Gcp Adc
Acquires an OAuth2 access token from the GCE/GKE metadata server (source: adc or metadata) and injects “Authorization: Bearer " on every proxied request to Vertex AI
Category: Setup-dependent integration
Task: Acquires an OAuth2 access token from the GCE/GKE metadata server (source: adc or metadata) and injects “Authorization: Bearer " on every proxied request to Vertex AI
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
# GCP ADC upstream authentication (experimental)
#
# Acquires an OAuth2 access token from the GCE/GKE metadata server
# (source: adc or metadata) and injects "Authorization: Bearer
# <token>" on every proxied request to Vertex AI. The token is
# cached in memory (cache-through: a request that finds the cache
# stale fetches a fresh token inline before proceeding); the
# downstream client never sees GCP credentials.
#
# source: key_file (a service-account key JSON file) is not
# implemented yet -- it needs JWT signing -- and fails closed with
# a clear "not implemented" reason.
#
# This filter only injects Authorization — it does NOT set Host
# or path. Point the cluster at your Vertex regional endpoint
# (and tls.sni) the same way as any other upstream.
#
# Experimental: rebuild with --features gcp-adc-filter.
# Configuration may change before graduation.
#
# Usage:
# cargo run -p praxis-ai-proxy --features gcp-adc-filter -- \
# -c examples/configs/gcp-adc.yaml
listeners:
- name: gateway
address: "0.0.0.0:8080"
filter_chains:
- vertex
filter_chains:
- name: vertex
filters:
- filter: router
routes:
- path_prefix: "/"
cluster: vertex
- filter: load_balancer
clusters:
- name: vertex
endpoints:
- "127.0.0.1:3000"
- filter: gcp_adc
# source: adc # default: GOOGLE_APPLICATION_CREDENTIALS, else GKE metadata
# scope: https://www.googleapis.com/auth/cloud-platform
# Metadata authentication uses only the fixed metadata endpoint;
# redirects and ambient HTTP proxies are disabled.
insecure_options:
allow_private_endpoints: true # example proxies to a local backend