Project State Owner Headers
Demonstrates the production boundary used when an external authenticator injects separate tenant and subject headers. state_owner consumes those assertions into an immutable internal owner and strips the inbound copies. project_state_owner_headers then recreates destination-specific headers from that normalized context
Category: Setup-dependent integration
Task: Demonstrates the production boundary used when an external authenticator injects separate tenant and subject headers. state_owner consumes those assertions into an immutable internal owner and strips the inbound copies. project_state_owner_headers then recreates destination-specific headers from that normalized context
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
Run it: Use ghcr.io/praxis-proxy/ai:0.5.0 and follow the container quickstart to mount and start the configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
# Project Trusted State Owner Headers
#
# Demonstrates the production boundary used when an external authenticator
# injects separate tenant and subject headers. `state_owner` consumes those
# assertions into an immutable internal owner and strips the inbound copies.
# `project_state_owner_headers` then recreates destination-specific headers
# from that normalized context. Place the projection only in a chain whose
# upstream is authorized to receive identity (for example, an OGX
# upstream-header endpoint).
#
listeners:
- name: gateway
address: "127.0.0.1:8080"
filter_chains:
- ogx-identity
filter_chains:
- name: ogx-identity
filters:
- filter: state_owner
mode: trusted_headers
tenant:
header: x-auth-tenant
issuer:
static: urn:example:authorino
subject:
header: x-auth-user
# OGX upstream_header authentication reads these names when configured
# with principal_header: x-user-id and tenant_header: x-tenant-id.
- filter: project_state_owner_headers
tenant_header: x-tenant-id
subject_header: x-user-id
- filter: router
routes:
- path_prefix: "/"
cluster: ogx
- filter: load_balancer
clusters:
- name: ogx
endpoints:
- "127.0.0.1:3000"
insecure_options:
allow_private_endpoints: true # example proxies to a local OGX-compatible backend