Web Search

Demonstrates the openai_web_search filter configuration

Category: Setup-dependent integration
Task: Demonstrates the openai_web_search filter configuration

Prerequisites: The external service, credentials, or certificates referenced by this configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Web Search Filter
# Requires `--features openai-responses` because these filters are opt-in.
#
# Demonstrates the `openai_web_search` filter configuration. The filter
# validates its configuration (provider, API key, timeouts), binds its
# outbound chain, and constructs a search client at startup, then handles
# model-driven `web_search_call` dispatch in the agentic loop.
#
# Configuration:
#   provider:             Search backend (brave or tavily)
#   api_key:              Provider API key (supports ${ENV_VAR} syntax)
#   default_context_size: How many results to return (low/medium/high)
#   timeout_ms:           Callout timeout in milliseconds
#   outbound_chain:       Named filter chain each provider callout executes
#                         through. Operator-managed cross-cutting filters run
#                         on the callout; the filtered-subrequest executor
#                         enforces destination authority, DNS/SSRF, TLS/SNI,
#                         and Host centrally. Targeting local-sensitive
#                         addresses requires insecure_options.allow_private_upstreams.
#   base_url:             Override the provider API base URL. DNS is pinned and
#                         resolved addresses are gated by the executor's SSRF
#                         policy. The configured api_key is sent only to this
#                         validated origin; redirects are not followed.

listeners:
  - name: ai-gateway
    address: "127.0.0.1:8080"
    filter_chains: [web-search-pipeline]

filter_chains:
  - name: web-search-pipeline
    filters:
      - filter: openai_tool_parse
      - filter: openai_web_search
        provider: brave
        api_key: ${WEB_SEARCH_API_KEY}
        default_context_size: medium
        timeout_ms: 10000
        outbound_chain: web-search-outbound
      - filter: router
        routes:
          - path_prefix: "/"
            cluster: "inference"
      - filter: load_balancer
        clusters:
          - name: "inference"
            endpoints:
              - "127.0.0.1:3001"

  # Outbound chain each web-search provider callout executes through. Cross-cutting
  # filters here (e.g. request_id) run on the callout, while the filtered-subrequest
  # executor enforces destination authority, DNS/SSRF, TLS/SNI, and Host centrally.
  - name: web-search-outbound
    filters:
      - filter: request_id

insecure_options:
  allow_private_endpoints: true # example proxies to local backends