From 3d527b722da2552e0b464989c7f7a991cda13d32 Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Sat, 28 Mar 2026 09:56:58 -0700 Subject: [PATCH 1/3] [Infra] Add isolated unit test workflows with hardened security posture Replace monolithic matrix workflow with individual, descriptively-named workflow files. Each workflow uses a shared reusable base and follows least-privilege security: zero secrets, read-only permissions, SHA-pinned actions, persist-credentials: false, and env-var indirection to prevent template injection. Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/_test-unit-base.yml | 95 ++++++++++++++++++ .github/workflows/test-unit-core-utils.yml | 20 ++++ .github/workflows/test-unit-documentation.yml | 20 ++++ .../test-unit-enterprise-routing.yml | 24 +++++ .github/workflows/test-unit-integrations.yml | 20 ++++ .github/workflows/test-unit-litellm-utils.yml | 20 ++++ .github/workflows/test-unit-llm-providers.yml | 29 ++++++ .github/workflows/test-unit-misc.yml | 31 ++++++ .github/workflows/test-unit-pass-through.yml | 20 ++++ .github/workflows/test-unit-proxy-auth.yml | 20 ++++ .../workflows/test-unit-proxy-endpoints.yml | 35 +++++++ .github/workflows/test-unit-proxy-infra.yml | 28 ++++++ .github/workflows/test-unit-proxy-legacy.yml | 96 +++++++++++++++++++ .../test-unit-responses-caching-types.yml | 20 ++++ .github/workflows/test-unit-router.yml | 20 ++++ .github/workflows/test-unit-security.yml | 20 ++++ 16 files changed, 518 insertions(+) create mode 100644 .github/workflows/_test-unit-base.yml create mode 100644 .github/workflows/test-unit-core-utils.yml create mode 100644 .github/workflows/test-unit-documentation.yml create mode 100644 .github/workflows/test-unit-enterprise-routing.yml create mode 100644 .github/workflows/test-unit-integrations.yml create mode 100644 .github/workflows/test-unit-litellm-utils.yml create mode 100644 .github/workflows/test-unit-llm-providers.yml create mode 100644 .github/workflows/test-unit-misc.yml create mode 100644 .github/workflows/test-unit-pass-through.yml create mode 100644 .github/workflows/test-unit-proxy-auth.yml create mode 100644 .github/workflows/test-unit-proxy-endpoints.yml create mode 100644 .github/workflows/test-unit-proxy-infra.yml create mode 100644 .github/workflows/test-unit-proxy-legacy.yml create mode 100644 .github/workflows/test-unit-responses-caching-types.yml create mode 100644 .github/workflows/test-unit-router.yml create mode 100644 .github/workflows/test-unit-security.yml diff --git a/.github/workflows/_test-unit-base.yml b/.github/workflows/_test-unit-base.yml new file mode 100644 index 00000000000..d52a1eb34c3 --- /dev/null +++ b/.github/workflows/_test-unit-base.yml @@ -0,0 +1,95 @@ +name: _Unit Test Base (Reusable) + +on: + workflow_call: + inputs: + test-path: + description: "Pytest path(s) to run" + required: true + type: string + workers: + description: "Number of pytest-xdist workers" + required: false + type: number + default: 2 + reruns: + description: "Number of reruns for flaky tests" + required: false + type: number + default: 2 + timeout-minutes: + description: "Job timeout in minutes" + required: false + type: number + default: 20 + max-failures: + description: "Stop after this many failures" + required: false + type: number + default: 10 + +permissions: + contents: read + +jobs: + test: + runs-on: ubuntu-latest + timeout-minutes: ${{ inputs.timeout-minutes }} + + steps: + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 + with: + persist-credentials: false + + - name: Set up Python + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 + with: + python-version: "3.12" + + - name: Install Poetry + run: pip install 'poetry==2.3.2' + + - name: Cache Poetry dependencies + uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + with: + path: | + ~/.cache/pypoetry + ~/.cache/pip + .venv + key: ${{ runner.os }}-poetry-${{ hashFiles('poetry.lock') }} + restore-keys: | + ${{ runner.os }}-poetry- + + - name: Install dependencies + run: | + poetry config virtualenvs.in-project true + poetry install --with dev,proxy-dev --extras "proxy semantic-router" + poetry run pip install google-genai==1.22.0 \ + google-cloud-aiplatform==1.115.0 fastapi-offline==1.7.3 python-multipart==0.0.22 openapi-core==0.23.0 + + - name: Setup litellm-enterprise + run: | + poetry run pip install --force-reinstall --no-deps -e enterprise/ + + - name: Generate Prisma client + env: + PRISMA_BINARY_CACHE_DIR: ${{ runner.temp }}/prisma-cache + run: | + poetry run pip install nodejs-wheel-binaries==24.13.1 + poetry run prisma generate --schema litellm/proxy/schema.prisma + + - name: Run tests + env: + TEST_PATH: ${{ inputs.test-path }} + MAX_FAILURES: ${{ inputs.max-failures }} + WORKERS: ${{ inputs.workers }} + RERUNS: ${{ inputs.reruns }} + run: | + poetry run pytest ${TEST_PATH} \ + --tb=short -vv \ + --maxfail="${MAX_FAILURES}" \ + -n "${WORKERS}" \ + --reruns "${RERUNS}" \ + --reruns-delay 1 \ + --dist=loadscope \ + --durations=20 diff --git a/.github/workflows/test-unit-core-utils.yml b/.github/workflows/test-unit-core-utils.yml new file mode 100644 index 00000000000..e984aaf54ee --- /dev/null +++ b/.github/workflows/test-unit-core-utils.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Core Utilities" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/test_litellm/litellm_core_utils" + workers: 2 + reruns: 1 diff --git a/.github/workflows/test-unit-documentation.yml b/.github/workflows/test-unit-documentation.yml new file mode 100644 index 00000000000..c241880d7d6 --- /dev/null +++ b/.github/workflows/test-unit-documentation.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Documentation Validation" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/documentation_tests" + workers: 2 + reruns: 1 diff --git a/.github/workflows/test-unit-enterprise-routing.yml b/.github/workflows/test-unit-enterprise-routing.yml new file mode 100644 index 00000000000..2c14e21a7db --- /dev/null +++ b/.github/workflows/test-unit-enterprise-routing.yml @@ -0,0 +1,24 @@ +name: "Unit Tests: Enterprise, Google GenAI & Routing" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: >- + tests/test_litellm/enterprise + tests/test_litellm/google_genai + tests/test_litellm/router_utils + tests/test_litellm/router_strategy + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-integrations.yml b/.github/workflows/test-unit-integrations.yml new file mode 100644 index 00000000000..ec6f4ad93be --- /dev/null +++ b/.github/workflows/test-unit-integrations.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Integrations (Callbacks & Logging)" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/test_litellm/integrations" + workers: 2 + reruns: 3 diff --git a/.github/workflows/test-unit-litellm-utils.yml b/.github/workflows/test-unit-litellm-utils.yml new file mode 100644 index 00000000000..840dd73b355 --- /dev/null +++ b/.github/workflows/test-unit-litellm-utils.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: LiteLLM Utilities" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/litellm_utils_tests" + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-llm-providers.yml b/.github/workflows/test-unit-llm-providers.yml new file mode 100644 index 00000000000..6c00272b0c8 --- /dev/null +++ b/.github/workflows/test-unit-llm-providers.yml @@ -0,0 +1,29 @@ +name: "Unit Tests: LLM Provider Transformations" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + vertex-ai: + name: Vertex AI + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/test_litellm/llms/vertex_ai" + workers: 1 + reruns: 2 + + other-providers: + name: All Other Providers + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/test_litellm/llms --ignore=tests/test_litellm/llms/vertex_ai" + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-misc.yml b/.github/workflows/test-unit-misc.yml new file mode 100644 index 00000000000..a29603a4601 --- /dev/null +++ b/.github/workflows/test-unit-misc.yml @@ -0,0 +1,31 @@ +name: "Unit Tests: MCP, Secrets, Containers & Misc" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: >- + tests/test_litellm/secret_managers + tests/test_litellm/a2a_protocol + tests/test_litellm/anthropic_interface + tests/test_litellm/completion_extras + tests/test_litellm/containers + tests/test_litellm/experimental_mcp_client + tests/test_litellm/images + tests/test_litellm/interactions + tests/test_litellm/passthrough + tests/test_litellm/vector_stores + tests/test_litellm/test_*.py + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-pass-through.yml b/.github/workflows/test-unit-pass-through.yml new file mode 100644 index 00000000000..a953c935e5d --- /dev/null +++ b/.github/workflows/test-unit-pass-through.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Pass-Through Endpoints" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/pass_through_unit_tests" + workers: 4 + reruns: 2 diff --git a/.github/workflows/test-unit-proxy-auth.yml b/.github/workflows/test-unit-proxy-auth.yml new file mode 100644 index 00000000000..6a1fec8b55c --- /dev/null +++ b/.github/workflows/test-unit-proxy-auth.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Proxy Auth & Key Management" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/test_litellm/proxy/auth tests/test_litellm/proxy/hooks tests/test_litellm/proxy/policy_engine tests/test_litellm/proxy/client" + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-proxy-endpoints.yml b/.github/workflows/test-unit-proxy-endpoints.yml new file mode 100644 index 00000000000..901437c1e2f --- /dev/null +++ b/.github/workflows/test-unit-proxy-endpoints.yml @@ -0,0 +1,35 @@ +name: "Unit Tests: Proxy API Endpoints" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: >- + tests/test_litellm/proxy/management_endpoints + tests/test_litellm/proxy/guardrails + tests/test_litellm/proxy/management_helpers + tests/test_litellm/proxy/anthropic_endpoints + tests/test_litellm/proxy/google_endpoints + tests/test_litellm/proxy/openai_files_endpoint + tests/test_litellm/proxy/response_api_endpoints + tests/test_litellm/proxy/image_endpoints + tests/test_litellm/proxy/vector_store_endpoints + tests/test_litellm/proxy/agent_endpoints + tests/test_litellm/proxy/discovery_endpoints + tests/test_litellm/proxy/health_endpoints + tests/test_litellm/proxy/public_endpoints + tests/test_litellm/proxy/prompts + tests/test_litellm/proxy/ui_crud_endpoints + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-proxy-infra.yml b/.github/workflows/test-unit-proxy-infra.yml new file mode 100644 index 00000000000..ce8ad396686 --- /dev/null +++ b/.github/workflows/test-unit-proxy-infra.yml @@ -0,0 +1,28 @@ +name: "Unit Tests: Proxy Infrastructure" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: >- + tests/test_litellm/proxy/db + tests/test_litellm/proxy/middleware + tests/test_litellm/proxy/spend_tracking + tests/test_litellm/proxy/pass_through_endpoints + tests/test_litellm/proxy/_experimental + tests/test_litellm/proxy/experimental + tests/test_litellm/proxy/common_utils + tests/test_litellm/proxy/test_*.py + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-proxy-legacy.yml b/.github/workflows/test-unit-proxy-legacy.yml new file mode 100644 index 00000000000..a9391137263 --- /dev/null +++ b/.github/workflows/test-unit-proxy-legacy.yml @@ -0,0 +1,96 @@ +name: "Unit Tests: Proxy Legacy Tests" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + runs-on: ubuntu-latest + timeout-minutes: 20 + strategy: + fail-fast: false + matrix: + test-group: + - name: "auth-and-jwt" + path: "tests/proxy_unit_tests/test_[a-j]*.py" + - name: "key-generation" + path: "tests/proxy_unit_tests/test_[k-o]*.py" + - name: "proxy-config" + path: "tests/proxy_unit_tests/test_prisma*.py tests/proxy_unit_tests/test_project*.py tests/proxy_unit_tests/test_prompt*.py tests/proxy_unit_tests/test_proxy_[c-r]*.py" + - name: "proxy-server" + path: "tests/proxy_unit_tests/test_proxy_server.py" + - name: "proxy-server-extras" + path: "tests/proxy_unit_tests/test_proxy_server_*.py tests/proxy_unit_tests/test_proxy_setting_guardrails.py" + - name: "proxy-utils" + path: "tests/proxy_unit_tests/test_proxy_utils.py" + - name: "proxy-token-counter" + path: "tests/proxy_unit_tests/test_proxy_token_counter.py" + - name: "proxy-response-and-misc" + path: "tests/proxy_unit_tests/test_[r-t]*.py" + - name: "proxy-user-auth-and-spend" + path: "tests/proxy_unit_tests/test_[u-z]*.py" + + name: ${{ matrix.test-group.name }} + + steps: + - uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0 + with: + persist-credentials: false + + - name: Set up Python + uses: actions/setup-python@a26af69be951a213d495a4c3e4e4022e16d87065 # v5.6.0 + with: + python-version: "3.12" + + - name: Install Poetry + run: pip install 'poetry==2.3.2' + + - name: Cache Poetry dependencies + uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4.3.0 + with: + path: | + ~/.cache/pypoetry + ~/.cache/pip + .venv + key: ${{ runner.os }}-poetry-${{ hashFiles('poetry.lock') }} + restore-keys: | + ${{ runner.os }}-poetry- + + - name: Install dependencies + run: | + poetry config virtualenvs.in-project true + poetry install --with dev,proxy-dev --extras "proxy semantic-router" + poetry run pip install google-genai==1.22.0 \ + google-cloud-aiplatform==1.115.0 fastapi-offline==1.7.3 python-multipart==0.0.22 openapi-core==0.23.0 + + - name: Setup litellm-enterprise + run: | + poetry run pip install --force-reinstall --no-deps -e enterprise/ + + - name: Generate Prisma client + env: + PRISMA_BINARY_CACHE_DIR: ${{ runner.temp }}/prisma-cache + run: | + poetry run pip install nodejs-wheel-binaries==24.13.1 + poetry run prisma generate --schema litellm/proxy/schema.prisma + + - name: Run tests - ${{ matrix.test-group.name }} + env: + TEST_PATH: ${{ matrix.test-group.path }} + run: | + poetry run pytest ${TEST_PATH} \ + --tb=short -vv \ + --maxfail=10 \ + -n 2 \ + --reruns 1 \ + --reruns-delay 1 \ + --dist=loadscope \ + --durations=20 diff --git a/.github/workflows/test-unit-responses-caching-types.yml b/.github/workflows/test-unit-responses-caching-types.yml new file mode 100644 index 00000000000..b78897a0462 --- /dev/null +++ b/.github/workflows/test-unit-responses-caching-types.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Responses, Caching & Types" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/test_litellm/responses tests/test_litellm/caching tests/test_litellm/types" + workers: 2 + reruns: 2 diff --git a/.github/workflows/test-unit-router.yml b/.github/workflows/test-unit-router.yml new file mode 100644 index 00000000000..bb5d5852864 --- /dev/null +++ b/.github/workflows/test-unit-router.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Router" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/router_unit_tests" + workers: 4 + reruns: 2 diff --git a/.github/workflows/test-unit-security.yml b/.github/workflows/test-unit-security.yml new file mode 100644 index 00000000000..ca6771f0d33 --- /dev/null +++ b/.github/workflows/test-unit-security.yml @@ -0,0 +1,20 @@ +name: "Unit Tests: Security" + +on: + pull_request: + branches: [main] + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} + cancel-in-progress: true + +jobs: + test: + uses: ./.github/workflows/_test-unit-base.yml + with: + test-path: "tests/proxy_security_tests" + workers: 1 + reruns: 1 From a34ed20901e96fdee82adcc7facc01f1082de1f5 Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Sat, 28 Mar 2026 10:07:32 -0700 Subject: [PATCH 2/3] [Infra] Fix job naming in reusable workflow callers Rename job keys from generic 'test' to descriptive names (e.g., 'core-utils', 'proxy-auth', 'router') so GitHub checks display as 'core-utils / run' instead of 'test / test'. Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/_test-unit-base.yml | 2 +- .github/workflows/test-unit-core-utils.yml | 2 +- .github/workflows/test-unit-documentation.yml | 2 +- .github/workflows/test-unit-enterprise-routing.yml | 2 +- .github/workflows/test-unit-integrations.yml | 2 +- .github/workflows/test-unit-litellm-utils.yml | 2 +- .github/workflows/test-unit-misc.yml | 2 +- .github/workflows/test-unit-pass-through.yml | 2 +- .github/workflows/test-unit-proxy-auth.yml | 2 +- .github/workflows/test-unit-proxy-endpoints.yml | 2 +- .github/workflows/test-unit-proxy-infra.yml | 2 +- .github/workflows/test-unit-responses-caching-types.yml | 2 +- .github/workflows/test-unit-router.yml | 2 +- .github/workflows/test-unit-security.yml | 2 +- 14 files changed, 14 insertions(+), 14 deletions(-) diff --git a/.github/workflows/_test-unit-base.yml b/.github/workflows/_test-unit-base.yml index d52a1eb34c3..7a62fd37c4c 100644 --- a/.github/workflows/_test-unit-base.yml +++ b/.github/workflows/_test-unit-base.yml @@ -32,7 +32,7 @@ permissions: contents: read jobs: - test: + run: runs-on: ubuntu-latest timeout-minutes: ${{ inputs.timeout-minutes }} diff --git a/.github/workflows/test-unit-core-utils.yml b/.github/workflows/test-unit-core-utils.yml index e984aaf54ee..2f3698fdf60 100644 --- a/.github/workflows/test-unit-core-utils.yml +++ b/.github/workflows/test-unit-core-utils.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + core-utils: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/test_litellm/litellm_core_utils" diff --git a/.github/workflows/test-unit-documentation.yml b/.github/workflows/test-unit-documentation.yml index c241880d7d6..9ea61ec424b 100644 --- a/.github/workflows/test-unit-documentation.yml +++ b/.github/workflows/test-unit-documentation.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + documentation: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/documentation_tests" diff --git a/.github/workflows/test-unit-enterprise-routing.yml b/.github/workflows/test-unit-enterprise-routing.yml index 2c14e21a7db..13ae3efedba 100644 --- a/.github/workflows/test-unit-enterprise-routing.yml +++ b/.github/workflows/test-unit-enterprise-routing.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + enterprise-routing: uses: ./.github/workflows/_test-unit-base.yml with: test-path: >- diff --git a/.github/workflows/test-unit-integrations.yml b/.github/workflows/test-unit-integrations.yml index ec6f4ad93be..2789f99d81c 100644 --- a/.github/workflows/test-unit-integrations.yml +++ b/.github/workflows/test-unit-integrations.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + integrations: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/test_litellm/integrations" diff --git a/.github/workflows/test-unit-litellm-utils.yml b/.github/workflows/test-unit-litellm-utils.yml index 840dd73b355..bc246d0cc50 100644 --- a/.github/workflows/test-unit-litellm-utils.yml +++ b/.github/workflows/test-unit-litellm-utils.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + litellm-utils: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/litellm_utils_tests" diff --git a/.github/workflows/test-unit-misc.yml b/.github/workflows/test-unit-misc.yml index a29603a4601..9228decd7cc 100644 --- a/.github/workflows/test-unit-misc.yml +++ b/.github/workflows/test-unit-misc.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + misc: uses: ./.github/workflows/_test-unit-base.yml with: test-path: >- diff --git a/.github/workflows/test-unit-pass-through.yml b/.github/workflows/test-unit-pass-through.yml index a953c935e5d..18cefebd763 100644 --- a/.github/workflows/test-unit-pass-through.yml +++ b/.github/workflows/test-unit-pass-through.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + pass-through: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/pass_through_unit_tests" diff --git a/.github/workflows/test-unit-proxy-auth.yml b/.github/workflows/test-unit-proxy-auth.yml index 6a1fec8b55c..e71821db701 100644 --- a/.github/workflows/test-unit-proxy-auth.yml +++ b/.github/workflows/test-unit-proxy-auth.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + proxy-auth: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/test_litellm/proxy/auth tests/test_litellm/proxy/hooks tests/test_litellm/proxy/policy_engine tests/test_litellm/proxy/client" diff --git a/.github/workflows/test-unit-proxy-endpoints.yml b/.github/workflows/test-unit-proxy-endpoints.yml index 901437c1e2f..caff3b3ae06 100644 --- a/.github/workflows/test-unit-proxy-endpoints.yml +++ b/.github/workflows/test-unit-proxy-endpoints.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + proxy-endpoints: uses: ./.github/workflows/_test-unit-base.yml with: test-path: >- diff --git a/.github/workflows/test-unit-proxy-infra.yml b/.github/workflows/test-unit-proxy-infra.yml index ce8ad396686..4dfbbe317ed 100644 --- a/.github/workflows/test-unit-proxy-infra.yml +++ b/.github/workflows/test-unit-proxy-infra.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + proxy-infra: uses: ./.github/workflows/_test-unit-base.yml with: test-path: >- diff --git a/.github/workflows/test-unit-responses-caching-types.yml b/.github/workflows/test-unit-responses-caching-types.yml index b78897a0462..7f3acac2803 100644 --- a/.github/workflows/test-unit-responses-caching-types.yml +++ b/.github/workflows/test-unit-responses-caching-types.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + responses-caching-types: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/test_litellm/responses tests/test_litellm/caching tests/test_litellm/types" diff --git a/.github/workflows/test-unit-router.yml b/.github/workflows/test-unit-router.yml index bb5d5852864..a10259c9b98 100644 --- a/.github/workflows/test-unit-router.yml +++ b/.github/workflows/test-unit-router.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + router: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/router_unit_tests" diff --git a/.github/workflows/test-unit-security.yml b/.github/workflows/test-unit-security.yml index ca6771f0d33..4064bc83921 100644 --- a/.github/workflows/test-unit-security.yml +++ b/.github/workflows/test-unit-security.yml @@ -12,7 +12,7 @@ concurrency: cancel-in-progress: true jobs: - test: + security: uses: ./.github/workflows/_test-unit-base.yml with: test-path: "tests/proxy_security_tests" From c717189ed2549b8dd28ec8f3ac4286e4aa748de9 Mon Sep 17 00:00:00 2001 From: Yuneng Jiang Date: Sat, 28 Mar 2026 10:16:19 -0700 Subject: [PATCH 3/3] [Infra] Remove workflows that require API keys or external services These test suites are not pure unit tests and don't belong in Phase 1: - litellm_utils_tests: health check tests need OPENAI_API_KEY - pass_through_unit_tests: tests hit real Anthropic API - router_unit_tests: tests call real OpenAI moderation endpoints - proxy_security_tests: requires DATABASE_URL (Postgres) - documentation_tests: requires docs directory at specific relative path These will be re-added in later phases with proper secret scoping. Co-Authored-By: Claude Opus 4.6 (1M context) --- .github/workflows/test-unit-documentation.yml | 20 ------------------- .github/workflows/test-unit-litellm-utils.yml | 20 ------------------- .github/workflows/test-unit-pass-through.yml | 20 ------------------- .github/workflows/test-unit-router.yml | 20 ------------------- .github/workflows/test-unit-security.yml | 20 ------------------- 5 files changed, 100 deletions(-) delete mode 100644 .github/workflows/test-unit-documentation.yml delete mode 100644 .github/workflows/test-unit-litellm-utils.yml delete mode 100644 .github/workflows/test-unit-pass-through.yml delete mode 100644 .github/workflows/test-unit-router.yml delete mode 100644 .github/workflows/test-unit-security.yml diff --git a/.github/workflows/test-unit-documentation.yml b/.github/workflows/test-unit-documentation.yml deleted file mode 100644 index 9ea61ec424b..00000000000 --- a/.github/workflows/test-unit-documentation.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: "Unit Tests: Documentation Validation" - -on: - pull_request: - branches: [main] - -permissions: - contents: read - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: true - -jobs: - documentation: - uses: ./.github/workflows/_test-unit-base.yml - with: - test-path: "tests/documentation_tests" - workers: 2 - reruns: 1 diff --git a/.github/workflows/test-unit-litellm-utils.yml b/.github/workflows/test-unit-litellm-utils.yml deleted file mode 100644 index bc246d0cc50..00000000000 --- a/.github/workflows/test-unit-litellm-utils.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: "Unit Tests: LiteLLM Utilities" - -on: - pull_request: - branches: [main] - -permissions: - contents: read - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: true - -jobs: - litellm-utils: - uses: ./.github/workflows/_test-unit-base.yml - with: - test-path: "tests/litellm_utils_tests" - workers: 2 - reruns: 2 diff --git a/.github/workflows/test-unit-pass-through.yml b/.github/workflows/test-unit-pass-through.yml deleted file mode 100644 index 18cefebd763..00000000000 --- a/.github/workflows/test-unit-pass-through.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: "Unit Tests: Pass-Through Endpoints" - -on: - pull_request: - branches: [main] - -permissions: - contents: read - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: true - -jobs: - pass-through: - uses: ./.github/workflows/_test-unit-base.yml - with: - test-path: "tests/pass_through_unit_tests" - workers: 4 - reruns: 2 diff --git a/.github/workflows/test-unit-router.yml b/.github/workflows/test-unit-router.yml deleted file mode 100644 index a10259c9b98..00000000000 --- a/.github/workflows/test-unit-router.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: "Unit Tests: Router" - -on: - pull_request: - branches: [main] - -permissions: - contents: read - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: true - -jobs: - router: - uses: ./.github/workflows/_test-unit-base.yml - with: - test-path: "tests/router_unit_tests" - workers: 4 - reruns: 2 diff --git a/.github/workflows/test-unit-security.yml b/.github/workflows/test-unit-security.yml deleted file mode 100644 index 4064bc83921..00000000000 --- a/.github/workflows/test-unit-security.yml +++ /dev/null @@ -1,20 +0,0 @@ -name: "Unit Tests: Security" - -on: - pull_request: - branches: [main] - -permissions: - contents: read - -concurrency: - group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} - cancel-in-progress: true - -jobs: - security: - uses: ./.github/workflows/_test-unit-base.yml - with: - test-path: "tests/proxy_security_tests" - workers: 1 - reruns: 1