Enable Harness AI Securityv3.4+
Enable the Harness AI Security plugin on a Route or Service that already has the Harness WAAP plugin attached, or enable it globally if Harness WAAP is global.
Set the base plugin’s mode to sync if you need request evaluation, redaction, or blocking.
This configuration evaluates both the request and the response against the sensitive-data rules configured in the Traceable Platform, and fails open if the Edge Decision Service is unreachable or times out.
Set allow_on_failure to false on either block if you need evaluation failures to block traffic instead.
Note: A successful passthrough without redaction doesn’t necessarily indicate a problem. It can mean that no configured platform rule matched your test traffic.
Prerequisites
-
The Harness AI Security plugin is installed.
-
The Harness WAAP plugin is enabled on the same Route or Service, with
modeset tosync(required for request evaluation). -
A sensitive-data classification or data-protection rule is configured in the Traceable Platform for the content you want to detect, redact, or block.
Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: traceable-ai-extension
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: trueMake the following request:
curl -i -X POST http://localhost:8001/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongClusterPlugin
metadata:
name: traceable-ai-extension
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
labels:
global: 'true'
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: true
plugin: traceable-ai-extension
" | kubectl apply -f -Prerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_traceable_ai_extension" "my_traceable_ai_extension" {
enabled = true
config = {
request_config = {
timeout = 500
allow_on_failure = true
}
response_config = {
timeout = 500
allow_on_failure = true
}
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: traceable-ai-extension
service: serviceName|Id
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: trueMake sure to replace the following placeholders with your own values:
-
serviceName|Id: Theidornameof the service the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/services/{serviceName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
serviceName|Id: Theidornameof the service the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/services/{serviceId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
serviceId: Theidof the service the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: traceable-ai-extension
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: true
plugin: traceable-ai-extension
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the service resource:
kubectl annotate -n kong service SERVICE_NAME konghq.com/plugins=traceable-ai-extensionPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_traceable_ai_extension" "my_traceable_ai_extension" {
enabled = true
config = {
request_config = {
timeout = 500
allow_on_failure = true
}
response_config = {
timeout = 500
allow_on_failure = true
}
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
service = {
id = konnect_gateway_service.my_service.id
}
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: traceable-ai-extension
route: routeName|Id
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: trueMake sure to replace the following placeholders with your own values:
-
routeName|Id: Theidornameof the route the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/routes/{routeName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
routeName|Id: Theidornameof the route the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/routes/{routeId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
routeId: Theidof the route the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: traceable-ai-extension
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: true
plugin: traceable-ai-extension
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the httproute or ingress resource:
kubectl annotate -n kong httproute konghq.com/plugins=traceable-ai-extensionkubectl annotate -n kong ingress konghq.com/plugins=traceable-ai-extensionPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_traceable_ai_extension" "my_traceable_ai_extension" {
enabled = true
config = {
request_config = {
timeout = 500
allow_on_failure = true
}
response_config = {
timeout = 500
allow_on_failure = true
}
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
route = {
id = konnect_gateway_route.my_route.id
}
}Add this section to your kong.yaml configuration file:
_format_version: "3.0"
plugins:
- name: traceable-ai-extension
consumer_group: consumerGroupName|Id
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: trueMake sure to replace the following placeholders with your own values:
-
consumerGroupName|Id: Theidornameof the consumer group the plugin configuration will target.
Make the following request:
curl -i -X POST http://localhost:8001/consumer_groups/{consumerGroupName|Id}/plugins/ \
--header "Accept: application/json" \
--header "Content-Type: application/json" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
consumerGroupName|Id: Theidornameof the consumer group the plugin configuration will target.
Make the following request:
curl -X POST https://{region}.api.konghq.com/v2/control-planes/{controlPlaneId}/core-entities/consumer_groups/{consumerGroupId}/plugins/ \
--header "accept: application/json" \
--header "Content-Type: application/json" \
--header "Authorization: Bearer $KONNECT_TOKEN" \
--data '
{
"name": "traceable-ai-extension",
"config": {
"request_config": {
"timeout": 500,
"allow_on_failure": true
},
"response_config": {
"timeout": 500,
"allow_on_failure": true
}
}
}
'Make sure to replace the following placeholders with your own values:
-
region: Geographic region where your Kong Konnect is hosted and operates. -
KONNECT_TOKEN: Your Personal Access Token (PAT) associated with your Konnect account. -
controlPlaneId: Theidof the control plane. -
consumerGroupId: Theidof the consumer group the plugin configuration will target.
See the Konnect Control Planes Config API reference to learn about region-specific URLs and personal access tokens.
echo "
apiVersion: configuration.konghq.com/v1
kind: KongPlugin
metadata:
name: traceable-ai-extension
namespace: kong
annotations:
kubernetes.io/ingress.class: kong
config:
request_config:
timeout: 500
allow_on_failure: true
response_config:
timeout: 500
allow_on_failure: true
plugin: traceable-ai-extension
" | kubectl apply -f -Next, apply the KongPlugin resource by annotating the KongConsumerGroup resource:
kubectl annotate -n kong kongconsumergroup CONSUMERGROUP_NAME konghq.com/plugins=traceable-ai-extensionPrerequisite: Configure your Personal Access Token
terraform {
required_providers {
konnect = {
source = "kong/konnect"
}
}
}
provider "konnect" {
personal_access_token = "$KONNECT_TOKEN"
server_url = "https://us.api.konghq.com/"
}Add the following to your Terraform configuration to create a Konnect Gateway Plugin:
resource "konnect_gateway_plugin_traceable_ai_extension" "my_traceable_ai_extension" {
enabled = true
config = {
request_config = {
timeout = 500
allow_on_failure = true
}
response_config = {
timeout = 500
allow_on_failure = true
}
}
control_plane_id = konnect_gateway_control_plane.my_konnect_cp.id
consumer_group = {
id = konnect_gateway_consumer_group.my_consumer_group.id
}
}