Skip to content
Coder Docs

Rules Engine Documentation

Learn how the Agent Firewall rules engine filters agent network requests with configurable rules.

On this page

Note

Agent Firewall is part of AI Governance, which is included with a Premium license.

Overview

The rulesengine package provides a flexible rule-based filtering system for HTTP/HTTPS requests. Rules use a simple key-value syntax with support for wildcards and multiple values.

Basic Syntax

Rules follow the format: key=value [key=value ...] with three supported keys:

  • method: HTTP method(s) - Any HTTP method (e.g., GET, POST, PUT, DELETE), * (all methods), or comma-separated list
  • domain: Domain/hostname pattern - github.com, *.example.com, * (all domains)
  • path: URL path pattern - /api/users, /api/*/users, * (all paths), or comma-separated list

Key behavior:

  • If a key is omitted, it matches all values
  • Multiple key-value pairs in one rule are separated by whitespace
  • Multiple rules in the allowlist are OR'd together (OR logic)
  • Default deny: if no rule matches, the request is denied

Examples:

allowlist:
  - domain=github.com # All methods, all paths for github.com (exact match)
  - domain=*.github.com # All subdomains of github.com
  - method=GET,POST domain=api.example.com # GET/POST to api.example.com (exact match)
  - domain=api.example.com path=/users,/posts # Multiple paths
  - method=GET domain=github.com path=/api/* # All three keys

Wildcard Symbol for Domains

The * wildcard matches domain labels (parts separated by dots).

PatternMatchesDoes NOT Match
*All domains-
github.comgithub.com (exact match only)api.github.com, v1.api.github.com (subdomains), github.io
*.github.comapi.github.com, v1.api.github.com (1+ subdomain levels)github.com (base domain)
api.*.comapi.github.com, api.google.comapi.v1.github.com (* in the middle matches exactly one domain label)
*.*.comapi.example.com, api.v1.github.com-
api.*No ERROR - Cannot end with *-

Important:

  • Patterns without * match exactly (no automatic subdomain matching)
  • *.example.com matches one or more subdomain levels
  • To match both base domain and subdomains, use separate rules: domain=github.com and domain=*.github.com
  • Domain patterns cannot end with asterisk

Wildcard Symbol for Paths

The * wildcard matches path segments (parts separated by slashes).

PatternMatchesDoes NOT Match
*All paths-
/api/users/api/users/api/users/123 (subpaths don't match)
/api/*/api/users, /api/posts/api
/api/*/users/api/v1/users, /api/v2/users/api/users, /api/v1/v2/users
/*/users/api/users, /v1/users/api/v1/users
/api/v1/*/api/v1/users, /api/v1/users/123/details (1+ segments)/api/v1

Important:

  • * matches exactly one segment (except at the end)
  • * at the end matches one or more segments (special behavior)
  • * must match an entire segment (cannot be part of a segment like /api/user*)

Special Meaning of Wildcard at Beginning and End

PositionDomainPath
Beginning1+ subdomain levelsExactly 1 segment
MiddleExactly 1 labelExactly 1 segment
EndNo Not allowed1+ segments (special)
StandaloneAll domainsAll paths

Multipath

Specify multiple paths in a single rule by separating them with commas:

allowlist:
  - domain=api.example.com path=/users,/posts,/comments
  - domain=api.example.com path=/api,/api/*

NOTE: The pattern /api/* does not include the base path /api. To match both, use path=/api,/api/*.