guardrails

Rejects requests matching string, regex, or PII rules against headers and/or body content.
On this page

Rejects requests matching string, regex, or PII rules against headers and/or body content.

Configuration

FieldTypeRequiredDescription
actionreject | flagnoWhat to do when a rule matches (default: reject).
reject_oversizedboolnoReject a body that exactly reaches the inspection buffer limit (1 MiB) instead of inspecting it. Bodies that exceed the limit are always rejected with 413 by the streaming buffer regardless of this flag — there is no silent truncation. This flag only governs a body sized exactly at the limit, which is otherwise inspected as-is.
rulesRuleConfig[]yesList of rules to evaluate.
rules[].namestringnoHeader name (required when target is [Header]).
rules[].containsstring | (ssn | credit_card | phone | email)[]noLiteral substring (case-insensitive) or PII category list.
rules[].negateboolnoInvert the match: reject when the content does NOT match. For negated header rules, a missing header also triggers rejection. Defaults to false.
rules[].patternstringnoRegex pattern match.
rules[].targetheader | bodyyesWhat to inspect: header or body.

Example

filter: guardrails
action: flag            # or "reject" (default)
rules:
  # Detect PII in a header
  - target: header
    name: "Authorization"
    contains: [ssn, credit_card, email]
  # Detect PII in body
  - target: body
    contains: [ssn, credit_card, phone, email]
  # Block SQL injection in body
  - target: body
    contains: "DROP TABLE"
  # Block requests from bad bots
  - target: header
    name: "User-Agent"
    pattern: "bad-bot.*"
  # Require body to look like JSON (reject if NOT matching)
  - target: body
    pattern: "^\\{.*\\}$"
    negate: true