feat: add JWT/OAuth2 authentication & multi-tenant federation
ci / test (push) Failing after 1m49s

- Add LLMAuth struct with support for Bearer, API Key, and Custom auth types
- Implement applyAuth() to inject auth headers into LLM requests
- Add X-Tenant-ID header for multi-tenant isolation
- Add X-OAuth-Scopes header for OAuth2 scope enforcement
- Add UpdateAuth() for runtime token refresh (long-running workflows)
- Update LLMRouterConfig with Auth and TenantID fields
- Document 4 authentication patterns (Bearer, API Key, Custom, Router config)
- Add security best practices: token vault integration, tenant isolation, scopes
- Add audit headers for compliance & logging
- Create multi-tenant router factory pattern

Auth types supported:
- Bearer: JWT/OAuth2 tokens (most secure for federated access)
- API Key: Static keys (X-API-Key header)
- Custom: Any custom header-based scheme
- None: No authentication

Customers can now pass per-tenant JWT tokens with customized scopes
and isolated LLM API access per tenant/customer.
This commit is contained in:
Test
2026-09-04 10:54:22 -07:00
parent 86ad8e7b5e
commit 66c17e821f
5 changed files with 324 additions and 6 deletions
+2 -2
View File
@@ -13,8 +13,8 @@ spec:
labels:
app: poimen-worker
annotations:
git-commit: "f3ce019c" # ✅ Updated on each push, triggers rolling restart
deployment-date: "2026-09-03"
git-commit: "30644a8e" # ✅ Updated on each push, triggers rolling restart
deployment-date: "2026-09-04"
spec:
containers:
- name: worker