provider_route
On this page
Exact provider-local mapping from an authenticated intelligent routing selection to a private backend cluster.
Configuration Notes
The provider listener requires downstream mTLS and must run peer_identity_trust before this filter. The filter consumes the exact x-ai-routing-candidate, x-ai-routing-request-id, and optional x-ai-routing-revision fields, validates candidate/model/path against provider-local configuration, and removes all x-ai-routing-* peer fields before the backend hop. It also removes client-supplied provider attribution fields before writing provider-owned replacements. A valid peer overlay revision is rewritten into the provider-owned namespace for backend telemetry; it is correlation evidence, not an authorization grant.
These names are AI-owned rather than Praxis-reserved because Praxis intentionally strips x-praxis-* headers before upstream requests. Praxis AI startup validation rejects optional/plaintext client certificate modes, a provider chain that does not begin with peer_identity_trust, conditional/fail-open boundary filters, and branch-conditional provider consumers.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
provider_id | string | yes | Provider-owned identifier used for observability and demo attribution. |
model_header | string | no | Header populated by an inference parser with the requested model. |
routes | ProviderRouteConfig[] | yes | Exact provider-local candidate mappings. |
routes[].candidate_id | string | yes | Stable candidate ID selected by the edge intelligent_route. |
routes[].cluster | string | yes | Provider-local backend cluster. |
routes[].credential | CandidateCredential | no | Optional provider-local credential reference for the final API hop. |
routes[].credential.strategy | string | yes | Injection strategy. |
routes[].credential.secretRef | CredentialRef | yes | Secret locator, never secret bytes. |
routes[].credential.secretRef.key | string | yes | Secret data key. |
routes[].credential.secretRef.name | string | yes | Secret name. |
routes[].credential.secretRef.namespace | string | yes | Secret namespace. |
routes[].model | string | yes | Exact model accepted for this candidate. |
routes[].paths | string[] | yes | Exact inference paths accepted for this candidate. |
emit_demo_attribution | bool | no | Add provider gateway and selected-backend response attribution headers. |