- Add LLMAuth struct with support for Bearer, API Key, and Custom auth types - Implement applyAuth() to inject auth headers into LLM requests - Add X-Tenant-ID header for multi-tenant isolation - Add X-OAuth-Scopes header for OAuth2 scope enforcement - Add UpdateAuth() for runtime token refresh (long-running workflows) - Update LLMRouterConfig with Auth and TenantID fields - Document 4 authentication patterns (Bearer, API Key, Custom, Router config) - Add security best practices: token vault integration, tenant isolation, scopes - Add audit headers for compliance & logging - Create multi-tenant router factory pattern Auth types supported: - Bearer: JWT/OAuth2 tokens (most secure for federated access) - API Key: Static keys (X-API-Key header) - Custom: Any custom header-based scheme - None: No authentication Customers can now pass per-tenant JWT tokens with customized scopes and isolated LLM API access per tenant/customer.
- Explain Poimen philosophy (shepherd metaphor for orchestration) - Document architecture and data flow with visual diagrams - List all 9 registered activities with knowledge specs - Provide getting started guide and usage patterns - Include CI/CD pipeline, troubleshooting, and roadmap - Integrate skills registration guide for contributors - Explain registerable knowledge types (activity, domain, patterns) - Document CRAP score improvements (97% reduction) - Create virtuous cycle explanation (self-improving system) - Add .gitignore exception for README.md Refs: Shepherd metaphor emphasizes learning, adaptation, and composition over rigid task scheduling. Each registered skill teaches the system.