Skip to content

feat(#455 slice 3): per-fallback / per-endpoint gateway auth (overlay is primary-only) #491

Description

@initializ-mk

Follow-up slice of #455. The slice-1 (#464) gateway overlay + api_key_helper apply to the PRIMARY model only. ModelFallback (forge-core/types/config.go) has no auth_scheme/auth_header_name, and resolveFallbacks (forge-core/runtime/config.go) resolves fallback auth from provider-native env keys only — so fallbacks cannot go through the gateway.

Problem

"Run several models all behind the gateway" (e.g. an anthropic primary + an openai fallback, both via the Kong/OIDC gateway) is not expressible: the fallback would try direct-to-provider with a native key and fail. Documented limitation in docs/reference/settings.md.

Scope

  • Lift auth_scheme / auth_header_name / api_key_helper (+ env) onto ModelFallback — the intentionally-deferred follow-up noted in types/config.go.
  • Wire resolveFallbacks to honor a fallback's base_url (currently only read from env) + auth fields.
  • Extend the runtime overlay (applyGatewaySettings) to apply the matching gateway to each fallback by its provider (settings.ModelSettings.GatewayForProvider), not just mc.Client.
  • Multi-key token cache already supports this: GatewayCredKey(helper, env) is keyed by (helper, env), so per-provider fallback gateways get distinct tokens for free.
  • FORGE_MODEL_FALLBACKS env encoding would need a parallel update (per the types/config.go note).

Acceptance

  • A forge.yaml with a gateway primary + a gateway fallback (different provider) routes BOTH through their matching gateway with a fresh token.
  • forge auth status / login covers each configured fallback gateway.

Depends on #455 slice 1 (#464).

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestforge-coreAffects the forge-core library (runtime, security, types, llm, mcp, auth)

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions