fix(terraform): preserve server-derived key routes

This commit is contained in:
Roman Soletskyi 2026-09-23 10:33:30 +02:00
parent 2fb90ddbba
commit 2a0ffdb972
2 changed files with 30 additions and 3 deletions

View file

@ -172,6 +172,7 @@ func resourceKey() *schema.Resource {
"allowed_routes": {
Type: schema.TypeList,
Optional: true,
Computed: true,
Elem: &schema.Schema{Type: schema.TypeString},
},
"allowed_passthrough_routes": {
@ -589,9 +590,7 @@ func mapKeyToResourceData(d *schema.ResourceData, key *Key) {
if len(key.EnforcedParams) > 0 {
d.Set("enforced_params", key.EnforcedParams)
}
if len(key.AllowedRoutes) > 0 {
d.Set("allowed_routes", key.AllowedRoutes)
}
d.Set("allowed_routes", append([]string{}, key.AllowedRoutes...))
if len(key.AllowedPassthroughRoutes) > 0 {
d.Set("allowed_passthrough_routes", key.AllowedPassthroughRoutes)
}

View file

@ -232,6 +232,34 @@ func TestKeyTypeChangeForcesReplacement(t *testing.T) {
}
}
func TestKeyTypePresetRoutesDoNotDrift(t *testing.T) {
cases := map[string]struct {
read *Key
config map[string]interface{}
}{
"llm_api preset": {read: &Key{KeyType: "llm_api", AllowedRoutes: []string{"llm_api_routes"}}, config: map[string]interface{}{"key_type": "llm_api"}},
"default no routes": {read: &Key{KeyType: "default"}, config: map[string]interface{}{}},
}
for name, tc := range cases {
t.Run(name, func(t *testing.T) {
res := resourceKey()
priorData := newKeyResourceData(t, map[string]interface{}{})
priorData.SetId("hash-1")
if err := priorData.Set("server_metadata", serverKeyMetadata(tc.read.Metadata)); err != nil {
t.Fatalf("set server_metadata: %v", err)
}
mapKeyToResourceData(priorData, tc.read)
diff, err := res.Diff(context.Background(), priorData.State(), terraform.NewResourceConfigRaw(tc.config), nil)
if err != nil {
t.Fatalf("diff failed: %v", err)
}
if diff != nil && !diff.Empty() {
t.Fatalf("server-derived allowed_routes must not drift, diff = %+v", diff)
}
})
}
}
// The proxy validates each model_max_budget entry as a BudgetConfig object and
// 500s on a bare number, so the JSON string must reach /key/generate as nested
// objects and the proxy's response must map back to equivalent JSON in state.