Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -107,6 +107,12 @@ spec:
EOF
```

## Provider failures

Set `failureMode` on a `webhook`, `openAIModeration`, `bedrockGuardrails`, or `googleModelArmor` guard to choose what happens when the provider is unreachable or returns an error. The default, `FailClosed`, rejects the request or response. Set `failureMode: FailOpen` to let the content continue unchanged instead.

A provider error is not a verdict, so `action: Audit` does not change how an error is handled. An audit guard with the default `failureMode` still rejects traffic when the provider call fails.

## Guard scope {#scope}

A request guard does not inspect the whole request. By default, a guard reads the system prompt and the text of regular user and assistant messages. Tool call content is left alone, so a Social Security number that a tool returns to the model reaches the provider unmasked.
Expand Down
20 changes: 20 additions & 0 deletions content/docs/kubernetes/main/release-notes/release-notes.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,3 +106,23 @@ Now, the `destination.address`, `destination.port`, and `destination.hostname` C
`destination.hostname` is set only on Gateway listeners with `protocol: TLS`. It is unset on HTTP and HTTPS listeners, even when the client sends SNI, and for clients that send no SNI. A `Require` policy that references it denies every such connection, so apply it only to Gateways whose listeners use `protocol: TLS`.

For an example, see [Restrict network access by TLS SNI]({{< link-hextra path="/documentation/security/authorization/#restrict-network-access-by-tls-sni" >}}).

#### Custom key for CA certificate references {#v16-ca-cert-ref-key}

<!-- ref: https://github.com/agentgateway/agentgateway/pull/3419 -->

A `caCertificateRefs` entry in the backend TLS settings of an {{< reuse "agw-docs/snippets/policy.md" >}}, {{< reuse "agw-docs/snippets/backend.md" >}}, or {{< reuse "agw-docs/snippets/agentgatewaymodel.md" >}} now takes an optional `key` field. Set it to read the CA bundle from a key other than `ca.crt` in the referenced ConfigMap or Secret, such as a key that trust-manager or an external secret store writes. Omit the field to keep reading `ca.crt`.

The field does not apply to a BackendTLSPolicy or to the `frontendValidation` field of a Gateway listener, which still read `ca.crt`. For an example, see [CA certificate in a Secret]({{< link-hextra path="/documentation/security/backendtls/#secret-ca" >}}).

### LLM {#v16-features-llm}

#### Failure mode for provider guardrails {#v16-guardrail-failure-mode}

<!-- ref: https://github.com/agentgateway/agentgateway/pull/3618 -->

The `failureMode` field, which was previously available only on `webhook` guards, is now available on `openAIModeration`, `bedrockGuardrails`, and `googleModelArmor` guards. The field sets what happens when the provider is unreachable or returns an error. The default, `FailClosed`, rejects the request or response. Set `failureMode: FailOpen` to let the content continue unchanged instead.

For most traffic, the default keeps the 1.5.x behavior, because a provider error already rejected the request or response. Two paths change. On a realtime WebSocket connection, and for streaming responses that are evaluated as they arrive, a provider error from one of these guards used to let the content through. It now rejects the content, unless you set `failureMode: FailOpen`.

For more information, see [Provider failures]({{< link-hextra path="/documentation/llm/guardrails/overview/#provider-failures" >}}).
Original file line number Diff line number Diff line change
Expand Up @@ -104,6 +104,12 @@ llm:
action: audit
```

## Provider failures

Set `failureMode` on a `webhook`, `openAIModeration`, `bedrockGuardrails`, `googleModelArmor`, or `azureContentSafety` guard to choose what happens when the provider is unreachable or returns an error. The default, `failClosed`, rejects the request or response. Set `failureMode: failOpen` to let the content continue unchanged instead.

A provider error is not a verdict, so `action: audit` does not change how an error is handled. An audit guard with the default `failureMode` still rejects traffic when the provider call fails.

## Guard scope {#scope}

A request guard does not inspect the whole request. By default, a guard reads the system prompt and the text of regular user and assistant messages. Tool call content is left alone, so a Social Security number that a tool returns to the model reaches the provider unmasked.
Expand Down
12 changes: 12 additions & 0 deletions content/docs/standalone/main/release-notes/release-notes.md
Original file line number Diff line number Diff line change
Expand Up @@ -121,3 +121,15 @@ Now, the `destination.address`, `destination.port`, and `destination.hostname` C
`destination.hostname` is set only on listeners with the `TLS` protocol. It is unset on HTTP and HTTPS listeners, even when the client sends SNI, and for clients that send no SNI. A `require` rule that references it rejects every such connection, so apply it only to `TLS` listeners.

For the variables and an example, see [Require TLS SNI]({{< link-hextra path="/documentation/configuration/security/network-authz/#require-tls-sni" >}}).

### LLM {#v16-features-llm}

#### Failure mode for provider guardrails {#v16-guardrail-failure-mode}

<!-- ref: https://github.com/agentgateway/agentgateway/pull/3618 -->

The `failureMode` field, which was previously available only on `webhook` guards, is now available on `openAIModeration`, `bedrockGuardrails`, `googleModelArmor`, and `azureContentSafety` guards. The field sets what happens when the provider is unreachable or returns an error. The default, `failClosed`, rejects the request or response. Set `failureMode: failOpen` to let the content continue unchanged instead.

For most traffic, the default keeps the 1.5.x behavior, because a provider error already rejected the request or response. Two paths change. On a realtime WebSocket connection, and for streaming responses that are evaluated as they arrive, a provider error from one of these guards used to let the content through. It now rejects the content, unless you set `failureMode: failOpen`.

For more information, see [Provider failures]({{< link-hextra path="/documentation/llm/prompt-guards/overview/#provider-failures" >}}).
Loading