Plugin catalogue
| Plugin | Kind | Configured on |
|---|---|---|
| Cloud APIM Threat Protection - Preset | NgPresetPlugin | A route |
| Cloud APIM Threat Protection - Global Preset | NgPresetPlugin | The global configuration |
| Cloud APIM WAF | NgRequestTransformer | A route |
| Cloud APIM WAF - Incoming Request Validator | NgIncomingRequestValidator | The global configuration |
| Cloud APIM Threat Protection - IP reputation | NgAccessValidator | A route |
| Cloud APIM Threat Protection - IP reputation (Incoming Request Validator) | NgIncomingRequestValidator | The global configuration |
| Cloud APIM Threat Protection - Threat gate | NgAccessValidator | A route |
| Cloud APIM Threat Protection - Threat response | NgRequestTransformer | A route |
| Cloud APIM Threat Protection - Bot guard | NgAccessValidator | A route |
| Cloud APIM Threat Protection - Fail2ban | NgAccessValidator + NgRequestTransformer | A route |
| Cloud APIM Threat Protection - Honeypot (Incoming Request Validator) | NgIncomingRequestValidator | The global configuration |
| Cloud APIM Threat Protection - Traffic guard | NgAccessValidator | A route. See traffic guard |
| Cloud APIM Threat Protection - Upload guard | NgRequestTransformer | A route. See upload guard |
| Cloud APIM Threat Protection - Login guard | NgRequestTransformer | A route. See login guard |
| Cloud APIM Threat Protection - Object guard | NgRequestTransformer | A route. See object guard |
| Cloud APIM Threat Protection - API contract | NgRequestTransformer | A route. See API contracts |
| Cloud APIM Threat Protection - Error leakage guard | NgRequestTransformer | A route. See error leakage |
| Cloud APIM Threat Protection - Sensitive data guard | NgRequestTransformer | A route. See sensitive data |
All appear under the Threat Protection category.
Order on a route
The fabric plugins are position-sensitive:
1. Threat gate refuse callers already banned, before anything is inspected
2. Bot guard identify and verify crawlers
3. IP reputation contribute reputation signals
4. Fail2ban enforce its own bans; count failures on the way back out
5. Traffic guard score a surge away from the learned traffic
6. API contract check the request against the OpenAPI contract; the response too, when asked
7. Cloud APIM WAF inspect the payload
8. Upload guard judge every uploaded file by what it is
9. Login guard score stuffing, spraying and attacks on an account; count failures on the way back
10. Object guard count each consumer's objects, hold it to its budget; read the status on the way back
11. Threat response read the accumulated score, apply one tier
12. Error leakage guard on the way back, replace what leaks with a neutral error
13. Sensitive data guard then mask card numbers, IBANs, identifiers and secrets in place
The response plugin must come after the WAF, or it reads a score the WAF has not contributed to yet — silently, with every request still flowing. See the fabric.
The preset plugin expands into that exact chain with explicit
plugin_index values, which is the reason to prefer it over composing the five slots by hand. The
global preset produces the same chain from the global configuration,
picking what each route gets from a table of selectors rather than from a slot on the route.
Global plugins are not route plugins
The two incoming request validators do not appear in the route designer, and that is intentional.
Otoroshi reads incoming request validators from globalConfig.plugins.config.incoming_request_validators
and never from route.plugins. Adding one to a route would produce a plugin that sits there
looking configured and never runs — a worse outcome than not offering it at all. Otoroshi's own
incoming request validators are absent from the designer for the same reason.
There is no admin UI for that list, so it is edited as JSON on the global configuration:
{
"plugins": {
"config": {
"incoming_request_validators": [
{
"plugin": "cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimIpReputation",
"enabled": true,
"config": { "mode": "monitor" }
},
{
"plugin": "cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimWaf",
"enabled": true,
"config": { "ref": "waf-config_1f3a..." }
}
]
}
}
}
Each entry accepts plugin, enabled, debug, include, exclude and config. Order is
significant — validators run in the order listed, so put the cheap reputation check before the rule
engine.
Fully qualified class names
For the global configuration, and for anything that references plugins by id:
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimSecuritySuitePreset
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimWaf
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimWaf
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimIpReputation
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimIpReputation
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimThreatGate
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimThreatResponse
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimBotGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimFail2Ban
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimHoneypot
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimErrorLeakageGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimSensitiveDataGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimUploadGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimLoginGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimTrafficGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimObjectGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimApiContract