Commit 17254d7
authored
feat(middleware): add dynamic conditional middleware guardrails (#831)
#### Overview
Add dynamically registered conditional middleware guardrails that can enable or disable global runtime registrations by registration kind and effective name. The surface is available to Rust, primary language bindings, native plugins, and gRPC worker plugins without introducing a new native ABI version beyond V4.
- [x] I confirm this contribution is my own work, or I have the right to submit it under this project's license.
- [x] I searched existing issues and open pull requests, and this does not duplicate existing work.
#### Details
- Add stable runtime-registration kinds, structured registration identity/discovery, and a process-global conditional guardrail registry.
- Centralize the shared runtime-registration discovery DTOs in `nemo-relay-types` while preserving the existing core, native plugin SDK, and worker SDK import paths through re-exports.
- Apply matching gates at runtime snapshot boundaries so registering or deregistering a gate changes behavior between turns without rebuilding the underlying registration registry.
- Preserve the agreed invariants: global registrations only, scope-local registrations remain ungated, every matching gate must allow a target, and gate failures fail open.
- Expose registration discovery and dynamic gate lifecycle APIs through Rust, Python, Node.js, experimental Go/C FFI, native plugin ABI V4, and the gRPC worker protocol/Python worker SDK.
- Document native and worker timer-driven control patterns and middleware semantics.
Validation:
- `cargo test -p nemo-relay-types` — passed, including stable kind serialization, DTO round trips, and trait coverage.
- `just test-rust` — passed.
- `just test-python` — passed (689 package tests and 19 Python plugin-example tests).
- `just test-node` — passed (396 package tests and 21 Node plugin-example tests).
- The new Go conditional-guardrail test passed. `just test-go` otherwise reaches the existing `TestObservabilityPluginActivatesDerivedLogsAndExplicitMetrics` timeout waiting for `/v1/logs`; the same failure reproduced twice from untouched `origin/release/0.8`, so it is not introduced by this branch.
- `cargo clippy --workspace --all-targets -- -D warnings` — passed.
- `uv run pre-commit run --all-files` — passed.
Real-provider end-to-end validation has not been run. Current executable coverage uses in-process/runtime fixtures and local test collectors.
Breaking changes: none expected. This extends the V4 ABI being introduced for the 0.8 release rather than adding V5. The shared DTO move preserves existing Rust import paths and JSON/protobuf/C ABI wire shapes.
#### Where should the reviewer start?
Start with `crates/types/src/api/registry.rs` for the canonical discovery model and `crates/core/src/api/registry.rs` for the gate registry and compatibility re-exports, then `crates/core/src/api/runtime/state.rs` for runtime filtering semantics. Cross-plane APIs are centered in `crates/plugin/src/lib.rs`, `crates/core/src/plugin/dynamic/worker.rs`, and `crates/worker-proto/proto/nemo/relay/worker/v1/plugin_worker.proto`. End-to-end core behavior is covered in `crates/core/tests/integration/middleware_tests.rs`.
#### Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)
- Relates to: N/A
## Summary by CodeRabbit
- **New Features**
- Added conditional middleware guardrails that can temporarily disable matching subscribers, sanitizers, guardrails, metadata injectors, or intercepts.
- Added runtime registration discovery with filtering and ownership metadata.
- Added management APIs across Python, Node.js, Go, C, native plugins, and worker plugins.
- Added lifecycle cleanup, callback safety, and fail-open behavior.
- **Bug Fixes**
- Improved runtime consistency by evaluating middleware from stable snapshots.
- **Documentation**
- Documented guardrail behavior, ordering, ownership, discovery, and usage.
Authors:
- Bryan Bednarski (https://github.com/bbednarski9)
- Will Killian (https://github.com/willkill07)
Approvers:
- Will Killian (https://github.com/willkill07)
URL: #8311 parent b4ef220 commit 17254d7
53 files changed
Lines changed: 5118 additions & 370 deletions
File tree
- crates
- core
- src
- api
- runtime
- context
- plugin/dynamic
- tests
- fixtures
- native_plugin/src
- worker_plugin/src
- integration
- unit
- ffi
- src
- api
- tests/unit/api
- node
- src
- api
- tests
- plugin
- src
- tests
- python/src/py_api
- types
- src/api
- tests
- worker-proto/proto/nemo/relay/worker/v1
- worker
- src
- tests
- docs
- about-nemo-relay/concepts
- build-plugins
- native
- workers
- go/nemo_relay
- python
- nemo_relay
- plugin/src/nemo_relay_plugin
- tests
- plugin
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
9 | | - | |
10 | | - | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
15 | 15 | | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
16 | 275 | | |
17 | 276 | | |
18 | 277 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
11 | | - | |
| 11 | + | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
| 21 | + | |
21 | 22 | | |
22 | 23 | | |
23 | 24 | | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
27 | 28 | | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
28 | 37 | | |
29 | 38 | | |
30 | 39 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
369 | 369 | | |
370 | 370 | | |
371 | 371 | | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
372 | 387 | | |
373 | 388 | | |
374 | 389 | | |
| |||
0 commit comments