# How we built the Traffic Policy module and its actions

DevFeed: [How we built the Traffic Policy module and its actions](<https://devfeed.tech/articles/how-we-built-the-traffic-policy-module-and-its-actions-83224.md>)

Original publisher: [Read original article](<https://ngrok.com/blog/engineering-traffic-policy>)

Author: Rachel Kolavo

Published: 2024-10-23T00:00:00Z

Content type: article

Language: en

Sources: [\[ngrok news\]](<https://devfeed.tech/sources/ngrok-news.md>)

Topics: [API Governance](<https://devfeed.tech/topics/api-governance.md>), [Load Balancing](<https://devfeed.tech/topics/load-balancing.md>), [rate-limiting](<https://devfeed.tech/topics/rate-limiting.md>), [observability](<https://devfeed.tech/topics/observability.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-gateway](<https://devfeed.tech/tags/api-gateway.md>), [cel](<https://devfeed.tech/tags/cel.md>), [client](<https://devfeed.tech/tags/client.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [traffic-policy](<https://devfeed.tech/tags/traffic-policy.md>)

## AI overview

The article explains how ngrok built Traffic Policy to replace scattered middleware configuration with conditional rules written in Common Expression Language (CEL). It describes request lifecycle phases, chained handlers, and an optimization that tracks only variables used by each expression to reduce evaluation work. Traffic Policy supports actions such as IP restrictions, JWT validation, rate limiting, URL rewriting, redirects, and logging.

## Source excerpt

Traffic Policy is now the one true (and final!) way to shape your requests and responses. Let's explore why we built it, how, and what it means for you.