Composed Chains

Multiple named chains are composed per listener

Category: Practical
Task: Multiple named chains are composed per listener

Prerequisites: The product runtime and any backend services referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/praxis:0.7.2 and follow the first reverse-proxy tutorial to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Composed Filter Chains
#
# Multiple named chains are composed per listener. The public
# listener gets security + observability + routing. The
# internal listener skips security.
#
listeners:
  - name: public
    address: "127.0.0.1:8080"
    filter_chains:
      - security
      - observability
      - routing

  - name: internal
    address: "127.0.0.1:9090"
    filter_chains:
      - observability
      - routing

filter_chains:
  - name: security
    filters:
      - filter: headers
        response_set:
          - name: X-Content-Type-Options
            value: nosniff
          - name: X-Frame-Options
            value: DENY

  - name: observability
    filters:
      - filter: request_id
      - filter: access_log

  - name: routing
    filters:
      - filter: router
        routes:
          - path_prefix: "/api/"
            cluster: api
          - path_prefix: "/"
            cluster: web
      - filter: load_balancer
        clusters:
          - name: api
            endpoints:
              - "10.0.0.1:8080"
          - name: web
            endpoints:
              - "10.0.0.2:8080"