apiVersion: extensions.istio.io/v1alpha1 kind: WasmPlugin metadata: creationTimestamp: "2026-06-10T00:35:12Z" generation: 7 labels: kuadrant.io/managed: "true" managedFields: - apiVersion: extensions.istio.io/v1alpha1 fieldsType: FieldsV1 fieldsV1: f:metadata: f:labels: .: {} f:kuadrant.io/managed: {} f:ownerReferences: .: {} k:{"uid":"847e2486-4157-489a-9f82-93407d06f083"}: {} f:spec: .: {} f:phase: {} f:pluginConfig: .: {} f:actionSets: {} f:services: .: {} f:auth-service: .: {} f:endpoint: {} f:failureMode: {} f:timeout: {} f:type: {} f:ratelimit-check-service: .: {} f:endpoint: {} f:failureMode: {} f:timeout: {} f:type: {} f:ratelimit-report-service: .: {} f:endpoint: {} f:failureMode: {} f:timeout: {} f:type: {} f:ratelimit-service: .: {} f:endpoint: {} f:failureMode: {} f:timeout: {} f:type: {} f:targetRefs: {} f:url: {} manager: manager operation: Update time: "2026-06-10T00:37:36Z" name: kuadrant-maas-default-gateway namespace: openshift-ingress ownerReferences: - apiVersion: gateway.networking.k8s.io/v1 blockOwnerDeletion: true controller: true kind: Gateway name: maas-default-gateway uid: 847e2486-4157-489a-9f82-93407d06f083 resourceVersion: "28505" uid: f98828d0-bc85-4e02-b555-b549da43a1c4 spec: phase: STATS pluginConfig: actionSets: - actions: - scope: 9bbfc0b2e9e9acadd41342cd7c36a24afa8a5eef942d161782a6adae8411158a service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: d3ebc9b090772d606e8b0054df99581eb8ca6a728b50a06b26997ec5a3c934c4 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-unconfigured-facebook-opt-125m-simulated/v1/chat/completions') - actions: - scope: 01918e70442d2cb18c94316131b0e0a241b4a5d12df5b1e1981a3bef420bbdb5 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: cc8ec555bc850da61662c956013a5dd85635138a47e13f9cb1c5d29b061aa027 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-unconfigured-facebook-opt-125m-simulated/v1/completions') - actions: - scope: e38d76c6f386f12bc12190c87b39e6e77e182be454f85659a9197c301f2cd9be service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 500d9b361aefca75bd8ecc3539b967d444b636b395eb8e561f4486fb92c3393a routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-unconfigured-facebook-opt-125m-simulated/v1/responses') - actions: - scope: edcceb5a2e0cf1edde0fc3ed43068ce5b123a6fdc41949959c2c3b7a5a48bf24 service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium name: 44c5682c6e286234061f9d89188d28f63c18b6ee88968d9d8c9a27c0b3aeda82 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/premium-simulated-simulated-premium/v1/chat/completions') - actions: - scope: 80f10756c0e833d16937036ed66f1daf5bef95559ef05a5e852766b97b9bdaef service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium name: 9bc2b4ccec3f1161c49f6a430b7835ce849f6cc713a06c508f1aeff713856f84 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/premium-simulated-simulated-premium/v1/completions') - actions: - scope: 4dc577fd60594d78a4a8bebe396f4b5a928f41bdc3f95c06d717cf1ddc3158b2 service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium name: 2d69c30b369124e36bc288a4de934b0ba675642036862fe16ae4ced0bf1a1a89 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/premium-simulated-simulated-premium/v1/responses') - actions: - scope: 18e32965997cdd9967355c6fa5264ed12c0a215989d459ed88d7d6de02865f76 service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated name: d1d09ba6908379aaf2cdddc20fd315192a4988b007de45adf3f92563551a945b routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/facebook-opt-125m-simulated/v1/chat/completions') - actions: - scope: e50f5fdcb9fb7e124557afe69edae9a95d05da488eae1cc4b5c1c7c1220a826a service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 98aabcb3b04ab3e54795a14ce9e6475b625de6eeeb37c8166c88cd5b4adadc2b routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-2-simulated/v1/chat/completions') - actions: - scope: 9903213c635804dd416e9f12956f0fa896195627091daaf593a30df64cf640c5 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-unconfigured-facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 046c543cdee7d4fdf67d018b2770334cb4d5cd22dd43b6de07bafb37a76096b4 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-unconfigured-facebook-opt-125m-simulated') - actions: - scope: 319a353672fc7601c875fa3f8b807adf60b64f093f022b2a1c3dfef3ac8cd4f4 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 003443caeffda8bf30c00a513818ab4e7e5d8f4c4e58facdc527ae1fcfc10543 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-trlp-test-simulated/v1/chat/completions') - actions: - scope: 3dc75fc8307b952a3e873400cf417e90f2861e8a225abec4b22708deb7901db7 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: e3c39edfb64a9c733baa26a09814d0a0a75195146d5f355263e77188a6ac3bcd routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-simulated/v1/chat/completions') - actions: - scope: cc09b530b46a73b0d4ddb40e465580cff15db19d77e93e4903c9737647deeb1a service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated name: 41ea38011fd0dffd1811e0dae9a10db714b0b04878152f5ac01ef0e6a40ed800 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/facebook-opt-125m-simulated/v1/completions') - actions: - scope: 311b1be286674fd5684c9ac59b318287dade9769cfe4aeebd8c88e2dc6b72418 service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated name: 6148509a8fd27ae35ff7107199890334e0f0c1f541b9a8df95c75433e9f90be6 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/facebook-opt-125m-simulated/v1/responses') - actions: - scope: 331dc257e65f55f80700a586f7807093eda7b3d8e7d91215dc3c47731508480c service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: b883d2d0e60958f69d90b8d1d7c9cdedd7ebab36c3f8d1df9b55262568191c6b routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-2-simulated/v1/completions') - actions: - scope: bf72a6316f6ed79299511e58d068836cdc71dbca5e23944f783c9340ffa0aee1 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 8e7acde54d1d64889ccb1aacf21b7139806b1810857b7470d936cd8b52f159f5 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-trlp-test-simulated/v1/completions') - actions: - scope: 35d34d59676c333235d7c9f02273e0380bb39f27cfd30856fedc0f7c0e5f79aa service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 6009540e8d30921c6deeedb6e24db2ea87987b63a97bf42ed5e0b032eecdac39 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-2-simulated/v1/responses') - actions: - scope: 3c0d47082320c9bb02d3788ab2b052c696af91abc2ae438437ae71a26936c7c2 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 0150a080af75519c01789ba99d8defd6f322cb28d491506ddf9ae2f9af8800e9 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-simulated/v1/completions') - actions: - scope: df733b2c652bfe2458c9e19932b1091e939c1a62178d6879462b3b4f73fca4bb service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 4fbba06e8aca90fd7598a22da99a2616f0316776243c36331a8bbe6b6687d08e routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-trlp-test-simulated/v1/responses') - actions: - scope: d3b195a61a7f24c6bf1fba40f9f2e2565facb6af92e959c1546ac398a9172618 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 8c8e8394d0d0eece84adb46c6c418ffc319049e3584f5adb1c1d0853b05c8a44 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-simulated/v1/responses') - actions: - scope: 7371c34ce8e4df2309ee8f952c87f921947b289427b6e9ea579dcb9970fc1b86 service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_premium_simulator_subscription_premium_simulated_simulated_premium_tokens__a2a80825 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/premium-simulator-subscription@llm/premium-simulated-simulated-premium" && !request.path.endsWith("/v1/models") scope: llm/premium-simulated-simulated-premium-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-premium-simulated-simulated-premium name: 37b061be1aeae130bb743b62160084e090be87323ead0e882e86df682fb00168 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/premium-simulated-simulated-premium') - actions: - scope: 3dd75e19cd66d310c30638e330078972afd6d2d96305f91055bc6a6f363fb8d3 service: auth-service sources: - authpolicy.kuadrant.io:llm/maas-auth-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated - conditionalData: - data: - expression: key: tokenlimit.models_as_a_service_simulator_subscription_facebook_opt_125m_simulated_tokens__87db8427 value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - auth.identity.selected_subscription_key == "models-as-a-service/simulator-subscription@llm/facebook-opt-125m-simulated" && !request.path.endsWith("/v1/models") scope: llm/facebook-opt-125m-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:llm/maas-trlp-facebook-opt-125m-simulated name: 6d55ac49e70e281c544499ecb02cc8598bf21f94ff4ccf11ef0eaca6b14273c1 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/facebook-opt-125m-simulated') - actions: - scope: a89b0896df0d8cd430f1c81b6eb292ddc044daed393537d009a6330718f58d4b service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-2-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 54d0a7b8bad434065cd7334c670611348fd3b6e11083af581c2ee34f98a71e2a routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-2-simulated') - actions: - scope: 5fea747cb803a5ee3aeb620187bd9ec74ccccd10a92474ef528215a7ff146c8f service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-trlp-test-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 54f4e8b226e970ee866fe05d05b77ab4aebed5d4132403b6e7525bd0acc9080f routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-trlp-test-simulated') - actions: - scope: 86cbb62fb4d82d4dc402b3281444539a5625c4bb4c86bbc4912c70e690a2e374 service: auth-service sources: - authpolicy.kuadrant.io:openshift-ingress/gateway-default-auth - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: llm/e2e-distinct-simulated-kserve-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 7e303161cba4dd81544b9d4eabcea3e89336c99e27c62e7ae39aeb6320c9e049 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/llm/e2e-distinct-simulated') - actions: - predicates: - request.path != "/maas-api/health" || request.method != "GET" scope: 64a4fb0342f88ea589d83c2f8fa31545655652a27e95b54e34ff1aea7a23ce7a service: auth-service sources: - authpolicy.kuadrant.io:redhat-ai-gateway-infra/maas-api-auth-policy - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: redhat-ai-gateway-infra/maas-api-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: redhat-ai-gateway-infra/maas-api-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: 0fd71d47ef8124b1df5b58057ef7ee46139072b8517f047a576e27c28d390547 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/v1/models') - actions: - predicates: - request.path != "/maas-api/health" || request.method != "GET" scope: 36a57cb26c1f3baa754055a5b21729579f55f7d59e2035fdb41cf938a33d7612 service: auth-service sources: - authpolicy.kuadrant.io:redhat-ai-gateway-infra/maas-api-auth-policy - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: "0" predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: redhat-ai-gateway-infra/maas-api-route service: ratelimit-check-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny - conditionalData: - data: - expression: key: tokenlimit.deny_all_by_default__6d45535f value: "1" - expression: key: auth.identity.userid value: auth.identity.userid - expression: key: ratelimit.hits_addend value: responseBodyJSON("/usage/total_tokens") predicates: - '!request.path.startsWith("/maas-api") && !request.path.startsWith("/v1/models")' scope: redhat-ai-gateway-infra/maas-api-route service: ratelimit-report-service sources: - tokenratelimitpolicy.kuadrant.io:openshift-ingress/gateway-default-deny name: ab7f4f2d0042528265930d08bdbfdd294b0ac5888a4ec0ca32ccb9d0f2ac6b21 routeRuleConditions: hostnames: - maas.apps.4117d229-f4b5-4d96-b3c5-8cee1529bfd5.prod.konfluxeaas.com predicates: - request.url_path.startsWith('/maas-api') services: auth-service: endpoint: kuadrant-auth-service failureMode: deny timeout: 200ms type: auth ratelimit-check-service: endpoint: kuadrant-ratelimit-service failureMode: deny timeout: 100ms type: ratelimit-check ratelimit-report-service: endpoint: kuadrant-ratelimit-service failureMode: deny timeout: 100ms type: ratelimit-report ratelimit-service: endpoint: kuadrant-ratelimit-service failureMode: allow timeout: 100ms type: ratelimit targetRefs: - group: gateway.networking.k8s.io kind: Gateway name: maas-default-gateway url: quay.io/kuadrant/wasm-shim:v0.12.1