Google’s AX Takes a Port in Every Egress Rule. Nothing Downstream Can Enforce One.
Author(s): Chew Loong Nian – AI ENGINEER
Originally published on Towards AI.
Google's AX Takes a Port in Every Egress Rule. Nothing Downstream Can Enforce One.
Google’s agent orchestrator sets a port on six egress rules in its own repo. I traced all six to a wire format with no port field in it — and the CLI prints them back at you anyway.

The article explains that although AX’s Gateway/HostRule schema includes a port field and both manifests and the CLI show it (e.g., “api.openai.com:443”), the underlying wire protocol to the enforcement layer contains no port information and the destination matcher logic only authorizes by hostname/IP, explicitly rejecting URLs and hostnames that include ports. It walks through a small “port check” script that traces how the wire path reads fields and shows that AX’s reconciliation and CLI formatting are misleading: port values may survive schema parsing and display, but they never reach enforcement. It further highlights ways the “fence” can unintentionally open—such as unresolved gateway names, wildcard short-circuiting, and empty allowlists causing no policy to be sent—and concludes with recommendations: treat Gateway as a hostname allowlist, remove or reserve the port field from manifests/schema, avoid wildcards, validate gateways with the CLI before applying tasks, and ensure GatewayReady/policy application succeeded.
Read the full blog for free on Medium.
Join thousands of data leaders on the AI newsletter. Join over 80,000 subscribers and keep up to date with the latest developments in AI. From research to projects and ideas. If you are building an AI startup, an AI-related product, or a service, we invite you to consider becoming a sponsor.
Published via Towards AI
Towards AI Academy
We Build Enterprise-Grade AI. We'll Teach You to Master It Too.
15 engineers. 100,000+ students. Towards AI Academy teaches what actually survives production.
Start free — no commitment:
→ 6-Day Agentic AI Engineering Email Guide — one practical lesson per day
→ Agents Architecture Cheatsheet — 3 years of architecture decisions in 6 pages
Our courses:
→ AI Engineering Certification — 90+ lessons from project selection to deployed product. The most comprehensive practical LLM course out there.
→ Agent Engineering Course — Hands on with production agent architectures, memory, routing, and eval frameworks — built from real enterprise engagements.
→ AI for Work — Understand, evaluate, and apply AI for complex work tasks.
Note: Article content contains the views of the contributing authors and not Towards AI.