Guardrails

Reject requests that match header or body inspection rules

Category: Setup-dependent integration
Task: Reject requests that match header or body inspection rules

Prerequisites: The external service, credentials, or certificates referenced by this configuration.

Run it: Use ghcr.io/praxis-proxy/praxis:0.7.2 and follow the first reverse-proxy tutorial to mount and start the configuration.

This configuration comes from the selected release. The example has not been run here; external services are not bundled.

Download the source file.

# Guardrails
#
# Reject requests that match header or body inspection
# rules. Rules use literal substring matching (`contains`)
# or regex (`pattern`). Set `negate: true` to invert the
# match (reject when content does NOT match). Any triggered
# rule returns 401 Unauthorized.
#
listeners:
  - name: default
    address: "127.0.0.1:8080"
    filter_chains:
      - main

filter_chains:
  - name: main
    filters:
      - filter: guardrails
        rules:
          # Block known bad bots by User-Agent
          - target: header
            name: "User-Agent"
            pattern: "bad-bot.*"

          # Block body containing suspicious content
          - target: body
            contains: "evilmonkey"

          # Require X-Authorized header to contain "trusted"
          # (reject if NOT present or NOT matching)
          - target: header
            name: "X-Authorized"
            contains: "trusted"
            negate: true

          # Require body to look like JSON
          # (reject if body does NOT match the pattern)
          - target: body
            pattern: "^\\{.*\\}$"
            negate: true

          # Block PII in body
          - target: body
            contains: [ssn, credit_card, phone, email]

          # Block PII in header
          - target: header
            name: "X-Secret"
            contains: [ssn, credit_card, phone, email]

      - filter: router
        routes:
          - path_prefix: "/"
            cluster: backend

      - filter: load_balancer
        clusters:
          - name: backend
            endpoints:
              - "127.0.0.1:3000"

insecure_options:
  allow_private_endpoints: true # example proxies to local backends