Skip to content

improvement on the model routing credential injector - #1477

Open
botengyao wants to merge 3 commits into
envoyproxy:mainfrom
botengyao:ai-transcoder-credential-injector
Open

botengyao wants to merge 3 commits into
envoyproxy:mainfrom
botengyao:ai-transcoder-credential-injector

Conversation

@botengyao

Copy link
Copy Markdown
Member

No description provided.

Only a request read_model parsed has a model, and read_model parses only
the requests of the chat_completions route, so the provider routes match
on the model alone and Anthropic's rewrite no longer names the path.

Signed-off-by: Boteng Yao <botengyao@gmail.com>
Each provider's key is now a static secret, added by a credential
injector that only the provider's route enables. The injectors are
upstream filters, as the router creates those once the model's route
is picked. Without a key, Envoy answers with a 401 instead of sending
the request, which verify.sh checks when no keys are set.

The routes name their host with host_rewrite_literal, as the dynamic
forward proxy cluster resolves hosts itself, and set Anthropic's path
with path_rewrite.

Signed-off-by: Boteng Yao <botengyao@gmail.com>
@botengyao
botengyao marked this pull request as ready for review October 1, 2026 21:20
Signed-off-by: Boteng Yao <botengyao@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant