Dynamic forward proxy cluster configuration

This documentation is for the Envoy v3 API.

As of Envoy v1.18 the v2 API has been removed and is no longer supported.

If you are upgrading from v2 API config you may wish to view the v2 API documentation:


[extensions.clusters.dynamic_forward_proxy.v3.ClusterConfig proto]

Configuration for the dynamic forward proxy cluster. See the architecture overview for more information.

This extension may be referenced by the qualified name envoy.clusters.dynamic_forward_proxy


This extension is intended to be robust against untrusted downstream traffic. It assumes that the upstream is trusted.


This extension extends and can be used with the following extension category:

  "dns_cache_config": "{...}",
  "allow_insecure_cluster_options": "..."

(extensions.common.dynamic_forward_proxy.v3.DnsCacheConfig, REQUIRED) The DNS cache configuration that the cluster will attach to. Note this configuration must match that of associated dynamic forward proxy HTTP filter configuration.


(bool) If true allow the cluster configuration to disable the auto_sni and auto_san_validation options in the cluster’s upstream_http_protocol_options