Summary
This regex generator turns a list of hosts, paths, versions, email domains or HTTP status codes into an escaped pattern for rollout targeting rules, Prometheus matchers and log filters. You choose between search match (JavaScript, Go, grep) and full match (Prometheus, Alertmanager, Envoy) semantics, then test lines in the browser. Nothing leaves your machine.
Regex generator for rollout targeting and log filters
Paste the hosts, paths, versions or status codes you want to match. Get an escaped pattern for your regex engine, then check it against real lines before it reaches production.

What the generator does with your values
Escapes every literal
Dots, slashes, brackets and pluses in your values are escaped, so api.internal.example.com cannot match api-internal-example-com. Hand-written allowlists fail here more than anywhere else.
Writes for the engine you run
Search engines need ^ and $ to pin a match. Prometheus, Alertmanager and Envoy match the whole string and need .* for prefix and suffix rules. You choose the engine, the generator adapts the pattern.
Tests before you ship
Every test line gets a match or no match badge using the pattern you are about to copy. Add the near misses on purpose: checkout-v22 next to checkout-v2, example.com.evil.io next to example.com.
The regex that passed review and still paged someone
Most regex incidents in rollout and alerting config are not exotic. A targeting rule that was meant to cover three internal hosts also covered a lookalike. An alert matcher written with anchors Prometheus does not need quietly dropped a service. A log filter matched on a substring and hid the errors it was meant to count. The pattern is rarely too clever. It is almost always too loose, or it was tested only on lines that were supposed to match. A rule that gates a rollout should be tested on the lines that must not match first.
- Escape the dots in every hostname
- Know whether your engine anchors for you
- Test the near misses, not only the hits
- Prefer a literal list over a regex when the set is small and stable
From a list of values to a pattern you trust
-
1
Pick the match type
Exact values for host and flag key allowlists, prefix for route groups, status codes for alert rules, version families for rollout targeting by app version.
-
2
Pick the engine
Use search match for code and grep. Use full match for Prometheus matchers, Alertmanager routes and Envoy. This one choice removes the most common anchoring mistake.
-
3
Paste near misses into the test box
Add a lookalike host, a neighbouring version and a status code just outside the range. If any of them shows match, tighten the values before you copy the pattern.
Common questions
Is this regex generator free, and does it send my values anywhere?
Which regex engine does the output target?
Why does Prometheus ignore my ^ and $ anchors?
Does the pattern avoid catastrophic backtracking?
How are special characters handled?
Can I use the pattern in a feature flag targeting rule?
What does it not do?
Gate the rollout on the SLO, not on a hunch
Targeting rules decide who gets a change. upstreamapi's AI Pilot decides whether it keeps going, and reverts on its own when the error rate crosses your SLO threshold.