Praxis v0.7.2 capabilities and support

What the selected Praxis release supports, gates behind build features, or does not implement.

On this page

This page describes the Praxis v0.7.2 default release, pinned to commit 1de023cba3fee967f828c9ff35f27596f8f6792c. A custom build can omit defaults or add experimental features; check its build and configuration before relying on a capability.

Protocols

Capabilityv0.7.2 statusNotes
HTTP reverse proxyingSupportedHTTP/1 and HTTP/2 are handled through the selected Pingora adapter. SSE and gRPC workloads pass through the HTTP proxy; the grpc_detection filter classifies content types for pipeline conditions.
TCP forwardingSupportedTCP listeners forward opaque streams and can use TCP filters. TCP forwarding uses a separate listener mode. Praxis v0.7.2 does not implement HTTP CONNECT tunneling.
WebSocket upgradesSupportedThe HTTP proxy preserves validated WebSocket upgrade responses. WebSocket frames pass through without message-aware filtering.
HTTP/3 / QUICNot implementedThe v0.7.2 architecture describes the adapter as planned.
HTTP CONNECT tunnelNot implementedThe open CONNECT design issue says the current reverse proxy rejects CONNECT. Use a purpose-built forward proxy if clients require HTTP_PROXY or HTTPS_PROXY tunneling.

Configurable operations

CapabilityDefault-build statusEnabled by default?
YAML listeners, routing, and load balancingSupportedThe server can start with a built-in local status response; upstream routing needs a router, a load balancer, and configured clusters.
Downstream TLS and upstream TLSSupportedConfigure certificates and TLS settings per listener or cluster. Upstream certificate verification is enabled by default; HTTPS is not implicitly enabled on every listener.
TCP TLS and client-certificate checksSupportedConfigure a TCP/HTTP TLS listener and the relevant certificate or peer-identity settings. SPIFFE-specific identity support requires the spiffe feature.
CORS, rate limiting, ACL, CSRF, and guardrailsSupported filtersNo. Add the needed filters to the configured chain; the default config does not apply these policies.
Endpoint health checks and admin health endpointsSupportedThe default build includes admin-api; configure admin.address and health checks as needed. The default config binds admin to loopback.
Config-file reloadSupportedconfig-reload is enabled in the default build. Some changes, including listener topology and protocol type, need a restart.
OpenTelemetry tracingBuild-feature dependentOff by default; compile with otel and configure an exporter.
Iterative request routing and SPIFFE peer identityExperimental build featuresOff by default. Enabling experimental features produces a startup warning; do not assume they are part of the standard binary.

Use the complete build-feature reference (Praxis v0.7.2) and the filter reference (Praxis v0.7.2) for exact fields and feature gates. The operator guides link to TLS, health, security, metrics, and reload instructions.

Project status, compatibility, and license

Praxis v0.7.2 is pre-v1. Its security policy says all 0.x releases are unsupported for security updates. The workspace uses the Rust lint unsafe_code = "deny", with narrow explicitly expected SIMD intrinsics; that lint does not describe third-party dependencies or certify the binary.

Praxis v0.7.2 depends on Praxis Policy Engine crate v0.3.1. Praxis AI v0.4.1 independently depends on Praxis crates v0.7.0. The documentation catalog’s Policy default is v0.4.0. These independent docs releases are not a tested compatibility matrix; use the dependency versions in the relevant manifests and test the exact builds you combine.

Praxis is licensed under Apache-2.0. Building the v0.7.2 source requires Rust 1.96.0; see the installation guide if you need to build it.