Nested Branches

Branch filters that themselves contain branches, forming a multi-level decision tree

Category: Setup-dependent integration
Task: Branch filters that themselves contain branches, forming a multi-level decision tree

Prerequisites: The external service, credentials, or certificates referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/praxis:0.7.2 and follow the first reverse-proxy tutorial to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Nested Branches
#
# Branch filters that themselves contain branches,
# forming a multi-level decision tree. The outer branch
# fires unconditionally to run guardrails, and the inner
# branch fires conditionally on the guardrails result to
# block dangerous requests.
#
# Use case: an outer branch always runs security checks,
# and an inner branch reacts to the check result.
#
listeners:
  - name: web
    address: "127.0.0.1:8080"
    filter_chains: [main]

filter_chains:
  - name: main
    filters:
      # Stamp each request for tracing
      - filter: request_id

      # Entry point: kicks off the security tree
      - filter: headers
        request_add:
          - name: X-Entry
            value: "start"
        branch_chains:
          # Outer branch: always runs guardrails.
          # Unconditional because every request needs
          # security inspection
          - name: security_check
            rejoin: next
            chains:
              - name: guardrails_chain
                filters:
                  # Guardrails (outer level). action: flag
                  # writes results without rejecting.
                  - filter: guardrails
                    action: flag
                    rules:
                      - target: header
                        name: "X-Danger"
                        contains: "true"
                    branch_chains:
                      # Inner branch: block dangerous
                      # requests detected by guardrails
                      - name: block_dangerous
                        on_result:
                          filter: guardrails
                          result: blocked
                        rejoin: terminal
                        chains:
                          - name: blocked_response
                            filters:
                              - filter: static_response
                                status: 403

      # Route after security tree completes
      - filter: router
        name: routing
        routes:
          - path_prefix: "/"
            cluster: backend

      - filter: load_balancer
        clusters:
          - name: backend
            endpoints:
              - "127.0.0.1:3000"

insecure_options:
  allow_private_endpoints: true # example proxies to local backends