forwarded_headers

Injects X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host headers into upstream requests.
On this page

Injects X-Forwarded-For, X-Forwarded-Proto, and X-Forwarded-Host headers into upstream requests.

Configuration Notes

When the client IP is from a trusted proxy, existing X-Forwarded-For values are preserved and the client IP is appended, and a non-empty X-Forwarded-Proto or X-Forwarded-Host the proxy set is kept, since it describes the original client connection. Otherwise, all three are overwritten to prevent spoofing.

When use_standard_header is true, also injects the RFC 7239 Forwarded header with for, proto, and host parameters.

Configuration

FieldTypeRequiredDescription
trusted_proxiesstring[]noCIDR ranges of trusted proxies whose existing X-Forwarded-For values are preserved (appended to). Untrusted sources have the header overwritten.
use_standard_headerboolnoWhen true, also inject the standard RFC 7239 Forwarded header in addition to X-Forwarded-* headers.

Example

filter: forwarded_headers
trusted_proxies: ["10.0.0.0/8"]
use_standard_header: true