MatchExpr entries. All entries must match for the policy to execute (AND semantics). An empty list matches all requests.
AND vs OR
Within a single policy, match expressions are combined with AND. A policy with a path match and a method match only runs when both conditions are true. There is no built-in OR operator. To express OR, create multiple policies with the same config and different match lists. For example, to apply different rate limits to different parts of an API:/v1/search matches policy 1 and gets the stricter limit. A request to /v1/keys skips policy 1 (path does not match) and hits policy 2.
This approach is simpler to reason about than a recursive expression tree and covers the vast majority of routing needs. The proto schema is designed so that combinators (And/Or/Not) can be added later as new oneof branches without breaking the wire format.
Matcher types
Path
Matches againstrequest.URL.Path using a string match. The path is compared without the query string. Patterns must include the leading slash.
- Prefix
- Regex
- Exact (case-insensitive)
Method
Matches against the HTTP method. Comparison is always case-insensitive per the HTTP specification. Multiple methods can be listed, and the request matches if it uses any of them (OR semantics). An empty method list matches all methods.- Method only
- Path + Method (AND)
Header
Matches against request headers. Header names are matched case-insensitively per HTTP specification. When a header has multiple values, the match succeeds if any value matches (OR semantics).Header name. Matched case-insensitively.
Either
present (bool, checks header existence) or value (string match against header values).- Present
- Value match
Query parameter
Matches against URL query parameters. Parameter names are matched case-sensitively. When a parameter has multiple values, the match succeeds if any value matches (OR semantics).Parameter name. Matched case-sensitively.
Either
present (bool, checks parameter existence) or value (string match against parameter
values).- Present
- Value match