Provider Route
This listener requires downstream mTLS. peer_identity_trust authenticates and authorizes the edge gateway before AI-owned x-ai-routing- fields can influence provider-local routing
Category: Setup-dependent integration
Task: This listener requires downstream mTLS. peer_identity_trust authenticates and authorizes the edge gateway before AI-owned x-ai-routing- fields can influence provider-local routing
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
Run it: Use ghcr.io/praxis-proxy/ai:0.5.0 and follow the container quickstart to mount and start the configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
# Provider-side Praxis AI inference pipeline.
#
# This listener requires downstream mTLS. `peer_identity_trust` authenticates
# and authorizes the edge gateway before AI-owned x-ai-routing-* fields can
# influence provider-local routing.
listeners:
- name: provider
address: "0.0.0.0:8443"
filter_chains:
- provider-inference
tls:
certificates:
- cert_path: /etc/praxis/tls/tls.crt
key_path: /etc/praxis/tls/tls.key
client_ca:
ca_path: /etc/praxis/tls/client-ca.crt
client_cert_mode: require
filter_chains:
- name: provider-inference
filters:
# This security filter must remain first, unconditional, and fail closed.
- filter: peer_identity_trust
trusted_peers:
- organization: ai-grid
# Parse the OpenAI-compatible request and promote model to X-Model.
- filter: json_body_field
field: model
header: X-Model
# Exact local policy mapping. This is not another routing engine.
- filter: provider_route
provider_id: site-us-west
model_header: X-Model
emit_demo_attribution: true
routes:
- candidate_id: inference_model/mock-model/site-us-west/provider-us-west
model: mock-model
paths:
- /v1/chat/completions
- /v1/responses
cluster: mock-backend
credential:
strategy: bearer_token
secretRef:
name: openai-provider
namespace: grid-demo
key: token
- candidate_id: inference_model/mock-anthropic-model/site-us-west/provider-us-west
model: mock-anthropic-model
paths:
- /v1/messages
cluster: mock-backend
credential:
strategy: apikey
secretRef:
name: anthropic-provider
namespace: grid-demo
key: api-key
# Provider credentials are mounted as files and resolved at startup.
- filter: credential_inject
credentials:
- strategy: bearer_token
name: openai-provider
namespace: grid-demo
key: token
file: /run/secrets/provider-credentials/openai-provider/token
# strategy: apikey injects the raw token into `header` (default x-api-key).
- strategy: apikey
name: anthropic-provider
namespace: grid-demo
key: api-key
file: /run/secrets/provider-credentials/anthropic-provider/api-key
- filter: load_balancer
clusters:
- name: mock-backend
endpoints:
- "mock-backend.grid-demo.svc.cluster.local:8080"
admin:
address: "127.0.0.1:9901"
insecure_options:
allow_private_endpoints: true # example proxies to local backends
shutdown_timeout_secs: 5