Follow-up slice of #455. The slice-1 (#464) gateway overlay + api_key_helper apply to the PRIMARY model only. ModelFallback (forge-core/types/config.go) has no auth_scheme/auth_header_name, and resolveFallbacks (forge-core/runtime/config.go) resolves fallback auth from provider-native env keys only — so fallbacks cannot go through the gateway.
Problem
"Run several models all behind the gateway" (e.g. an anthropic primary + an openai fallback, both via the Kong/OIDC gateway) is not expressible: the fallback would try direct-to-provider with a native key and fail. Documented limitation in docs/reference/settings.md.
Scope
- Lift
auth_scheme / auth_header_name / api_key_helper (+ env) onto ModelFallback — the intentionally-deferred follow-up noted in types/config.go.
- Wire
resolveFallbacks to honor a fallback's base_url (currently only read from env) + auth fields.
- Extend the runtime overlay (
applyGatewaySettings) to apply the matching gateway to each fallback by its provider (settings.ModelSettings.GatewayForProvider), not just mc.Client.
- Multi-key token cache already supports this:
GatewayCredKey(helper, env) is keyed by (helper, env), so per-provider fallback gateways get distinct tokens for free.
FORGE_MODEL_FALLBACKS env encoding would need a parallel update (per the types/config.go note).
Acceptance
Depends on #455 slice 1 (#464).
Follow-up slice of #455. The slice-1 (#464) gateway overlay +
api_key_helperapply to the PRIMARY model only.ModelFallback(forge-core/types/config.go) has noauth_scheme/auth_header_name, andresolveFallbacks(forge-core/runtime/config.go) resolves fallback auth from provider-native env keys only — so fallbacks cannot go through the gateway.Problem
"Run several models all behind the gateway" (e.g. an anthropic primary + an openai fallback, both via the Kong/OIDC gateway) is not expressible: the fallback would try direct-to-provider with a native key and fail. Documented limitation in
docs/reference/settings.md.Scope
auth_scheme/auth_header_name/api_key_helper(+env) ontoModelFallback— the intentionally-deferred follow-up noted intypes/config.go.resolveFallbacksto honor a fallback'sbase_url(currently only read from env) + auth fields.applyGatewaySettings) to apply the matching gateway to each fallback by its provider (settings.ModelSettings.GatewayForProvider), not justmc.Client.GatewayCredKey(helper, env)is keyed by(helper, env), so per-provider fallback gateways get distinct tokens for free.FORGE_MODEL_FALLBACKSenv encoding would need a parallel update (per thetypes/config.gonote).Acceptance
forge auth status/ login covers each configured fallback gateway.Depends on #455 slice 1 (#464).