# TLS Version Constraint
#
# Restrict accepted TLS versions via `min_version`.
# Use `tls13` to require TLS 1.3 exclusively, rejecting
# TLS 1.2 handshakes. Useful for environments that mandate
# modern cipher suites and forward secrecy (PCI DSS 4.0,
# internal zero-trust networks, API-only services).
#
# Version negotiation:
#
#   Client                          Praxis :8443
#     |                                |
#     |--- ClientHello (TLS 1.2) ----->|
#     |                                | min_version: tls13
#     |<-- handshake_failure ----------|
#     |                                |
#     |--- ClientHello (TLS 1.3) ----->|
#     |                                | min_version: tls13
#     |<-- ServerHello (TLS 1.3) -----|
#     |<===== encrypted session ======>|
#
# Accepted values for min_version:
#   tls12  (default) allows TLS 1.2 and 1.3
#   tls13            allows TLS 1.3 only
#
# Usage:
#   mkcert -install && mkcert localhost 127.0.0.1
#   cargo run -p praxis-proxy -- -c examples/configs/protocols/tls-version-constraint.yaml
#   curl --tlsv1.3 https://localhost:8443/    # succeeds
#   curl --tlsv1.2 https://localhost:8443/    # rejected

listeners:
  - name: tls13-only
    address: "127.0.0.1:8443"
    filter_chains:
      - main
    tls:
      certificates:
        - cert_path: ./localhost+1.pem
          key_path: ./localhost+1-key.pem
      min_version: tls13

filter_chains:
  - name: main
    filters:
      - filter: router
        routes:
          - path_prefix: "/"
            cluster: backend

      - filter: load_balancer
        clusters:
          - name: backend
            endpoints:
              - "127.0.0.1:3000"

insecure_options:
  allow_private_endpoints: true # example proxies to local backends
