From a9cd1fc7645b88a15ae58d648da9ba635f36ad5f Mon Sep 17 00:00:00 2001 From: Ishaan Jaff Date: Wed, 6 May 2026 15:31:17 -0700 Subject: [PATCH] fix(cloud-agents): default LITELLM_CLOUD_AGENT_MOCK_AWS to off (Greptile P1) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Previously the test-connection endpoint defaulted to mock-on, so a fresh production proxy would silently return a synthetic success for any non-empty AWS access key. Operators saving incorrect credentials would only discover the failure later when VMs failed to launch. Default is now "0" — operators must set LITELLM_CLOUD_AGENT_MOCK_AWS=1 explicitly to opt into the mock path during local development. Also adds an inline comment on _build_update_payload's `is not None` guard so a future contributor doesn't silently drop `False` / `0` updates by switching to truthy comparison. --- .../vm_config_endpoints.py | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/litellm/proxy/agent_settings_endpoints/vm_config_endpoints.py b/litellm/proxy/agent_settings_endpoints/vm_config_endpoints.py index f676a775f5d..765fd0d5985 100644 --- a/litellm/proxy/agent_settings_endpoints/vm_config_endpoints.py +++ b/litellm/proxy/agent_settings_endpoints/vm_config_endpoints.py @@ -159,6 +159,11 @@ def _build_update_payload( ) for field in plain_fields: value = getattr(body, field, None) + # Use `is not None` (not truthiness): `False`, `0`, and `""` are + # all valid values that callers may legitimately want to write + # (e.g. disabling warm pool with `warm_pool_enabled=False`, + # zeroing `warm_pool_size`). A future contributor adding a field + # here should keep this guard so those updates don't get dropped. if value is not None: payload[field] = value @@ -322,8 +327,15 @@ def _mock_caller_identity(creds: Dict[str, Optional[str]]) -> TestConnectionResp def _aws_mock_enabled() -> bool: - """Real STS is owned by B0. Mock by default until that ticket closes.""" - return os.getenv("LITELLM_CLOUD_AGENT_MOCK_AWS", "1") == "1" + """Whether `test-connection` should return a synthetic mock response + instead of calling the real `sts:GetCallerIdentity`. + + Defaults to OFF — a fresh production proxy must always validate AWS + credentials against STS, never silently return success for invalid + creds. Set `LITELLM_CLOUD_AGENT_MOCK_AWS=1` explicitly to opt into the + mock path during local development / tests. + """ + return os.getenv("LITELLM_CLOUD_AGENT_MOCK_AWS", "0") == "1" @router.post(