Docs

Proxies

Integrate governance with the proxy and sidecar infrastructure through which AI traffic is controlled.

Proxies is the governed proxy and sidecar infrastructure that fronts real MCP traffic. The page spans two distinct implementations: the Data Plane's own edge deployments, provisioned into a customer's cluster, and a separate outbound proxy for MCP vendors the Data Plane calls on the customer's behalf. Internally the first is still called "edges" (the implementation module and one primary route are literally /edges); the taxonomy renames it to "Proxies" for anything customer-facing.

An edge deployment row describes one proxy — Envoy, NGINX, Istio, Kong, or FaburAI-managed — that can front many MCP servers by path routing rather than being pinned to one. Sizing comes from three presets (small, medium, large — each with a concrete replica count, CPU/memory request, and an approximate requests-per-second target) or a custom replica count. Creating a deployment kicks off a provisioner that renders the Kubernetes manifests for the chosen adapter — an Enforcer Deployment plus the proxy-specific wiring, such as an Envoy ext_authz filter's ConfigMap snippet — and stores them on the row.

That render step is real; applying it is not yet. As the provisioner's own code comments put it, "the render half is real, the apply half is still simulated" — nothing calls the Kubernetes API to create the rendered resources. Today an operator copies the rendered YAML off the row and applies it with kubectl themselves; the row is marked running after a short fixed delay regardless.

The second implementation, mcpproxy, is narrower and unrelated to edge provisioning: it's the Data Plane's own outbound proxy for MCP vendors that require the Data Plane to mint and hold an OAuth bearer on the customer's behalf — AWS today, via IAM-based token minting, and Workato via a static token. It caches minted tokens for an hour, tracks each client's upstream MCP session by a session-key header, evaluates policy the same way the central gateway does before forwarding, retries once on a 401 after forcing a token refresh, and only forwards to an explicit host allowlist as defense-in-depth on top of the catalog row that names the endpoint.

Reference

Interfaces

data-plane serves /edges
data-plane serves /mcp-proxy