Policy Llm
Authorizes body-addressed inference requests against llm: policy routes
Versions marked “overview” do not contain this page. Selecting one opens that version’s documentation overview.
Category: Setup-dependent integration
Task: Authorizes body-addressed inference requests against llm: policy routes
Prerequisites: The external service, credentials, or certificates referenced by this configuration.
This configuration comes from the selected release. The example has not been run here; external services are not bundled.
Download the source file.
Companion resources from the same snapshot:
# Inference Authorization
#
# Authorizes body-addressed inference requests against `llm:` policy routes.
# The proxy reads the top-level `model`; missing, unlisted, and ambiguous
# models fail closed by default. No protocol classifier is required.
#
# Point `config_path` at an operator-supplied policy. The integration fixture
# at `tests/integration/fixtures/llm-policy.yaml` provides a local example.
#
# Requires building with the `policy-engine` feature, which is off
# by default:
#
# Usage:
# cargo run -p praxis-proxy --features policy-engine -- -c examples/configs/security/policy-llm.yaml
#
listeners:
- name: default
address: "127.0.0.1:8080"
filter_chains:
- main
filter_chains:
- name: main
filters:
- filter: policy
config_path: /etc/praxis/llm-policy.yaml
llm:
require_model: true
provider: openai
# URL-addressed providers do not expose the model this filter evaluates.
- filter: router
routes:
- path_prefix: "/v1/"
cluster: inference
- filter: load_balancer
clusters:
- name: inference
endpoints:
- "127.0.0.1:3000"
insecure_options:
allow_private_endpoints: true