METADATA ======= Last Updated: 2026-09-30 Title: Clearplane - LLM Documentation Index Product: Clearplane self-hosted web security gateway Clearplane routes and protects traffic for services running in Docker infrastructure you control. These files contain the same documentation as the human-readable pages under /docs/. FULL DOCUMENTATION (recommended for agents): /llms/llms-full.txt A single consolidated file containing all published Clearplane documentation. Individual Documentation Files: - /llms/cli/index.txt Every embedded Clearplane command for setup, status, administrator recovery, bans, cache purges, databases, and secrets. - /llms/concepts/configuration-lifecycle.txt Understand validation, revisions, apply modes, and last-valid configuration behavior. - /llms/concepts/configuration-ownership.txt Know whether to edit a resource through the UI or API, or through Docker labels. - /llms/concepts/index.txt Understand the routing, policy, ownership, and configuration models behind Clearplane. - /llms/concepts/policies-and-scope.txt Understand reusable policies, route assignments, global defaults, and evaluation precedence. - /llms/concepts/routing-model.txt Match exact and wildcard hosts, then follow requests through clusters to upstream applications. - /llms/configuration/catalog.txt Generated configuration metadata with sources, UI locations, defaults, and examples. - /llms/configuration/docker-labels.txt How Clearplane applies Docker labels, with worked examples and the rules the configuration catalog does not cover. - /llms/configuration/environment-variables.txt Supply Clearplane bootstrap settings and secrets through environment variables, mounted secret files, and Compose inputs. - /llms/configuration/index.txt Look up every supported Clearplane configuration setting. - /llms/configuration/rest-api.txt Use Clearplane's public management API and generated OpenAPI contract safely. - /llms/get-started/index.txt Install Clearplane with Docker Compose and choose optional Cloud health and error reporting. - /llms/guides/access-traffic-delivery.txt Choose access, abuse-control, header, cross-origin, compression, and cache controls. - /llms/guides/bot-challenges.txt Use Edge proof-of-work challenges for WAF signals and rate limits, without a third-party service. - /llms/guides/enable-https.txt Configure wildcard HTTPS with DNS credentials on each app or shared numbered Core profiles. - /llms/guides/export-metrics-and-waf-events.txt Send WAF metrics to OTLP or Prometheus and deliver WAF audit events to your SIEM. - /llms/guides/index.txt Complete common Clearplane tasks through the UI or Docker labels. - /llms/guides/protect-service.txt Apply temporary IP bans when clients repeatedly produce selected upstream 4xx responses. - /llms/guides/publish-service.txt Route a public hostname to an upstream application through the UI or Docker labels. - /llms/guides/validate-api-schemas.txt Upload an OpenAPI document to a WAF policy so the WAF scores requests that do not match it. - /llms/guides/write-custom-waf-rules.txt Write, test and publish your own WAF rulesets, without Cloud. - /llms/index.txt Deploy, configure, protect, and operate Clearplane. - /llms/operations/change-apply-configuration.txt Apply configuration, manage privacy and community consent, and find the installation ID. - /llms/operations/index.txt Monitor Clearplane, apply changes, and resolve service failures. - /llms/operations/status-traffic-security.txt Review service health and traffic, browse indexed logs, and manage background clearing and retention. - /llms/operations/troubleshoot-service.txt Diagnose routing, upstream, HTTPS, and policy failures from the observed symptom. - /llms/security/container-runtime-isolation.txt Understand how ContainerProxy limits access to the Docker runtime socket. - /llms/security/exposure-and-networks.txt See which Clearplane component is public and what each Docker network connects. - /llms/security/hardening-checklist.txt Apply layered controls to the Clearplane host, management routes, and published services. - /llms/security/index.txt Understand Clearplane's exposure, network, service-identity, and container-runtime boundaries. - /llms/security/internal-service-trust.txt Understand how Clearplane authenticates each internal service connection. - /llms/security/third-party-notices.txt Third-party work included in Clearplane and the licence text each licence requires. - /llms/security/waf-api-schema.txt Scoring for configured OpenAPI validation failures. - /llms/security/waf-command-injection.txt CRS 932 patterns with native shell and server-side include supplements. - /llms/security/waf-coverage.txt Measured detection and false-positive rates of the recorded WAF ruleset payloads. - /llms/security/waf-data-leakage.txt Database, PHP, Java and IIS errors, source disclosure and directory listings. - /llms/security/waf-detections.txt Review every request the WAF matched a rule against, see its redacted request context, and tune a WAF policy before switching it to Prevention. - /llms/security/waf-exclusion-rulesets.txt Opt a route into an application's exclusion ruleset so known false positives stay suppressed without per-route tuning. - /llms/security/waf-inspected-traffic.txt Configure inspection of WebSocket messages, binary gRPC streams, large request bodies and upstream responses. - /llms/security/waf-path-traversal.txt CRS 930 patterns with bounded repeated-decoding checks. - /llms/security/waf-protocol.txt CRS 920–922 checks, request framing and incomplete inspection. - /llms/security/waf-rulesets.txt Understand WAF policies, active rulesets, release stages, opt-outs, and rollback. - /llms/security/waf-scanners.txt Known scanner user-agent signatures from CRS 913. - /llms/security/waf-scoring-and-paranoia.txt Choose how ruleset scores combine and inspect higher paranoia levels without adding blocking scores. - /llms/security/waf-sql-injection.txt CRS 942 patterns and data-driven libinjection SQL fingerprints. - /llms/security/waf-xss.txt CRS 941 patterns and data-driven libinjection HTML/XSS fingerprints. - /llms/waf-reference/detectors-and-patterns.txt Reusable word data, token patterns and fingerprint detectors. - /llms/waf-reference/examples.txt Compiler-tested rules, token patterns, a bot challenge and a conditional exclusion. - /llms/waf-reference/facts-and-limits.txt Protocol anomalies, parser facts, measures, schema violations and every work limit. - /llms/waf-reference/feature-versions.txt The Clearplane version that introduced each rule-language feature. - /llms/waf-reference/index.txt Reference for writing and reviewing WAF rulesets, for custom rules and Cloud rulesets alike. - /llms/waf-reference/operators.txt Every operator a condition can use to decide a match. - /llms/waf-reference/rule-flow.txt How conditions select, transform and compare fields within one transaction. - /llms/waf-reference/ruleset-format.txt The JSON document, profiles and metadata accepted by the WAF compiler. - /llms/waf-reference/scoring-and-integrity-tests.txt Score attribution, stage thresholds and embedded release checks. - /llms/waf-reference/targets.txt Every request, body, message and response field a WAF rule can inspect. - /llms/waf-reference/tokenizers.txt Grammar classes, fields, contexts and options of every tokenizer detectors use. - /llms/waf-reference/transformations.txt Every transformation a condition can apply before its operator runs.