Declare the native model routes and credentials the credential gateway relays - #343
Merged
Merged
Conversation
…y relays internal/modelprovider declares each protocol's native routes, upstream credential header, the stripped inbound credential headers and the non-secret placeholder, with LookupRoute returning a typed miss. model-execution.md replaces the no-proxy rule with the credential gateway rule.
…join StrippedHeaders adds Cookie and the Codex, Cloudflare AI Gateway and AWS credential headers in canonical form, removed case-insensitively with every value. UpstreamPath trims the base path's trailing slashes and appends the route. model-execution.md keeps the key in the gateway's memory, out of the Harness and the sandbox.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes the Harness–Model provider protocol for the agent-outside-sandbox shape: the Harness never holds the model key. A Session-local credential gateway on the agent host relays the native protocol unchanged and injects the key. This PR declares what that gateway relays. It contains no gateway code; that is a later lane.
internal/modelprovider/config.go, the boundary's protocol file, now declares:Authorization,Proxy-Authorization,Cookie,X-Api-Key,Api-Key,X-Openai-Actor-Authorization,Cf-Aig-AuthorizationandX-Amz-Security-Token;Placeholder;LookupRoute, which returns the typed missesErrRouteNotFoundandErrMethodNotAllowed;UpstreamPath, the single join rule: the base URL's escaped path with every trailing/removed, followed by the route path.It has no per-Harness branch: each protocol's routes are the union of the routes the pinned Harnesses call.
anthropicPOST /v1/messages,POST /v1/messages/count_tokensX-Api-Key: <key>responsesPOST /responsesAuthorization: Bearer <key>chat_completionsPOST /chat/completionsAuthorization: Bearer <key>anthropic, Claude Code sendsAuthorization: Bearerupstream today, while MiniMax Code and the Anthropic SDK's API-key path sendX-Api-Key. The protocol declaresX-Api-Key, the Anthropic Messages API's API-key header. Claude Code's upstream header form therefore changes once the gateway is wired.contracts/agents-api/model-execution.mdgains a "Credential gateway" section with the gateway rule, which replaces "no model API proxy, passthrough gateway". The dispatch paragraph now says that the gateway holds the key in memory and that the key never enters the Harness's environment, configuration or home, or the sandbox. The Harness onboarding guide, the Agents API guide and theharnessconfigpackage comment now link to it instead of restating the old rule.No adapter changes; adapter wiring is a later lane.
Checks:
go test,go vetand gofmt overinternal/modelproviderandinternal/harnessconfigPart of the agent-outside-sandbox work, milestone M1, lane L6p.