MCP Guardrails: Gate Tool Calls at the Method Layer With Agentgateway's ExtMCP
bibryam · x · 2026-10-04
A hands-on Cloud Native Deep Dive post explains how to build MCP guardrails with agentgateway.
- Standard gateways ship policy enforcement, auth and filtering, but custom inspection/mutation or proprietary policy engines require an extension point
- The classic primitive is ExtProc: offloading HTTP request/response processing to an external service over high-performance bidirectional gRPC streams
- For MCP, the equivalent is ExtMCP — not a thin ExtProc wrapper but a third-party callout primitive operating on parsed MCP method calls rather than raw HTTP, playing a role akin to extauthz/ExtProc
- Prerequisites for the walkthrough: a Kubernetes cluster (local is fine), agentgateway OSS, and a GitHub PAT — useful for engineers who want method-level tool-call control on production agent traffic
More from coding & agent
- Agent Guard uses CEL policies to block coding agents' risky dependency installs — HowDevelop · 2026-10-04
- Dev and vendor outsource negotiation to Codex and Claude, both run out of credits — LadyAshBorg · 2026-10-04
- When to split Cursor projects? Devs debate multi-project vs one big project — vinvan · 2026-10-04
- "Be creative" prompts drift across agent models, checkable requirements don't — ClickOk5811 · 2026-10-04
- Next breakout coding tool: a single orchestrator on top of parallel cloud agents — vinvan · 2026-10-04
- One plugin fixes Claude Code's browser use: install Browser Use CLI to catch up with Codex — EXM7777 · 2026-10-04