Step 1: Select Bot Traffic Scenario
Choose a bot identity to send signed HTTP requests to the Google Cloud Load Balancer
Authentic search/crawler bot with valid Ed25519 signature & trusted JWKS key.
Rogue scraper spoofing official Googlebot User-Agent with invalid cryptographic signature.
Previously captured signature packet replayed past the HTTP Message Signatures validity window.
Standard automated HTTP bot request missing required Web Bot Auth headers.
Step 2: Edge Processing Stages
Watch Google Cloud Service Extensions intercept, fetch JWKS, and verify signatures
Step 3: Verifications and Results
Inspect edge decision (200 OK vs 403 Access Denied), Load Balancer Latency, and mutated HTTP headers
// HTTP Response Body from Google Cloud Load Balancer / Backend
// HTTP Message Signatures Section 2.5 Signature Base Target String will appear here after execution
| Header Name | Mutated Value injected by Service Extension |
|---|---|
| No request executed yet | |