Tls Sni Routing

Routes TLS connections to different upstreams based on the Server Name Indication (SNI) hostname in the ClientHello

Category: Setup-dependent integration
Task: Routes TLS connections to different upstreams based on the Server Name Indication (SNI) hostname in the ClientHello

Prerequisites: The external service, credentials, or certificates referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/praxis:0.7.2 and follow the first reverse-proxy tutorial to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# TLS SNI Routing (TCP Filter)
#
# Routes TLS connections to different upstreams based on the
# Server Name Indication (SNI) hostname in the ClientHello.
# No TLS termination: the proxy passes encrypted bytes through.
#
#   Client -> TLS -> Praxis :443 -> TLS -> upstream (by SNI)
#
insecure_options:
  allow_private_upstreams: true

listeners:
  - name: tls-gateway
    address: "0.0.0.0:8443"
    protocol: tcp
    filter_chains:
      - sni-routing

filter_chains:
  - name: sni-routing
    filters:
      - filter: sni_router
        routes:
          - server_names: [ "api.example.com" ]
            upstream: "127.0.0.1:9001"
          - server_names: [ "*.example.com" ]
            upstream: "127.0.0.1:9002"
        default_upstream: "127.0.0.1:9003"
      - filter: tcp_access_log