Overview
Bifrost Enterprise supports A10 Guardrails as a third-party guardrail provider for LLM requests and responses. A10 owns the policies and their decisions. Configure the rules on your A10 Guardrails firewall, then attach the A10 profile to a Bifrost rule to choose which traffic is evaluated. Bifrost sends the selected text to the firewall and enforces the result inline:- Allow: Bifrost continues the request or response unchanged. A10
FLAGresults are recorded but do not block. - Block: Bifrost returns a guardrail intervention and does not continue that phase.
- Rewrite: A10 returns transformed text, for example after redacting a value. Bifrost replaces the matching request or response text with A10’s version.
A10 is a provider-managed transformation: the firewall returns already-rewritten text, and Bifrost applies it. The A10 profile does not expose Bifrost
action, redaction_strategy, or redaction_mode settings. See Bifrost-Managed vs Provider-Managed Rewrites.Prerequisites
- Bifrost Enterprise with guardrails enabled
- A reachable A10 Guardrails firewall deployment and its base URL
- An A10 client ID for that firewall
- Input and/or output guardrails configured on the firewall
- Network egress from Bifrost to the firewall
How It Works
- Create a Bifrost provider configuration with
provider_name: "a10". - Attach it to a guardrail rule that applies to
input,output, orboth. - Bifrost sends a
POSTrequest to<base_url>/v1/validateParsedTextwith the client ID in thex-eag-clientidheader. Bifrost also sets direction headers so the firewall applies its input or output guardrails. - A10 evaluates its rules and returns an overall action, per-rule results, and any transformed text.
- Bifrost maps that result to the request or response path.
system, developer, user, assistant, and tool are sent as user.
Output evaluation sends an OpenAI-compatible chat.completion object, with each response text segment as a separate assistant choice.
Decision Mapping
Bifrost records up to eight A10 rule names and actions with the guardrail result. Screened content is not included in that summary.
Configuration Fields
Configure Bifrost
- Web UI
- API
- config.json
- Helm
- Go to Guardrails > Providers.
- Select A10 Guardrails and click Add Configuration.
- Enter a descriptive Name.
- Enter the Firewall base URL and Client ID.
- Set the timeout, click Verify, enable the configuration, then save it.
- Under Guardrails > Rules, attach the saved A10 profile to an input, output, or both-phase rule.
The configuration must be verified before it can be enabled. Changing any field other than Enabled requires verifying again.

Supported Content and Limitations
- LLM input and output: A10 evaluates text-bearing request and response content. Each text segment is evaluated and rewritten in place.
- Tool calls: LLM tool-call arguments are sent to A10 as text segments and can be blocked or rewritten.
- Single rewrite owner: A10 rewrites cannot be combined with Bifrost-managed redaction or another provider’s transformed output in the same request or response phase. Bifrost fails closed in that case.
- Errors: Non-2xx responses, timeouts, and unparseable A10 responses are treated as provider errors.
- Images and files: This integration sends text content, not image pixels, file bytes, or arbitrary binary payloads.

