# Identity assertions at the wire boundary
#
# Projects policy-derived identity into request headers and removes credentials
# that should not reach the upstream.
#
# Response assertions must be reachable from `global:`,
# `global.defaults.http:`, or an `http:` route because they run while response
# headers are still writable.
#
# These headers are unsigned and require a trusted proxy-to-upstream boundary.
# Client values under asserted names are replaced rather than forwarded.
#
# Usage:
#   cargo run -p praxis-proxy -- -c examples/configs/security/policy-assertions.yaml

listeners:
  - name: default
    address: "127.0.0.1:8080"
    filter_chains:
      - main

filter_chains:
  - name: main
    filters:
      # A global HTTP policy needs no protocol classifier.
      - filter: policy
        config_path: /etc/praxis/assertions-policy.yaml

      - filter: router
        routes:
          - path_prefix: "/"
            cluster: backend

      - filter: load_balancer
        clusters:
          - name: backend
            endpoints:
              - "127.0.0.1:3000"

insecure_options:
  allow_private_endpoints: true # example proxies to local backends
