<data_dir>/apis/<sandbox>.rules.json, one versioned file per sandbox, written atomically. The sandbox loads them with the spec, and a rule that cannot be true of this spec is refused at load, by name.
pikopod up serving examplepay, the first create with reference: order-77 is answered from the spec and the second by the rule:
x-pikopod-rule with the rule’s id.
When a rule is consulted
For every request, in this order: auth, faults, route, rules, operation. A rule is only consulted once the request is authenticated, no armed fault answered, and the route matched a declared operation. The first matching rule in file order wins, and the operation behind it never runs. A rule cannot fire on a route the spec does not declare.when
Body matchers:
State conditions read the
state a resource carries in the store, which a rule’s set_state sets:
respond
provenance is manual for a rule you wrote, promoted:<fingerprint> for one promoted from an observed divergence, and imported:<fingerprint> for one that arrived in an incident bundle. version is stamped when the rule is first saved, and the file’s version advances on every save.
Seeing which rule fired
requests --explain replays a request against a fork and names the rule:
reference-required, with "body": { "reference": "absent" }. The fork starts from an empty store, so a rule that depends on stored state, such as exists_in_store, only fires against the served sandbox.