From 368f2a66873477a59c5c9f52703a9e7bf735e7b5 Mon Sep 17 00:00:00 2001 From: Ishaan Jaffer Date: Fri, 24 Apr 2026 19:20:55 -0700 Subject: [PATCH] fix: reseed from DB on cache miss in _check_team_member_model_budget to prevent cold-start budget bypass --- litellm/proxy/auth/auth_checks.py | 13 ++++++++++--- 1 file changed, 10 insertions(+), 3 deletions(-) diff --git a/litellm/proxy/auth/auth_checks.py b/litellm/proxy/auth/auth_checks.py index ee1412af69d..ec005ce85e0 100644 --- a/litellm/proxy/auth/auth_checks.py +++ b/litellm/proxy/auth/auth_checks.py @@ -3372,7 +3372,7 @@ async def _check_team_member_model_budget( if not models_to_check: return - from litellm.proxy.proxy_server import get_current_spend + from litellm.proxy.proxy_server import _reseed_spend_from_db, get_current_spend for model_str in models_to_check: model_budget_config = team_member_model_max_budget.get(model_str) @@ -3387,10 +3387,17 @@ async def _check_team_member_model_budget( if max_budget is None: continue + counter_key = f"spend:team_member:{valid_token.user_id}:{team_object.team_id}:model:{model_str}" + # -1.0 is the sentinel for "cache cold". Negative spend is impossible, + # so this distinguishes "not cached yet" from a real zero balance. model_spend = await get_current_spend( - counter_key=f"spend:team_member:{valid_token.user_id}:{team_object.team_id}:model:{model_str}", - fallback_spend=0.0, + counter_key=counter_key, + fallback_spend=-1.0, ) + if model_spend < 0: + # Pod restart or Redis flush — reseed from the authoritative DB row + # before evaluating the budget. Mirrors _init_and_increment_spend_counter. + model_spend = await _reseed_spend_from_db(counter_key) if model_spend >= max_budget: raise litellm.BudgetExceededError(