Skip to main content

Plugin catalogue

PluginKindConfigured on
Cloud APIM Threat Protection - PresetNgPresetPluginA route
Cloud APIM Threat Protection - Global PresetNgPresetPluginThe global configuration
Cloud APIM WAFNgRequestTransformerA route
Cloud APIM WAF - Incoming Request ValidatorNgIncomingRequestValidatorThe global configuration
Cloud APIM Threat Protection - IP reputationNgAccessValidatorA route
Cloud APIM Threat Protection - IP reputation (Incoming Request Validator)NgIncomingRequestValidatorThe global configuration
Cloud APIM Threat Protection - Threat gateNgAccessValidatorA route
Cloud APIM Threat Protection - Threat responseNgRequestTransformerA route
Cloud APIM Threat Protection - Bot guardNgAccessValidatorA route
Cloud APIM Threat Protection - Fail2banNgAccessValidator + NgRequestTransformerA route
Cloud APIM Threat Protection - Honeypot (Incoming Request Validator)NgIncomingRequestValidatorThe global configuration
Cloud APIM Threat Protection - Traffic guardNgAccessValidatorA route. See traffic guard
Cloud APIM Threat Protection - Upload guardNgRequestTransformerA route. See upload guard
Cloud APIM Threat Protection - Login guardNgRequestTransformerA route. See login guard
Cloud APIM Threat Protection - Object guardNgRequestTransformerA route. See object guard
Cloud APIM Threat Protection - API contractNgRequestTransformerA route. See API contracts
Cloud APIM Threat Protection - Error leakage guardNgRequestTransformerA route. See error leakage
Cloud APIM Threat Protection - Sensitive data guardNgRequestTransformerA route. See sensitive data

All appear under the Threat Protection category.

Order on a route​

The fabric plugins are position-sensitive:

1. Threat gate refuse callers already banned, before anything is inspected
2. Bot guard identify and verify crawlers
3. IP reputation contribute reputation signals
4. Fail2ban enforce its own bans; count failures on the way back out
5. Traffic guard score a surge away from the learned traffic
6. API contract check the request against the OpenAPI contract; the response too, when asked
7. Cloud APIM WAF inspect the payload
8. Upload guard judge every uploaded file by what it is
9. Login guard score stuffing, spraying and attacks on an account; count failures on the way back
10. Object guard count each consumer's objects, hold it to its budget; read the status on the way back
11. Threat response read the accumulated score, apply one tier
12. Error leakage guard on the way back, replace what leaks with a neutral error
13. Sensitive data guard then mask card numbers, IBANs, identifiers and secrets in place

The response plugin must come after the WAF, or it reads a score the WAF has not contributed to yet — silently, with every request still flowing. See the fabric.

The preset plugin expands into that exact chain with explicit plugin_index values, which is the reason to prefer it over composing the five slots by hand. The global preset produces the same chain from the global configuration, picking what each route gets from a table of selectors rather than from a slot on the route.

Global plugins are not route plugins​

The two incoming request validators do not appear in the route designer, and that is intentional.

Otoroshi reads incoming request validators from globalConfig.plugins.config.incoming_request_validators and never from route.plugins. Adding one to a route would produce a plugin that sits there looking configured and never runs — a worse outcome than not offering it at all. Otoroshi's own incoming request validators are absent from the designer for the same reason.

There is no admin UI for that list, so it is edited as JSON on the global configuration:

{
"plugins": {
"config": {
"incoming_request_validators": [
{
"plugin": "cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimIpReputation",
"enabled": true,
"config": { "mode": "monitor" }
},
{
"plugin": "cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimWaf",
"enabled": true,
"config": { "ref": "waf-config_1f3a..." }
}
]
}
}
}

Each entry accepts plugin, enabled, debug, include, exclude and config. Order is significant — validators run in the order listed, so put the cheap reputation check before the rule engine.

Fully qualified class names​

For the global configuration, and for anything that references plugins by id:

cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimSecuritySuitePreset
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimWaf
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimWaf
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimIpReputation
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimIpReputation
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimThreatGate
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimThreatResponse
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimBotGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimFail2Ban
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimHoneypot
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimErrorLeakageGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimSensitiveDataGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimUploadGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimLoginGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimTrafficGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimObjectGuard
cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.CloudApimApiContract