provider_route

Exact provider-local mapping from an authenticated intelligent routing selection to a private backend cluster.
On this page

Exact provider-local mapping from an authenticated intelligent routing selection to a private backend cluster.

Configuration Notes

The provider listener requires downstream mTLS and must run peer_identity_trust before this filter. The filter consumes the exact x-ai-routing-candidate, x-ai-routing-request-id, and optional x-ai-routing-revision fields, validates candidate/model/path against provider-local configuration, and removes all x-ai-routing-* peer fields before the backend hop. It also removes client-supplied provider attribution fields before writing provider-owned replacements. A valid peer overlay revision is rewritten into the provider-owned namespace for backend telemetry; it is correlation evidence, not an authorization grant.

These names are AI-owned rather than Praxis-reserved because Praxis intentionally strips x-praxis-* headers before upstream requests. Praxis AI startup validation rejects optional/plaintext client certificate modes, a provider chain that does not begin with peer_identity_trust, conditional/fail-open boundary filters, and branch-conditional provider consumers.

Configuration

FieldTypeRequiredDescription
provider_idstringyesProvider-owned identifier used for observability and demo attribution.
model_headerstringnoHeader populated by an inference parser with the requested model.
routesProviderRouteConfig[]yesExact provider-local candidate mappings.
routes[].candidate_idstringyesStable candidate ID selected by the edge intelligent_route.
routes[].clusterstringyesProvider-local backend cluster.
routes[].credentialCandidateCredentialnoOptional provider-local credential reference for the final API hop.
routes[].credential.strategystringyesInjection strategy.
routes[].credential.secretRefCredentialRefyesSecret locator, never secret bytes.
routes[].credential.secretRef.keystringyesSecret data key.
routes[].credential.secretRef.namestringyesSecret name.
routes[].credential.secretRef.namespacestringyesSecret namespace.
routes[].modelstringyesExact model accepted for this candidate.
routes[].pathsstring[]yesExact inference paths accepted for this candidate.
emit_demo_attributionboolnoAdd provider gateway and selected-backend response attribution headers.