gateway AGENTS.md

AGENTS.md instructions for varnish/gateway, covering varnish gateway operator - development guide, project overview, documentation, current status and component overview.

Instructions file for CodexOpenCode

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/varnish/gateway/agents-md
Clone the repo
git clone --depth 1 https://github.com/varnish/gateway

Made for: Codex, OpenCode.

Per session 6,015 This file is loaded in full into every session.
When invoked 6,015 The same file — it is already loaded in full.
Security scan C 1 finding. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.06015 $0.06015
Opus 5 $0.03008 $0.03008
Sonnet 5 $0.01203 $0.01203
Haiku 4.5 $0.00602 $0.00602

Measured yesterday against content hash 1a9bc50327a9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade C, and why

gateway AGENTS.md scanned grade C with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reaches for credential fileshighPrivilege escalation

SSH keys, cloud credentials, git-credentials, .npmrc, /etc/shadow: reading these is how a config file becomes a credential leak.

# Run operator locally (uses ~/.kube/config)
AGENTS.md · 628 lines

How it starts

The opening of the file, as written. The whole thing — 628 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Varnish Gateway Operator - Development Guide

Project Overview

Kubernetes Gateway API implementation using Varnish. Three components:

  • operator: watches Gateway API resources, generates ghost.json config, manages deployments
  • chaperone: handles endpoint discovery and triggers ghost reload
  • ghost: Rust VMOD that handles all routing logic internally

Documentation

Current Status

The project passes the Gateway API conformance test suite (make test-conformance). Remaining work is tracked in GitHub issues.

Component Overview

Operator (cmd/operator/main.go):

  • Gateway controller - creates Deployment, Service, ConfigMap, Secret, ServiceAccount
  • HTTPRoute controller - watches routes, regenerates routing.json on changes
  • Status conditions (Accepted/Programmed) on Gateway and HTTPRoute
  • GatewayClassParameters CRD for user VCL injection and varnishd extra args
  • Client-side TLS termination with cert-manager support and hot-reload

Chaperone (cmd/chaperone/main.go):

  • Starts and manages varnishd via vrun package
  • Watches routing.json + EndpointSlices, merges into ghost.json
  • Triggers ghost reload via HTTP, VCL reload via varnishadm
  • TLS cert loading and hot-reload via fsnotify

Ghost VMOD (ghost/):

  • Rust-based VMOD handling all routing inside Varnish
  • Path matching (exact, prefix, regex), method, header, query parameter matching
  • Priority-based route selection with additive specificity bonuses
  • Hot-reload via /.varnish-ghost/reload
  • See ghost/CLAUDE.md and ghost/README.md for details

Key Packages

  • internal/ghost/ - Config types, ghost.json generator, EndpointSlice watcher
  • internal/vcl/ - VCL generator, merge, hot-reload via varnishadm
  • internal/varnishadm/ - Full varnishadm protocol (reverse mode, -M flag)
  • internal/vrun/ - varnishd process lifecycle management
  • internal/reload/ - HTTP client for ghost reload endpoint

Read the full file on GitHub · 628 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 628 lines · 6,015 tokens per session scan C 1a9bc50327a9

Subscribe to this mod's changes

gateway AGENTS.md is an instructions file published in the GitHub repository varnish/gateway (16 stars, last pushed 6d ago), licensed Apache-2.0. It adds 6,015 tokens to every session, about $0.0301 per session on Opus 5. A static security scan graded it C with 1 finding (reaches for credential files). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,345 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

next.js AGENTS.md

Instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens