Credential Injection

Injects per-cluster API credentials into upstream requests and strips client-provided credentials to prevent forwarding

Category: Setup-dependent integration
Task: Injects per-cluster API credentials into upstream requests and strips client-provided credentials to prevent forwarding

Prerequisites: The external service, credentials, or certificates referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/ai:0.4.1 and follow the container quickstart to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Credential Injection
#
# Injects per-cluster API credentials into upstream requests
# and strips client-provided credentials to prevent forwarding.
#
# In this example, requests routed to the "openai" cluster
# receive an Authorization header with a Bearer token, while
# requests to "internal" receive an x-api-key header. Client-
# provided values for these headers are stripped before
# injection (the default behavior).
#
# Credential sources:
#   value:   inline credential (shown below)
#   env_var: read from an environment variable at startup
#
# Example request (from an allowed IP):
#
#   curl http://localhost:8080/v1/chat/completions \
#     -H "Authorization: should-be-stripped"
#
# DANGER: This filter can be dangerous as the user is
# responsible for providing the source discriminator to limit
# which clients can get their requests upgraded to authorized.
#
# In this example an IP ACL restricts access to trusted networks
# before credentials are injected. However, consider this only as
# an example. In production you may need to coordinate source
# discrimination at many levels. A better source discriminator
# than IP ACL is client authentication: make the client authenticate
# and prove that it's allowed to use the backend before upgrading
# the connection.

listeners:
  - name: gateway
    address: "0.0.0.0:8080"
    filter_chains:
      - access-control
      - routing
      - credentials

filter_chains:
  - name: access-control
    filters:
      - filter: ip_acl
        allow:
          - "10.0.0.0/8"
          - "172.16.0.0/12"
          - "192.168.0.0/16"
          - "127.0.0.1/32"

  - name: routing
    filters:
      - filter: router
        routes:
          - path_prefix: "/v1/"
            cluster: openai
          - path_prefix: "/internal/"
            cluster: internal
      - filter: load_balancer
        clusters:
          - name: openai
            endpoints:
              - "127.0.0.1:3000"
          - name: internal
            endpoints:
              - "127.0.0.1:3001"

  - name: credentials
    filters:
      - filter: credential_injection
        clusters:
          - name: openai
            header: Authorization
            value: "sk-example-openai-key"
            header_prefix: "Bearer "
            strip_client_credential: true
          - name: internal
            header: x-api-key
            value: "internal-secret"
            strip_client_credential: true

insecure_options:
  allow_private_endpoints: true # example proxies to local backends