Field Extraction Access Control

Extracts the “tenant_id” field from the JSON request body and promotes it to an X-Tenant-Id header

Category: Practical
Task: Extracts the “tenant_id” field from the JSON request body and promotes it to an X-Tenant-Id header

Prerequisites: The product runtime and any backend services referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/praxis:0.7.2 and follow the first reverse-proxy tutorial to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Field Extraction for Tenant Access Control
#
# Extracts the "tenant_id" field from the JSON request body
# and promotes it to an X-Tenant-Id header. The router then
# matches on this header to enforce tenant isolation by
# directing each tenant's requests to dedicated backend
# clusters.
#
# Unknown or missing tenants fall through to a default
# cluster (which could be a rejection endpoint in
# production).
#
listeners:
  - name: api-gateway
    address: "0.0.0.0:8080" # dev value; binds all interfaces
    filter_chains:
      - extract-tenant
      - routing

filter_chains:
  - name: extract-tenant
    filters:
      - filter: json_body_field
        field: tenant_id
        header: X-Tenant-Id

  - name: routing
    filters:
      - filter: router
        routes:
          - path_prefix: "/"
            headers:
              x-tenant-id: "acme"
            cluster: acme
          - path_prefix: "/"
            headers:
              x-tenant-id: "globex"
            cluster: globex
          - path_prefix: "/"
            cluster: default
      - filter: load_balancer
        clusters:
          - name: acme
            endpoints:
              - "10.0.1.1:8080"
              - "10.0.1.2:8080"
          - name: globex
            endpoints:
              - "10.0.2.1:8080"
          - name: default
            endpoints:
              - "10.0.3.1:8080"