identity_header_guard

Captures request headers matching a configured prefix into filter_metadata and removes them from the upstream request.
On this page

Captures request headers matching a configured prefix into filter_metadata and removes them from the upstream request.

Configuration Notes

A client that sets x-tenant-username: admin directly is indistinguishable from a gateway that set it legitimately unless this filter strips the headers first. Place it early in the pipeline — before any filter that reads identity from request headers.

Configuration

FieldTypeRequiredDescription
prefixstringyesCase-insensitive header name prefix to capture and strip.
metadata_namespacestringnoMetadata namespace for captured headers. Headers are stored as {namespace}.{header_name}.

Example

filter: identity_header_guard
prefix: "x-tenant-"
metadata_namespace: "identity"