Skip to main content

Reputation plugins

Two plugins consult the reputation sources. As with the WAF, they differ in where they are configured and what they cover.

Cloud APIM Threat Protection - IP reputation​

A route plugin, evaluated during access validation — before the WAF reads any body.

{
"mode": "block",
"score_threshold": 0,
"status": 403,
"feeds": [],
"crowdsec": [],
"report_to_crowdsec": false,
"passthrough": ["10.0.0.0/8"]
}
FieldDefaultWhat it does
modeblockmonitor scores and reports without ever denying
score_threshold0Deny once the accumulated score reaches this. 0 means only block sources can deny
status403Status returned on a denial
feeds[]Feed ids to consult. Empty means every enabled feed
crowdsec[]Bouncer ids to consult. Empty means every enabled bouncer
(none)—ASN databases are not listed here: every enabled one is consulted. See the note below
report_to_crowdsecfalsePush denials back to CrowdSec as alerts
passthrough[]Addresses and CIDRs that bypass reputation entirely

A request is denied when mode is block and either a matching source is set to block, or the score reaches score_threshold.

Empty lists mean "everything"

Leaving feeds and crowdsec empty is the usual setup — sources are enabled or disabled on the entity, and every route inherits that. Name ids explicitly only when a route needs a different set.

ASN databases are always consulted

ASN classification has no plugin of its own — it is a third source inside this one. Every enabled AsnDatabase is consulted on every evaluation, and unlike feeds and crowdsec there is no per-route list to narrow it.

That is deliberate rather than an oversight: ASN ships as a low weight and never blocks on its own, so it is a signal you want everywhere or nowhere. Disable the database itself to switch it off, or set every category to weight 0.

Cloud APIM Threat Protection - IP reputation (Incoming Request Validator)​

The same logic, evaluated once per request before routing — cheaper, and it also covers traffic matching no route. It takes the same configuration.

Like the WAF's validator, it is a global plugin and is configured in the global configuration JSON:

{
"plugins": {
"config": {
"incoming_request_validators": [
{
"plugin": "cp:otoroshi_plugins.com.cloud.apim.otoroshi.extensions.waf.plugins.IncomingRequestValidatorCloudApimIpReputation",
"enabled": true,
"config": { "mode": "monitor", "score_threshold": 0 }
}
]
}
}
}

See the note on global plugins.

Where to put it​

Route pluginGlobal validator
Covers unrouted trafficNoYes
Per-route thresholdsYesNo
Monitoring modeYesYes

Reputation is one of the few things worth running globally: it is cheap, it is not route-specific, and the traffic it stops is exactly the traffic you do not want to spend routing on. A common shape is the global validator in monitor at first, then block with a conservative threshold, and the route plugin only where a route needs a stricter policy.