October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

Agentgateway CEL Errors: What to Know About Rule Outcomes

In agentgateway authorization, a CEL error is treated as false—but deny and require interpret false differently. See safer patterns for mandatory claims and phase-specific fields.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An agentgateway CEL evaluation error does not always deny a request: an errored deny rule does not match and may fail open, while an errored require rule denies and fails closed. Use require for conditions that must be true—such as a required JWT audience—and verify that the referenced context exists when the policy runs.

What happens when an agentgateway CEL expression errors?

Agentgateway treats an expression it cannot evaluate as false, but the authorization rule’s action determines what that false result means. The standalone HTTP authorization documentation states: “A CEL expression that cannot be evaluated is treated as false.” (agentgateway HTTP authorization documentation.)

As an Amazon Associate I earn from qualifying purchases.

Rule type What triggers the rule’s effect False result or evaluation error Practical effect
deny The expression evaluates true. It does not match. That rule does not deny the request; another rule or the overall policy may still deny it.
require The expression must evaluate true. It fails. The request is denied.

The docs summarize the distinction directly: “A require expression that is false (or errors) denies the request (fail-closed),” while “A deny expression that errors does not match, so it does not deny the request (fail-open).” Those statements describe the standalone HTTP authorization guide; Kubernetes policy configuration has its own format and should be read separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a deny rule can fail open on a missing JWT audience

Consider this standalone HTTP authorization expression:

deny: 'jwt.aud != "my-service"'

It is intended to deny a token whose audience differs from my-service. But if the JWT context or jwt.aud is unavailable, CEL cannot evaluate the comparison. The result is false, so this deny rule does not match. If no other configured rule denies the request, it may be permitted.

That outcome is not automatic: the complete rule set matters. In the standalone guide, no rules means allow. With denylist semantics—no Allow rules—unmatched traffic is allowed; when Allow rules exist, traffic that does not match an Allow is denied. A failed deny expression therefore does not, by itself, settle the final decision.

Why require is safer for mandatory conditions

If a condition must be true for a request to proceed, express it positively as a require condition in standalone configuration:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
require: 'jwt.aud == "my-service"'

The request is denied if the audience is absent, the context cannot be resolved, or the expression evaluates false. Agentgateway’s standalone guide recommends require for mandatory conditions because it fails closed.

In Kubernetes policy configuration, JWT claims must be made available by configuring JWT authentication in the policy. If a CEL expression refers to jwt without that context, the expression may fail to match and deny traffic even though the policy appears accepted and attached. See the Kubernetes authorization documentation for that policy format and its requirements.

How the full rule set determines the decision

The standalone HTTP authorization guide describes this evaluation logic:

  1. No rules: the request is allowed.
  2. Matching Deny: the request is denied.
  3. Require checks: every Require must match; any failed Require denies the request.
  4. Matching Allow: the request is allowed if it has not already been denied.
  5. No match: if there are no Allow rules, unmatched traffic is allowed; if Allow rules exist, unmatched traffic is denied.

In the Kubernetes format, an authorization block has one action. To use multiple actions, create separate AgentgatewayPolicy resources. The Kubernetes documentation says Allow expressions are ORed, Require expressions are ANDed, and Deny takes precedence. Do not transfer standalone syntax examples directly into a Kubernetes policy without checking the applicable format.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check that every referenced field exists at the policy phase

A CEL expression can be syntactically valid yet reference data unavailable when that policy is evaluated. The Kubernetes CEL reference explains that available variables differ by policy phase. For policies usable with both directly addressed and Service backends, it advises checking has(backend.endpoint) before reading backend.endpoint. Consult the CEL variables and functions reference for the phase-specific variables.

There is also a reported, version-specific concern in agentgateway issue #3092 involving authorization references to post-request fields such as mcp.tool.arguments, mcp.tool.result, and mcp.tool.error. The issue describes rules that fail to match or deny calls, and notes that a guard such as has(...) || ... can make a condition permissive. This report is not evidence that every MCP configuration behaves that way; verify the behavior for the release and flow you deploy.

Checklist for safer CEL authorization

  • Decide whether the policy expresses a mandatory positive condition or a denylist exception. Use require when the condition must be true.
  • Confirm authentication provides the context your expression references. Missing or invalid JWTs may be rejected during authentication; an absent JWT context at authorization can instead cause CEL evaluation failure.
  • Check the variable reference for the exact policy phase and deployment mode, including whether a field exists for the backend or request flow in question.
  • Test missing claims, missing headers, and unavailable fields in the CEL playground and through a representative request flow. The documentation describes the playground; these checks should be performed for your own configuration.
  • Review all Deny, Require, and Allow rules together. A failed Deny rule alone does not establish whether the request is ultimately allowed.

For standalone expression syntax and supported functions, consult the standalone CEL expressions reference and the agentgateway CEL functions schema.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.