Skip to main content

BYG Security and Operations

BYG moves guardrail enforcement into the gateway data path. Treat the policy identity, processor connection, failure mode, and telemetry schema as security boundaries.

Mandatory controls​

  • Overwrite the portable X-TSZ-Policy header at a trusted early gateway stage, or use the native route attribute resolver.
  • Keep tsz-ext-proc private and allow port 9002 only from the intended Envoy workloads.
  • Use mTLS in production, verify both peers, and rotate certificates through an approved PKI.
  • Keep secrets and provider credentials in gateway or workload Secret stores; never place them in policies, metadata, logs, or metrics.
  • Set finite body, processing, validator, stream-buffer, queue, and concurrency limits.
  • Default request enforcement to fail-closed. Approve and test any fail-open exception as an availability trade-off.
  • Use buffered responses where the policy requires that no unsafe response byte can reach the client.

Failure behavior​

Failures are evaluated at the stage where they occur. A request-stage failure must not be reported as a response decision, and a response-stage failure must not overwrite the original request decision. Audit and SIEM delivery are bounded and cannot block the data path.

Envoy may invoke response processing for a local reply without a preceding Safe Zone request callback. Such responses have no pinned policy state. The global TSZ_FAIL_MODE controls this case: closed returns a safe response-stage 403; open explicitly preserves availability. Both outcomes emit a bounded, content-free degraded signal.

Observability​

The processor exposes Prometheus metrics on GET /metrics at its health port and can export OpenTelemetry traces over OTLP/gRPC. Monitor at least:

  • request and response decisions by action and stage;
  • processing latency, timeouts, body-limit failures, and active streams;
  • stream halts and async-audit buffer or queue degradation;
  • response callbacks without request state;
  • controller reconciliation, policy conflicts, and activation failures.

Safe telemetry includes bounded action, stage, policy, type, direction, and reason fields plus non-sensitive correlation IDs. Request and response bodies, raw findings, credentials, user or tenant identifiers, raw error text, and unbounded route values must not become labels or span attributes.

Production verification​

Before enabling traffic, run contract and clean-cluster scenarios for request mask/block, response mask/block, fail-open and fail-closed outages, streaming, mTLS/NetworkPolicy, policy conflicts, version skew, and telemetry safety. Tune autoscaling from measured processor throughput, p95/p99 latency, memory, concurrent streams, and validator behavior.

The complete operational runbooks remain versioned with the source: