Browse documentation ↓
09 / CURRENT BOUNDARIES

Current limits

PragmaChange v1 is useful when its inputs match the behavior you want to measure. These boundaries matter when deciding where to use it.

What v1 observes

The native runtime inspects configured request fields before forwarding to your API. It can compute counts, rates, numeric aggregates, exact distinct counts, current values, body size, and gaps between request arrivals over bounded windows. It evaluates one trained forest for each matching endpoint selected in the release.

Native Nginx boundaries

  • No automatic production training capture. You import request events or feature vectors yourself.
  • No response visibility. It cannot measure the current backend's execution time, response status, or outcome because it runs before the upstream request.
  • No native business workflow state. The Nginx runtime does not track named actions or confirmed outcomes. The separate behavior service accepts application events and supplies sequence models and explicit prerequisite rules.
  • No challenge service. check forwards to your backend; you implement the verification behavior.
  • No shared history across proxy hosts. Workers share state inside one Nginx instance only.
  • Operator-controlled deployments. Servers provides reviewed serial rollouts and timestamped verification of loaded releases. That status is not continuous monitoring; uncertain or failed predecessors stop a rollout.
  • No measured attack detection accuracy. An unlabeled holdout and percentile threshold suggestions cannot establish it.

The management portal supports one administrator and bounded imports. Assisted setup can propose validated configurations after explicit provider setup. Endpoint source artifacts retain a manual retention policy; behavior events have configured retention, while snapshots/models remain until explicit purge.

Application-side boundaries

Reference clients are examples to adapt, not a required or published SDK product. Streaming is best effort; inspect dropped counters. Recorders require explicit finalization and support one bounded file per recording, without automatic rotation or crash recovery.

Behavior models start in shadow mode. They depend on trustworthy identities, meaningful action boundaries, and representative workflows. Sequence anomaly recommendations and measured holdout flag rates do not establish attack detection accuracy.

Match the problem to the tool

Use application rules for known invalid actions and workflow steps. Use normal authentication and rate limiting alongside PragmaChange. The anomaly model can add a signal about unusual request-derived behavior; it cannot prove a request is malicious.

The reference runtime prioritizes consistent bounded state over an unmeasured throughput claim. Benchmark your actual feature set and Nginx workload before setting a production capacity target.