Web Search
Demonstrates the openai_web_search filter configuration
Category: Setup-dependent integration
Task: Demonstrates the openai_web_search filter configuration
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
# Web Search Filter
# Requires `--features openai-responses` because these filters are opt-in.
#
# Demonstrates the `openai_web_search` filter configuration. The filter
# validates its configuration (provider, API key, timeouts), binds its
# outbound chain, and constructs a search client at startup, then handles
# model-driven `web_search_call` dispatch in the agentic loop.
#
# Configuration:
# provider: Search backend (brave or tavily)
# api_key: Provider API key (supports ${ENV_VAR} syntax)
# default_context_size: How many results to return (low/medium/high)
# timeout_ms: Callout timeout in milliseconds
# outbound_chain: Named filter chain each provider callout executes
# through. Operator-managed cross-cutting filters run
# on the callout; the filtered-subrequest executor
# enforces destination authority, DNS/SSRF, TLS/SNI,
# and Host centrally. Targeting local-sensitive
# addresses requires insecure_options.allow_private_upstreams.
# base_url: Override the provider API base URL. DNS is pinned and
# resolved addresses are gated by the executor's SSRF
# policy. The configured api_key is sent only to this
# validated origin; redirects are not followed.
listeners:
- name: ai-gateway
address: "127.0.0.1:8080"
filter_chains: [web-search-pipeline]
filter_chains:
- name: web-search-pipeline
filters:
- filter: openai_tool_parse
- filter: openai_web_search
provider: brave
api_key: ${WEB_SEARCH_API_KEY}
default_context_size: medium
timeout_ms: 10000
outbound_chain: web-search-outbound
- filter: router
routes:
- path_prefix: "/"
cluster: "inference"
- filter: load_balancer
clusters:
- name: "inference"
endpoints:
- "127.0.0.1:3001"
# Outbound chain each web-search provider callout executes through. Cross-cutting
# filters here (e.g. request_id) run on the callout, while the filtered-subrequest
# executor enforces destination authority, DNS/SSRF, TLS/SNI, and Host centrally.
- name: web-search-outbound
filters:
- filter: request_id
insecure_options:
allow_private_endpoints: true # example proxies to local backends