does not hold the cluster: a different repository documents itself in a different product's tree, on a schedule this run does not control. Listed so the other work is not a surprise later:
Draft a documentation change
agentgateway/agentgateway#3419 — feat(controller): select the CA bundle key in AgentgatewayPolicy CA refs
agentgateway/websiteAgentgatewayPolicy.backend.tls.caCertificateRefsinstead of hardcodingca.crtagentgateway#3418ca.crtkey in the configured Secret / ConfigMap. This is now a configurable key, with default value ofca.crtif omitted for backward compatibility.controller/pkg/agentgateway/cacert/ca.gocontroller/pkg/agentgateway/remotehttp/ca_bundle.goagentgateway/agentgateway#3618 — guardrails: add fail open/fail closed polciy to all types
agentgateway/websiteapi/resource.pb.goNew configuration: no page mentions it yet
agentgateway/agentgateway#3449 — feat(aws): add support for externalId in assumeRole
agentgateway/websiteapi/resource.pb.gocrates/agentgateway/src/http/auth/aws.rscrates/agentgateway/src/http/auth/tests.rsWarnings
agentgateway/agentgateway#3419, #3449, #3618 — CA key selection, AWS External ID, and guardrail failure modes
agentgateway/agentgateway#3419 adds a
keyselector to backend TLS CA certificate references, #3449 addsassumeRole.externalIdto AWS backend authentication, and #3618 addsfailureModeto cloud provider guardrails. The CA key behavior was already documented in the target checkout by the merged website sibling, so this draft leaves that page unchanged. This draft addsassumeRole.externalIdto the AWS authentication examples and field tables, with the STS length and character limits. It also documents provider failure handling for prompt guards, including the new fail-closed default for provider errors and thefailOpen/FailOpenoverride values.How
agentgateway-3419was drafted, and what was not verifiedagentgateway/agentgateway#3419, #3449, #3618 — CA key selection, AWS External ID, and guardrail failure modes
AgentgatewayPolicy.backend.tls.caCertificateRefsinstead of hardcodingca.crtagentgateway#3418 for #3419; none linked for #3449 or #3618Plan, and what changed it
assumeRole.externalId, and guardrail providerfailureModein the pages that own those tasks.assets/agw-docs/pages/security/backendtls.mdalready documents the CA key behavior from Docs for per-key rate limits and certificate key and metrics #1039, while the AWS authentication pages and guardrail overview pages did not cover the new fields.Why a documentation change is necessary
#3449 adds
externalIdto AWS AssumeRole configuration in both the Kubernetes CRDs and the standalone schema, and the existing AWS backend authentication guides listed the other AssumeRole fields without this one. The body and diff also state the validation limits and that the value is part of the credential cache key, which readers need when they configure trust policies that requirests:ExternalId.#3618 adds
failureModeto OpenAI moderation, Bedrock Guardrails, Google Model Armor, and standalone Azure Content Safety guards. The guardrail overviews explainedaction: auditbut did not say what happens when a provider call fails, and the diff changes the fallback from fail open to fail closed for provider errors.What changed on disk
assets/agw-docs/pages/security/backend-authn-aws.md: Added the KubernetesassumeRole.externalIdexample and field-table row behind a main-only version gate.assets/agw-docs/pages/security/backend-authn-aws-standalone.md: Added the standaloneassumeRole.externalIdexample and field-table row behind a main-only version gate.content/docs/kubernetes/main/documentation/llm/guardrails/overview.md: Added theProvider failuressection with the KubernetesFailClosed/FailOpenvalues.content/docs/standalone/main/documentation/llm/prompt-guards/overview.md: Added theProvider failuressection with the standalonefailClosed/failOpenvalues.How to verify this change
spec.backend.auth.aws.assumeRole.externalId: tenant-a:prod/12345;kubectl apply --dry-run=server -f <file>accepts the field.spec.backend.ai.promptGuard.request[].openAIModeration.failureMode: FailOpen;kubectl apply --dry-run=server -f <file>accepts the enum value.agentgateway --validate-only -f <file>for a config withbackendAuth.aws.assumeRole.externalId: tenant-a:prod/12345andllm.policies.guardrails.request[].openAIModeration.failureMode: failOpen; validation succeeds.tls.caCertificateRefs[].keyset to a key other thanca.crt;kubectl get <resource> -o yamlshows the configured key, and traffic to a backend that uses that CA succeeds.Proposed release note
A note is needed because #3419 and #3449 add feature surface and #3618 changes observable provider-error behavior by defaulting these guardrail provider failures to fail closed.
What was not verified
The configuration was not applied to a cluster, so every command in this draft is unrun. The #3449 and #3618 diffs are truncated; each cut falls inside the last shown file with no additional files below it by name, so content past the cut was not verified.
Release notes
This pull request also adds its release-note entries:
content/docs/kubernetes/main/release-notes/release-notes.md: Backend authentication and guardrail controls (feature)Draft branch:
pr-tracker-draft-agentgateway-3419-plus2Important
The test suite has not run on this pull request. It was opened by
github-actions[bot], and GitHub does not start workflows for pull requests opened with the repository's own token. Doc tests, link checking and the static checks are held asaction_requireduntil somebody presses Approve and run on the Checks tab. Cloudflare Pages and DCO are GitHub Apps rather than Actions, so those two do run on their own.Please approve the checks before reviewing the content: an absence of failures here means the tests have not run, not that they passed.