Grpc Http2 Upstream
Praxis proxies to upstreams over HTTP/1.1 by default. gRPC backends speak HTTP/2 only, and a call’s outcome (grpc-status) arrives in response trailers, which no HTTP/1.1 leg can carry
Configurations in Protocols.
Praxis proxies to upstreams over HTTP/1.1 by default. gRPC backends speak HTTP/2 only, and a call’s outcome (grpc-status) arrives in response trailers, which no HTTP/1.1 leg can carry
HTTP and TCP listeners run on a single server instance
TCP consistent-hash load balancing (client IP affinity)
TCP least-connections load balancing
Bidirectional TCP forwarding
TCP round-robin load balancing across database replicas
TCP proxy with session and max duration timeouts. tcp_session_timeout_ms wraps the entire TCP forwarding session in a hard deadline, terminating connections after the threshold regardless of activity. tcp_max_duration_secs caps the total session duration in seconds
The proxy requires TCP clients to present a valid TLS certificate signed by the trusted CA
TLS on the listener; plain TCP to the upstream backend
Restrict accepted cipher suites per listener
HTTPS on the listener; TLS to the upstream backend
Client mTLS to the proxy (client cert required), and proxy mTLS to the upstream backend (proxy presents its own client certificate)
The proxy requires clients to present a valid TLS certificate signed by the trusted CA
The proxy requests a client certificate but does not require one
The proxy authorizes a client at the TLS handshake by the SPIFFE ID in its X.509-SVID client certificate
Plain HTTP from clients; the proxy presents a client certificate to the upstream backend, which requires mutual TLS authentication
Multiple certificates on one listener; Praxis selects the certificate matching the client’s SNI hostname
Routes TLS connections to different upstreams based on the Server Name Indication (SNI) hostname in the ClientHello
Accept HTTPS connections and forward decrypted requests to an HTTP backend.
Plain HTTP listener; TLS to the upstream with certificate verification disabled
Restrict accepted TLS versions via min_version
Sets a trusted CA bundle for all upstream TLS connections via runtime.upstream_ca_file
Plain HTTP on the listener; TLS to the upstream
HTTP listener that transparently proxies WebSocket upgrade requests