credential_injection

Injects per-cluster API credentials into upstream requests.
On this page

Injects per-cluster API credentials into upstream requests.

Configuration Notes

For each configured cluster, injects a header (e.g. Authorization: Bearer sk-...), replacing any client-provided value for that header to prevent credential forwarding.

Credentials are resolved at construction time (inline values or environment variables). The filter matches on the cluster name selected by the router filter earlier in the pipeline.

Scoping is per-cluster: a request routed to a cluster with no configured entry is left untouched, so a client-supplied header (e.g. Authorization) is forwarded to that cluster unchanged. This filter is not a general credential stripper; pair it with an explicit header-removal filter if every cluster must have client credentials stripped. The injected secret itself is only ever applied to the cluster it is configured for.

On the response path the injected header is stripped before the response reaches the client, so a gateway-managed credential never leaks even if the upstream echoes it back.

Configuration

FieldTypeRequiredDescription
clustersClusterCredentialConfig[]yesPer-cluster credential injection rules.
clusters[].namestringyesCluster name this rule applies to.
clusters[].env_varstringnoEnvironment variable name containing the credential. Resolved at filter construction time. Mutually exclusive with value.
clusters[].headerstringyesHeader name to inject (e.g. "Authorization", "x-api-key").
clusters[].header_prefixstringnoOptional prefix prepended to the credential value before injection (e.g. "Bearer ").
clusters[].strip_client_credentialboolnoDeprecated: injection always replaces any client-provided value for the header. Retained for config compatibility.
clusters[].valuestring (secret)noLiteral credential value. Mutually exclusive with env_var. Wrapped in [SecretString] to prevent accidental logging.

Example

filter: credential_injection
clusters:
  - name: provider-a
    header: Authorization
    env_var: PROVIDER_A_API_KEY
    header_prefix: "Bearer "
    strip_client_credential: true
  - name: internal
    header: x-api-key
    value: "internal-secret"