# Provider API Key 放在专用 Header;日志必须统一脱敏。 version: 1 security: {requireProtectionOnPublicListen: true} gateway: {enabled: true, listen: '127.0.0.1:8080', auth: {mode: none}} routing: - name: gateway enabled: true purpose: gateway match: {hostRegex: '.*'} upstreams: [provider-a] strategy: {type: leastConnections} onUnavailable: {action: reject} upstreams: provider-a: enabled: true exposure: [gateway] provider: {billingMode: fetch, protocols: [http]} api: url: https://provider-a.example/proxies method: GET auth: type: apiKey location: header name: X-Provider-Key value: "${PROVIDER_API_KEY}" template: '{{.}}' proxyAuth: {type: response} pool: {maxSize: 500} capacity: {maxConcurrencyPerProxy: 10} refill: {reconcileInterval: 1s, minimumAvailableSlots: 25, targetAvailableSlots: 50} lifecycle: {ttl: 2m, allocationSafetyMargin: 15s} fetch: {estimatedIPsPerCall: 10, requestInterval: 1s, timeout: 3s, maxAttempts: 3, maxInFlight: 1, maxTotal: 10000} check: {interval: 30s, jitter: 20, maxInFlight: 100, timeout: 2s, maxAttempts: 2, maxConsecutiveFailures: 3}