Protocols

24 configurations in Protocols for Praxis.

Configurations in Protocols.

Configurations

  • Grpc Http2 Upstream — Praxis proxies to upstreams over HTTP/1.1 by default. gRPC backends speak HTTP/2 only, and a call’s outcome (grpc-status) arrives in response trailers, which no HTTP/1.1 leg can carry
  • Mixed Protocol — HTTP and TCP listeners run on a single server instance
  • Tcp Consistent Hash — TCP consistent-hash load balancing (client IP affinity)
  • Tcp Least Connections — TCP least-connections load balancing
  • Tcp Proxy — Bidirectional TCP forwarding
  • Tcp Round Robin — TCP round-robin load balancing across database replicas
  • Tcp Timeouts — TCP proxy with session and max duration timeouts. tcp_session_timeout_ms wraps the entire TCP forwarding session in a hard deadline, terminating connections after the threshold regardless of activity. tcp_max_duration_secs caps the total session duration in seconds
  • Tcp Tls Mtls — The proxy requires TCP clients to present a valid TLS certificate signed by the trusted CA
  • Tcp Tls Termination — TLS on the listener; plain TCP to the upstream backend
  • Tls Cipher Suites — Restrict accepted cipher suites per listener
  • Tls Http Reencrypt — HTTPS on the listener; TLS to the upstream backend
  • Tls Mtls Both — Client mTLS to the proxy (client cert required), and proxy mTLS to the upstream backend (proxy presents its own client certificate)
  • Tls Mtls Listener Request — The proxy requests a client certificate but does not require one
  • Tls Mtls Listener — The proxy requires clients to present a valid TLS certificate signed by the trusted CA
  • Tls Mtls Spiffe — The proxy authorizes a client at the TLS handshake by the SPIFFE ID in its X.509-SVID client certificate
  • Tls Mtls Upstream — Plain HTTP from clients; the proxy presents a client certificate to the upstream backend, which requires mutual TLS authentication
  • Tls Multi Cert — Multiple certificates on one listener; Praxis selects the certificate matching the client’s SNI hostname
  • Tls Sni Routing — Routes TLS connections to different upstreams based on the Server Name Indication (SNI) hostname in the ClientHello
  • Tls Termination — Accept HTTPS connections and forward decrypted requests to an HTTP backend.
  • Tls Verify Disabled — Plain HTTP listener; TLS to the upstream with certificate verification disabled
  • Tls Version Constraint — Restrict accepted TLS versions via min_version
  • Upstream Ca File — Sets a trusted CA bundle for all upstream TLS connections via runtime.upstream_ca_file
  • Upstream Tls — Plain HTTP on the listener; TLS to the upstream
  • Websocket — HTTP listener that transparently proxies WebSocket upgrade requests

Grpc Http2 Upstream

Praxis proxies to upstreams over HTTP/1.1 by default. gRPC backends speak HTTP/2 only, and a call’s outcome (grpc-status) arrives in response trailers, which no HTTP/1.1 leg can carry

Mixed Protocol

HTTP and TCP listeners run on a single server instance

Tcp Consistent Hash

TCP consistent-hash load balancing (client IP affinity)

Tcp Least Connections

TCP least-connections load balancing

Tcp Proxy

Bidirectional TCP forwarding

Tcp Round Robin

TCP round-robin load balancing across database replicas

Tcp Timeouts

TCP proxy with session and max duration timeouts. tcp_session_timeout_ms wraps the entire TCP forwarding session in a hard deadline, terminating connections after the threshold regardless of activity. tcp_max_duration_secs caps the total session duration in seconds

Tcp Tls Mtls

The proxy requires TCP clients to present a valid TLS certificate signed by the trusted CA

Tcp Tls Termination

TLS on the listener; plain TCP to the upstream backend

Tls Cipher Suites

Restrict accepted cipher suites per listener

Tls Http Reencrypt

HTTPS on the listener; TLS to the upstream backend

Tls Mtls Both

Client mTLS to the proxy (client cert required), and proxy mTLS to the upstream backend (proxy presents its own client certificate)

Tls Mtls Listener

The proxy requires clients to present a valid TLS certificate signed by the trusted CA

Tls Mtls Listener Request

The proxy requests a client certificate but does not require one

Tls Mtls Spiffe

The proxy authorizes a client at the TLS handshake by the SPIFFE ID in its X.509-SVID client certificate

Tls Mtls Upstream

Plain HTTP from clients; the proxy presents a client certificate to the upstream backend, which requires mutual TLS authentication

Tls Multi Cert

Multiple certificates on one listener; Praxis selects the certificate matching the client’s SNI hostname

Tls Sni Routing

Routes TLS connections to different upstreams based on the Server Name Indication (SNI) hostname in the ClientHello

Tls Termination

Accept HTTPS connections and forward decrypted requests to an HTTP backend.

Tls Verify Disabled

Plain HTTP listener; TLS to the upstream with certificate verification disabled

Tls Version Constraint

Restrict accepted TLS versions via min_version

Upstream Ca File

Sets a trusted CA bundle for all upstream TLS connections via runtime.upstream_ca_file

Upstream Tls

Plain HTTP on the listener; TLS to the upstream

Websocket

HTTP listener that transparently proxies WebSocket upgrade requests