# TLS SNI Routing (TCP Filter)
#
# Routes TLS connections to different upstreams based on the
# Server Name Indication (SNI) hostname in the ClientHello.
# No TLS termination: the proxy passes encrypted bytes through.
#
#   Client -> TLS -> Praxis :443 -> TLS -> upstream (by SNI)
#
# Usage:
#   cargo run -p praxis-proxy -- -c examples/configs/protocols/tls-sni-routing.yaml

insecure_options:
  allow_private_upstreams: true

listeners:
  - name: tls-gateway
    address: "0.0.0.0:8443"
    protocol: tcp
    filter_chains:
      - sni-routing

filter_chains:
  - name: sni-routing
    filters:
      - filter: sni_router
        routes:
          - server_names: [ "api.example.com" ]
            upstream: "127.0.0.1:9001"
          - server_names: [ "*.example.com" ]
            upstream: "127.0.0.1:9002"
        default_upstream: "127.0.0.1:9003"
      - filter: tcp_access_log
