Project State Owner Headers

Demonstrates the production boundary used when an external authenticator injects separate tenant and subject headers. state_owner consumes those assertions into an immutable internal owner and strips the inbound copies. project_state_owner_headers then recreates destination-specific headers from that normalized context

Category: Setup-dependent integration
Task: Demonstrates the production boundary used when an external authenticator injects separate tenant and subject headers. state_owner consumes those assertions into an immutable internal owner and strips the inbound copies. project_state_owner_headers then recreates destination-specific headers from that normalized context

Prerequisites: The external service, credentials, or certificates referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/ai:0.5.0 and follow the container quickstart to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Project Trusted State Owner Headers
#
# Demonstrates the production boundary used when an external authenticator
# injects separate tenant and subject headers. `state_owner` consumes those
# assertions into an immutable internal owner and strips the inbound copies.
# `project_state_owner_headers` then recreates destination-specific headers
# from that normalized context. Place the projection only in a chain whose
# upstream is authorized to receive identity (for example, an OGX
# upstream-header endpoint).
#
listeners:
  - name: gateway
    address: "127.0.0.1:8080"
    filter_chains:
      - ogx-identity

filter_chains:
  - name: ogx-identity
    filters:
      - filter: state_owner
        mode: trusted_headers
        tenant:
          header: x-auth-tenant
        issuer:
          static: urn:example:authorino
        subject:
          header: x-auth-user

      # OGX upstream_header authentication reads these names when configured
      # with principal_header: x-user-id and tenant_header: x-tenant-id.
      - filter: project_state_owner_headers
        tenant_header: x-tenant-id
        subject_header: x-user-id

      - filter: router
        routes:
          - path_prefix: "/"
            cluster: ogx
      - filter: load_balancer
        clusters:
          - name: ogx
            endpoints:
              - "127.0.0.1:3000"

insecure_options:
  allow_private_endpoints: true # example proxies to a local OGX-compatible backend