Uploaded June 2026 | Updated September 2026, 3 days ago
Are your Kubernetes APIs properly secured? The Kubernetes Gateway API is reshaping traffic routing, but default implementations often lack the deep, container-native security required for enterprise workloads.
In this demo, we show you how to seamlessly bridge the gap between SecOps and Platform Engineering by integrating F5’s enterprise-grade NGINX WAF directly into the F5 NGINX Gateway Fabric data plane. Watch as we block cross-site scripting (XSS) attacks in real-time and use DataGuard to automatically mask sensitive PII (like credit card numbers and SSNs) on outbound responses. All of this is managed through the centralized NGINX One Console and deployed with declarative zero-downtime Kubernetes workflows.
Release blog: https://www.f5.com/company/blog/waf-f...
Docs: https://docs.nginx.com/nginx-gateway-...
0:00 Introduction
0:10 The Security Gap in Modern Kubernetes
0:40 F5 WAF for NGINX Gateway Fabric — Architecture
1:00 Gateway API Integration & WAF Capabilities
1:30 Policy Workflow — NGINX One Console to Gateway Fabric
2:00 Demo: Create WAF Policy in NGINX One Console
2:30 Demo: Kubernetes Setup — Pods, WAF Proxy, WAFPolicy YAML
3:10 Demo: Apply Policy & Verify in Data Plane
3:30 Demo: Normal Traffic — Sensitive Data Exposed
3:50 Demo: XSS Attack — Blocked!
4:20 Demo: DataGuard — Create Policy to Mask PII
4:40 Demo: DataGuard in Action — Credit Card & SSN Masked
4:50 Security Dashboard — Main View
5:10 Security Dashboard — Advanced View & Signatures
5:20 Security Dashboard — Event Logs & Forensic Drilldown
5:50 What We Covered Today
6:06 End
Notes:
- Contributed by: Akash Ananthanarayanan
- Related Article: None
- Project Files: None
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: community.f5.com
➡️ YOUTUBE: youtube.com/devcentral
➡️ LINKEDIN: linkedin.com/showcase/f5-devcentral
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: linkedin.com/in/jrahm | https://x.com/jasonrahm
👋 Buu Lam: linkedin.com/in/buulam | https://x.com/buulam
👋 Chase Abbott: linkedin.com/in/chaseabbott1
Are your Kubernetes APIs properly secured? The Kubernetes Gateway API is reshaping traffic routing, but default implementations often lack the deep, container-native security required for enterprise workloads.
In this demo, we show you how to seamlessly bridge the gap between SecOps and Platform Engineering by integrating F5’s enterprise-grade NGINX WAF directly into the F5 NGINX Gateway Fabric data plane. Watch as we block cross-site scripting (XSS) attacks in real-time and use DataGuard to automatically mask sensitive PII (like credit card numbers and SSNs) on outbound responses. All of this is managed through the centralized NGINX One Console and deployed with declarative zero-downtime Kubernetes workflows.
Release blog: https://www.f5.com/company/blog/waf-f...
Docs: https://docs.nginx.com/nginx-gateway-...
0:00 Introduction
0:10 The Security Gap in Modern Kubernetes
0:40 F5 WAF for NGINX Gateway Fabric — Architecture
1:00 Gateway API Integration & WAF Capabilities
1:30 Policy Workflow — NGINX One Console to Gateway Fabric
2:00 Demo: Create WAF Policy in NGINX One Console
2:30 Demo: Kubernetes Setup — Pods, WAF Proxy, WAFPolicy YAML
3:10 Demo: Apply Policy & Verify in Data Plane
3:30 Demo: Normal Traffic — Sensitive Data Exposed
3:50 Demo: XSS Attack — Blocked!
4:20 Demo: DataGuard — Create Policy to Mask PII
4:40 Demo: DataGuard in Action — Credit Card & SSN Masked
4:50 Security Dashboard — Main View
5:10 Security Dashboard — Advanced View & Signatures
5:20 Security Dashboard — Event Logs & Forensic Drilldown
5:50 What We Covered Today
6:06 End
Notes:
- Contributed by: Akash Ananthanarayanan
- Related Article: None
- Project Files: None
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: community.f5.com
➡️ YOUTUBE: youtube.com/devcentral
➡️ LINKEDIN: linkedin.com/showcase/f5-devcentral
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: linkedin.com/in/jrahm | https://x.com/jasonrahm
👋 Buu Lam: linkedin.com/in/buulam | https://x.com/buulam
👋 Chase Abbott: linkedin.com/in/chaseabbott1



![Agentic Observability: Monitoring AI Traffic with F5 NGINX & OpenTelemetry
AI agents are fundamentally changing infrastructure traffic — and traditional load balancers are flying blind. In this demo, we show how to gain deep, real-time visibility into AI/MCP traffic natively using F5 NGINX and OpenTelemetry — with zero backend code changes.
Using NGINX JavaScript (NJS) at the proxy layer, we parse JSON streams in real time to extract tool names, client identities, and target MCP servers. Combined with OpenTelemetry and the golden signals (latency, throughput, error rates), you get a comprehensive observability layer for agentic AI infrastructure — exportable to any OTel-compatible backend.
🔗 Get the code and try it yourself: [Ihttps://github.com/nginx/nginx-mcp-js/tree/main]
🔗 MCP Blog: [https://blog.nginx.org/blog/introducing-agentic-observability-in-nginx-real-time-mcp-traffic-monitoring]
Timestamps:
0:00 – Introduction & the AI traffic problem
0:22 – Why AI agents are unpredictable (fan-out behavior)
0:46 – Three critical blind spots: delivery, UX, and observability
1:36 – The NGINX solution: native Layer 7 MCP inspection
2:07 – How it works: NJS parsing + OpenTelemetry golden signals
2:51 – Demo walkthrough: installation & NGINX config
3:12 – Extracting MCP metadata and mapping to OTel spans
3:53 – Running the load generator to simulate AI traffic
4:00 – Grafana dashboard overview
4:19 – Troubleshooting: isolating slow tools
4:46 – Identifying rogue AI clients by identity
5:05 – Monitoring backend MCP server health
5:32 – Wrap-up and next steps
Notes:
- Contributed by: Akash Ananthanarayanan
- Related Article: None
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: https://community.f5.com
➡️ YOUTUBE: https://youtube.com/devcentral
➡️ LINKEDIN: https://www.linkedin.com/showcase/f5-devcentral/
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: https://www.linkedin.com/in/jrahm/ | https://x.com/jasonrahm
👋 Buu Lam: https://www.linkedin.com/in/buulam/ | https://x.com/buulam
👋 Aubrey King: https://www.linkedin.com/in/aubreyking | https://x.com/aubreykingf5
👋 Chase Abbott: https://www.linkedin.com/in/chaseabbott1 Agentic Observability: Monitoring AI Traffic with F5 NGINX & OpenTelemetry](https://i.ytimg.com/vi/PydaFJirjj0/mqdefault.jpg)






