Nemo Guardrails Response
Evaluates upstream responses against a NeMo Guardrails service
Category: Setup-dependent integration
Task: Evaluates upstream responses against a NeMo Guardrails service
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
Run it: Use ghcr.io/praxis-proxy/ai:0.5.0 and follow the container quickstart to mount and start the configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
# Guardrails (NeMo) - Response Phase Only
#
# Evaluates upstream responses against a NeMo Guardrails service.
# Request-side guardrails are disabled so the request always reaches
# the upstream. This config is used by integration tests to verify
# response-phase behavior in isolation.
#
# Response phase:
# passed - response forwarded to the client unchanged
# blocked - response body replaced with a JSON error payload
# (status remains 200 because headers are already committed)
# modified - redaction verdict recorded; original body forwarded until #49
listeners:
- name: gateway
address: "0.0.0.0:8080"
filter_chains:
- nemo-guardrails-response
filter_chains:
- name: nemo-guardrails-response
filters:
- filter: ai_guardrails
# Optional. Omit for an empty pass-through chain; configure one when
# NeMo callouts need credentials, tracing, or destination policy.
outbound_chain: nemo-outbound
provider:
type: nemo
# Requires NeMo Guardrails 0.24.0 or newer.
endpoint: "http://127.0.0.1:3001/v1/checks"
guardrails:
config_ids: ["your-config"] # replace with a configuration deployed in NeMo
timeout_ms: 5000
max_message_checks: 32
phase:
request: false
response: true
- filter: router
routes:
- path_prefix: "/"
cluster: provider
- filter: load_balancer
clusters:
- name: provider
endpoints:
- "127.0.0.1:3000"
- name: nemo-outbound
filters:
- filter: request_id
insecure_options:
allow_private_endpoints: true # example proxies to local backends
allow_private_upstreams: true # example calls the local NeMo service