Skip to content

docs: add AIGatewayRoute security policy proposal - #2702

Open
fernandoescolar wants to merge 12 commits into
theagentrouter:mainfrom
fernandoescolar:feat/aigatewayroute-securitypolicy
Open

fernandoescolar wants to merge 12 commits into
theagentrouter:mainfrom
fernandoescolar:feat/aigatewayroute-securitypolicy

Conversation

@fernandoescolar

Copy link
Copy Markdown

Description

This commit adds a technical proposal for centralizing client-facing security configuration in AIGatewayRoute.

The proposal describes how the controller could generate and manage an Envoy Gateway SecurityPolicy targeting the HTTPRoute generated for each AIGatewayRoute. It covers JWT authentication, API key authentication, external authorization through Envoy ext_authz, JWT claim propagation, policy merging, resource ownership, reconciliation, cleanup, and conflict handling.

The proposal also defines the initial API and compatibility decisions for v1alpha1 and v1beta1. Model-aware authorization based on the model extracted from the request body is explicitly kept out of scope because it would require a broader data-plane and identity-propagation design.

Related Issues/PRs (if applicable)

N/A

Special notes for reviewers (if applicable)

This PR only adds documentation and does not implement the proposed API or controller changes.

The main goal is to gather feedback on the route-level SecurityPolicy design before implementation.

Signed-off-by: Fernando Escolar <fernando.escolar@digits.schwarz>
@fernandoescolar
fernandoescolar requested a review from a team as a code owner September 17, 2026 10:09
@netlify

netlify Bot commented Sep 17, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for theagentrouter canceled.

Name Link
🔨 Latest commit f4faa3c
🔍 Latest deploy log https://app.netlify.com/projects/theagentrouter/deploys/6ac200c71f02f400083f9985

@missBerg missBerg added design This is related to a design proposal or discussion area/api Control plane API (CRDs) area/security Guardrails, content safety, security integrations labels Sep 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/api Control plane API (CRDs) area/security Guardrails, content safety, security integrations design This is related to a design proposal or discussion

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants