openai_response_store
Persists Responses API responses to the configured response store backend.
On this page
Persists Responses API responses to the configured response store backend.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
backend | sqlite | postgres | yes | Storage backend to use. |
database_url | string (secret) | yes | Database connection URL. Wrapped in [SecretString] to prevent accidental logging of credentials. |
responses_table | string | yes | Table name for response records. |
conversations_table | string | yes | Table name for conversation message records. |
ssl_mode | SslMode | no | TLS mode for PostgreSQL connections. Only valid when backend is postgres. Overrides any sslmode parameter in the connection URL. |
ssl_root_cert | string (secret) | no | Path to a PEM-encoded root CA certificate for PostgreSQL TLS verification. Only valid when backend is postgres and the effective SSL mode is verify-ca or verify-full. |
ssl_client_cert | string (secret) | no | Path to a PEM-encoded client certificate for mutual TLS with PostgreSQL. Only valid when backend is postgres and the effective SSL mode is verify-ca or verify-full. Must be configured together with ssl_client_key. Enables certificate authentication so the server does not challenge for a password. |
ssl_client_key | string (secret) | no | Path to the PEM-encoded private key for ssl_client_cert. Only valid when backend is postgres. Must be an unencrypted PKCS#8 key (mode 0600) and configured together with ssl_client_cert. The native-tls backend (OpenSSL on Linux, Security.framework on macOS) accepts PKCS#8 only; convert a SEC1/PKCS#1 key with openssl pkcs8 -topk8 -nocrypt. |
require_certificate_authentication | bool | no | Enforce the certificate-authentication compliance profile for PostgreSQL. When enabled, the filter fails to start unless ssl_mode is verify-full, both ssl_client_cert and ssl_client_key are set, and no password reaches the connection (rejecting a password in database_url, TLS parameters in database_url, and the PGPASSWORD environment variable). It also rejects non-addressing connection parameters in database_url (application_name, options/options[...], statement-cache-capacity), which the certificate-authentication rebuild would silently drop; set such defaults on the database role instead (ALTER ROLE ... SET ...). The ssl_client_key file must also be owner-only (mode 0600, enforced on Unix). This keeps application-side password cryptography off the connection path. The PostgreSQL server must independently use a cert rule in pg_hba.conf; the proxy cannot enforce that server-side requirement. |
allow_private_database_url | bool | no | Allow PostgreSQL URLs that target local-sensitive addresses. By default, DNS names, localhost, loopback, private, link-local, cloud metadata, unspecified, and Unix socket targets are rejected. This opt-in is intended for local development and tests. |
pool | PoolConfig | no | Connection pool tuning options. When omitted, sqlx defaults apply (max_connections = 10, idle_timeout = 600s, acquire_timeout = 30s). |
compression | StoreCompressionConfig | no | Optional payload compression for stored JSON columns. When omitted, payloads are stored uncompressed. Reads auto-detect the format, so enabling compression keeps existing uncompressed records readable. |
Example
filter: openai_response_store
backend: postgres
database_url: postgres://praxis:[email protected]/praxis
responses_table: openai_responses
conversations_table: openai_conversation_messages
allow_private_database_url: true