Summary

This regex generator turns a list of hosts, paths, versions, email domains or HTTP status codes into an escaped pattern for rollout targeting rules, Prometheus matchers and log filters. You choose between search match (JavaScript, Go, grep) and full match (Prometheus, Alertmanager, Envoy) semantics, then test lines in the browser. Nothing leaves your machine.

Free tool

Regex generator for rollout targeting and log filters

Paste the hosts, paths, versions or status codes you want to match. Get an escaped pattern for your regex engine, then check it against real lines before it reaches production.

Laptop at night showing filtered terminal output on a developer desk

Generate a regex from a list of values

Choose what you are matching, list the values, and pick the engine. The pattern and the test results update as you type.

Generated pattern

    How it works

    What the generator does with your values

    Escapes every literal

    Dots, slashes, brackets and pluses in your values are escaped, so api.internal.example.com cannot match api-internal-example-com. Hand-written allowlists fail here more than anywhere else.

    Writes for the engine you run

    Search engines need ^ and $ to pin a match. Prometheus, Alertmanager and Envoy match the whole string and need .* for prefix and suffix rules. You choose the engine, the generator adapts the pattern.

    Tests before you ship

    Every test line gets a match or no match badge using the pattern you are about to copy. Add the near misses on purpose: checkout-v22 next to checkout-v2, example.com.evil.io next to example.com.

    Where patterns fail

    The regex that passed review and still paged someone

    Most regex incidents in rollout and alerting config are not exotic. A targeting rule that was meant to cover three internal hosts also covered a lookalike. An alert matcher written with anchors Prometheus does not need quietly dropped a service. A log filter matched on a substring and hid the errors it was meant to count. The pattern is rarely too clever. It is almost always too loose, or it was tested only on lines that were supposed to match. A rule that gates a rollout should be tested on the lines that must not match first.

    • Escape the dots in every hostname
    • Know whether your engine anchors for you
    • Test the near misses, not only the hits
    • Prefer a literal list over a regex when the set is small and stable
    Aisle of server racks with green status lights
    Usage

    From a list of values to a pattern you trust

    1. 1

      Pick the match type

      Exact values for host and flag key allowlists, prefix for route groups, status codes for alert rules, version families for rollout targeting by app version.

    2. 2

      Pick the engine

      Use search match for code and grep. Use full match for Prometheus matchers, Alertmanager routes and Envoy. This one choice removes the most common anchoring mistake.

    3. 3

      Paste near misses into the test box

      Add a lookalike host, a neighbouring version and a status code just outside the range. If any of them shows match, tighten the values before you copy the pattern.

    Common questions

    Is this regex generator free, and does it send my values anywhere?
    It is free and runs entirely in your browser. The values you type, the pattern and your test lines are never sent to a server. The only request is an anonymous counter that records that the tool was used.
    Which regex engine does the output target?
    Two behaviours cover most infrastructure work. Search match fits JavaScript, Go regexp, grep -E and PCRE, where a pattern can match anywhere in the line, so the tool adds ^ and $ when you need them. Full match fits Prometheus, Alertmanager and Envoy, which treat the whole string as the match, so the tool adds .* where you want a prefix, suffix or contains rule.
    Why does Prometheus ignore my ^ and $ anchors?
    Prometheus label matchers are fully anchored. The expression env=~"prod" is evaluated as ^(?:prod)$, so a pattern written for grep will silently match less than you expect, or nothing. Choose the full match engine and the generator writes the pattern the way Prometheus reads it.
    Does the pattern avoid catastrophic backtracking?
    The generated patterns use only literals, bounded character classes and flat alternations. They contain no nested quantifiers, which is the usual source of runaway backtracking in JavaScript and PCRE. RE2-based engines such as Go and Envoy run in linear time regardless.
    How are special characters handled?
    Every literal value is escaped. A host like api.internal.example.com becomes api\.internal\.example\.com, so the dot no longer matches any character. This is the most common bug in hand-written allowlists, and it lets api-internal-example-com through.
    Can I use the pattern in a feature flag targeting rule?
    Yes, as long as your flag platform supports a regex or matches-pattern operator on a context attribute such as hostname, path or user email. Check which engine it uses before you paste. If it only offers exact match or starts-with operators, a list of literal values is safer than a regex.
    What does it not do?
    It does not infer a pattern from examples and it does not generate numeric ranges or lookaheads. It builds a pattern from a list of values you give it, using rules you can read. Test lines are evaluated with the JavaScript engine, so confirm engine-specific behaviour in your own stack before you ship.

    Gate the rollout on the SLO, not on a hunch

    Targeting rules decide who gets a change. upstreamapi's AI Pilot decides whether it keeps going, and reverts on its own when the error rate crosses your SLO threshold.