feat: reach external providers through a LiteLLM proxy with declared fallback - #35
Merged
Merged
Conversation
…fallback The design names LiteLLM as the layer that normalizes external endpoints and centralizes fallback. There was no external provider path: a decision for the approved external model was sent to the local engine under that name. External decisions now go to a LiteLLM proxy, which holds the provider credentials so they never enter the gateway. The privacy rule is enforced a second time at the dispatch boundary, so a routing defect cannot send private or restricted data out. Each target has its own circuit. When the local engine fails, a request already entitled to external routing falls back to it; the switch is attributed in the route reason and counted. Enabling external fallback against a real engine without a proxy address is refused at start-up. The proxy is the only workload allowed to reach the internet, and only the gateway may call it. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Eighth PR closing gaps between the design spec and the implementation.
Gap this closes
§6/§7.1 name LiteLLM as the layer that normalizes external endpoints and centralizes fallback; §10 has "apply declared fallback if required". There was no external provider path: an external decision was sent to the local engine under the name
approved-external-fallback.What changed
DispatchingBackendsends local decisions to the engine and external ones to a LiteLLM proxy (ROUTER_EXTERNAL_BASE_URL,ROUTER_EXTERNAL_API_KEY). Provider credentials live in the proxy.policy_violation) without contacting the provider.router_fallbacks_totalcounts it.external_fallback_enabledwith the vLLM backend and no proxy address.config/litellm.yaml, anddeploy/kubernetes/external-provider.yaml: proxy Deployment, Service, and a NetworkPolicy making it the only workload with internet egress, reachable only from the gateway.os.environ/reference.Not done
config/litellm.yamlis a placeholder for whichever provider is approved.Test plan
ruff format,ruff check .,mypycleanpytest tests/unit tests/integration: 338 passed, coverage 98%🤖 Generated with Claude Code