2026-08-18 14:23:55 -07:00
|
|
|
# API auth layer — Kong key-auth on the model routes.
|
|
|
|
|
#
|
2026-08-18 15:36:18 -07:00
|
|
|
# TEMPORARILY RETIRED: verified live that Kong's key-auth here does not accept
|
|
|
|
|
# `Authorization: Bearer <key>` the way the comment below used to claim — a
|
|
|
|
|
# raw `apikey: <key>` header succeeds (200), the same request with only
|
|
|
|
|
# `Authorization: Bearer <key>` fails (401). No OpenAI-SDK-compatible client
|
|
|
|
|
# (pi included) sends a raw apikey header or lets you customize the header
|
|
|
|
|
# name, so every such client was hard-blocked. The KongPlugin below is
|
|
|
|
|
# commented out and every route's `konghq.com/plugins` annotation in
|
|
|
|
|
# llm-routes.yaml has `model-key-auth` stripped, so the model routes are
|
|
|
|
|
# unauthenticated for now. Re-enable once there's a Bearer-compatible fix
|
|
|
|
|
# (e.g. a request-transformer that copies the Bearer token into an `apikey`
|
|
|
|
|
# header before key-auth runs) — do not just uncomment this as-is, that
|
|
|
|
|
# reintroduces the exact block every real client hits.
|
2026-08-18 14:23:55 -07:00
|
|
|
#
|
2026-08-18 15:36:18 -07:00
|
|
|
# The key itself lives in the ksops-managed Secret model-invoke-apikey
|
|
|
|
|
# (labelled konghq.com/credential: key-auth) and is bound to the KongConsumer
|
|
|
|
|
# below, which stays defined (harmless without the plugin) so re-enabling
|
|
|
|
|
# later is a two-line uncomment instead of a rebuild.
|
2026-08-18 14:23:55 -07:00
|
|
|
---
|
|
|
|
|
apiVersion: configuration.konghq.com/v1
|
|
|
|
|
kind: KongConsumer
|
|
|
|
|
metadata:
|
|
|
|
|
name: model-invoker
|
|
|
|
|
namespace: api
|
|
|
|
|
annotations:
|
|
|
|
|
kubernetes.io/ingress.class: kong
|
|
|
|
|
username: model-invoker
|
|
|
|
|
credentials:
|
|
|
|
|
- model-invoke-apikey
|
2026-08-18 15:36:18 -07:00
|
|
|
# ---
|
|
|
|
|
# apiVersion: configuration.konghq.com/v1
|
|
|
|
|
# kind: KongPlugin
|
|
|
|
|
# metadata:
|
|
|
|
|
# name: model-key-auth
|
|
|
|
|
# namespace: llm-serving
|
|
|
|
|
# plugin: key-auth
|
|
|
|
|
# config:
|
|
|
|
|
# key_names:
|
|
|
|
|
# - apikey
|
|
|
|
|
# - authorization
|
|
|
|
|
# key_in_header: true
|
|
|
|
|
# key_in_query: false
|
|
|
|
|
# key_in_body: false
|
|
|
|
|
# hide_credentials: true
|