Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11An agentgateway CEL evaluation error does not always deny a request: an errored deny rule does not match and may fail open, while an errored require rule denies and fails closed. Use require for conditions that must be true—such as a required JWT audience—and verify that the referenced context exists when the policy runs.
What happens when an agentgateway CEL expression errors?
Agentgateway treats an expression it cannot evaluate as false, but the authorization rule’s action determines what that false result means. The standalone HTTP authorization documentation states: “A CEL expression that cannot be evaluated is treated as false.” (agentgateway HTTP authorization documentation.)
As an Amazon Associate I earn from qualifying purchases.
| Rule type | What triggers the rule’s effect | False result or evaluation error | Practical effect |
|---|---|---|---|
deny |
The expression evaluates true. | It does not match. | That rule does not deny the request; another rule or the overall policy may still deny it. |
require |
The expression must evaluate true. | It fails. | The request is denied. |
The docs summarize the distinction directly: “A require expression that is false (or errors) denies the request (fail-closed),” while “A deny expression that errors does not match, so it does not deny the request (fail-open).” Those statements describe the standalone HTTP authorization guide; Kubernetes policy configuration has its own format and should be read separately.
How a deny rule can fail open on a missing JWT audience
Consider this standalone HTTP authorization expression:
#1 Best Overall
deny: 'jwt.aud != "my-service"'
It is intended to deny a token whose audience differs from my-service. But if the JWT context or jwt.aud is unavailable, CEL cannot evaluate the comparison. The result is false, so this deny rule does not match. If no other configured rule denies the request, it may be permitted.
That outcome is not automatic: the complete rule set matters. In the standalone guide, no rules means allow. With denylist semantics—no Allow rules—unmatched traffic is allowed; when Allow rules exist, traffic that does not match an Allow is denied. A failed deny expression therefore does not, by itself, settle the final decision.
Why require is safer for mandatory conditions
If a condition must be true for a request to proceed, express it positively as a require condition in standalone configuration:
require: 'jwt.aud == "my-service"'
The request is denied if the audience is absent, the context cannot be resolved, or the expression evaluates false. Agentgateway’s standalone guide recommends require for mandatory conditions because it fails closed.
Rank #3
In Kubernetes policy configuration, JWT claims must be made available by configuring JWT authentication in the policy. If a CEL expression refers to jwt without that context, the expression may fail to match and deny traffic even though the policy appears accepted and attached. See the Kubernetes authorization documentation for that policy format and its requirements.
How the full rule set determines the decision
The standalone HTTP authorization guide describes this evaluation logic:
- No rules: the request is allowed.
- Matching Deny: the request is denied.
- Require checks: every Require must match; any failed Require denies the request.
- Matching Allow: the request is allowed if it has not already been denied.
- No match: if there are no Allow rules, unmatched traffic is allowed; if Allow rules exist, unmatched traffic is denied.
In the Kubernetes format, an authorization block has one action. To use multiple actions, create separate AgentgatewayPolicy resources. The Kubernetes documentation says Allow expressions are ORed, Require expressions are ANDed, and Deny takes precedence. Do not transfer standalone syntax examples directly into a Kubernetes policy without checking the applicable format.
Check that every referenced field exists at the policy phase
A CEL expression can be syntactically valid yet reference data unavailable when that policy is evaluated. The Kubernetes CEL reference explains that available variables differ by policy phase. For policies usable with both directly addressed and Service backends, it advises checking has(backend.endpoint) before reading backend.endpoint. Consult the CEL variables and functions reference for the phase-specific variables.
There is also a reported, version-specific concern in agentgateway issue #3092 involving authorization references to post-request fields such as mcp.tool.arguments, mcp.tool.result, and mcp.tool.error. The issue describes rules that fail to match or deny calls, and notes that a guard such as has(...) || ... can make a condition permissive. This report is not evidence that every MCP configuration behaves that way; verify the behavior for the release and flow you deploy.
Checklist for safer CEL authorization
- Decide whether the policy expresses a mandatory positive condition or a denylist exception. Use
requirewhen the condition must be true. - Confirm authentication provides the context your expression references. Missing or invalid JWTs may be rejected during authentication; an absent JWT context at authorization can instead cause CEL evaluation failure.
- Check the variable reference for the exact policy phase and deployment mode, including whether a field exists for the backend or request flow in question.
- Test missing claims, missing headers, and unavailable fields in the CEL playground and through a representative request flow. The documentation describes the playground; these checks should be performed for your own configuration.
- Review all Deny, Require, and Allow rules together. A failed Deny rule alone does not establish whether the request is ultimately allowed.
For standalone expression syntax and supported functions, consult the standalone CEL expressions reference and the agentgateway CEL functions schema.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errors




