credential_inject
Replaces caller credentials with the upstream credential selected by intelligent_route or provider_route.
On this page
Replaces caller credentials with the upstream credential selected by intelligent_route or provider_route.
Configuration Notes
Reads intelligent_route.credential.* filter metadata written by the preceding routing filter, looks up the configured token, removes caller authorization, and sets exactly one provider credential header (a bearer Authorization value, or the raw token in the configured header for apikey). Token values are never written to metadata, traces, or error bodies. See the module documentation for the complete data flow and configuration.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
credentials | CredentialEntryConfig[] | yes | Credential entries, keyed by secretRef (name/namespace/key). |
credentials[].name | string | yes | Kubernetes Secret name — must match intelligent_route.credential.name. |
credentials[].namespace | string | yes | Kubernetes Secret namespace — must match intelligent_route.credential.namespace. |
credentials[].key | string | yes | Key within Secret.data — must match intelligent_route.credential.key. |
credentials[].strategy | string | no | Credential strategy. Supports "bearer_token" (injects Authorization: Bearer <token>) and "apikey" (injects the raw token into header). |
credentials[].header | string | no | Injection header for strategy: apikey. Defaults to x-api-key. Mutually exclusive with strategy: bearer_token, which always injects Authorization. Reserved internal header prefixes (x-praxis-, x-mcp-), transport-controlled names (host, content-length, hop-by-hop, proxy-authorization), and authorization itself are rejected: the Praxis upstream boundary would strip the injected credential in flight, and transport-controlled targets would corrupt framing or leak the credential to an intermediary. |
credentials[].value | string | no | Inline token value. Mutually exclusive with env_var and file. |
credentials[].env_var | string | no | Environment variable holding the token. Mutually exclusive with value and file. |
credentials[].file | string | no | Path to a file containing the token. The initial value is validated at filter construction. A watcher revalidates the file after atomic projected-volume changes so Secret rotation does not require a restart. The file contents are trimmed of leading/trailing whitespace before use. The file must exist, be readable, and be non-empty; construction fails otherwise. Use this source when the token is mounted from a Kubernetes Secret volume so that token bytes never appear in Praxis ConfigMaps. Mutually exclusive with value and env_var. |
Example
filter: credential_inject
credentials:
- name: my-api-secret # matches intelligent_route.credential.name
namespace: grid-system # matches intelligent_route.credential.namespace
key: token # matches intelligent_route.credential.key
strategy: bearer_token # optional, defaults to bearer_token
file: /run/secrets/grid-credentials/my-api-secret/token
- name: other-secret
namespace: default
key: api-key
strategy: apikey # raw token in a header instead of Authorization
header: x-api-key # optional, defaults to x-api-key
env_var: OTHER_API_TOKEN # token from environment variable