Skip to content
Version 2026.6.3 is the latest release with the newest features, but gets no long-term support. To stay supported, upgrade with every new release or use a quarterly stable release instead.

Overview

Page as Markdown

Learn about the different policy sections.

The EnterpriseAgentgatewayPolicy custom resource lets you apply traffic management, security, observability, and backend connection policies to your agentgateway resources.

Policy sections

Each EnterpriseAgentgatewayPolicy has three top-level sections in the spec field that control different stages of request processing. You can include one or more of these sections in a single policy.

SectionDescriptionAvailable fields
frontendControls how the gateway accepts incoming connections. Applies at the gateway level before routing decisions.tcp, tls, http, networkAuthorization, accessLog, tracing
trafficControls how agentgateway processes traffic. Applies at the listener, route, or route rule level. Fields are listed in execution order.cors, jwtAuthentication, basicAuthentication, apiKeyAuthentication, extAuth, authorization, rateLimit, extProc, transformation, csrf, headerModifiers, hostRewrite, directResponse, buffer, timeouts, retry
backendControls how agentgateway connects to destination backends. Applies at the backend, service, route, or gateway level.tcp, tls, http, tunnel, transformation, auth, extAuth, health, ai, mcp

Example guides

Check out the following sections for policy examples.