From c896c9787635ae6ffef57e63c6c8c9abca651c33 Mon Sep 17 00:00:00 2001 From: Ryan Crabbe Date: Sat, 28 Feb 2026 15:17:28 -0800 Subject: [PATCH] Validate Hashicorp Vault config before saving --- .../config_override_endpoints.py | 22 +++++++++++++++++++ 1 file changed, 22 insertions(+) diff --git a/litellm/proxy/management_endpoints/config_override_endpoints.py b/litellm/proxy/management_endpoints/config_override_endpoints.py index 84e91a8748d..cdd43d0c33c 100644 --- a/litellm/proxy/management_endpoints/config_override_endpoints.py +++ b/litellm/proxy/management_endpoints/config_override_endpoints.py @@ -135,6 +135,28 @@ async def update_hashicorp_vault_config( config_data = config.model_dump(exclude_none=True) + # Validate that the config has enough fields to initialize + has_vault_addr = bool(config_data.get("vault_addr")) + has_token_auth = bool(config_data.get("vault_token")) + has_approle_auth = bool( + config_data.get("approle_role_id") and config_data.get("approle_secret_id") + ) + + if not has_vault_addr: + raise HTTPException( + status_code=400, + detail={"error": "vault_addr is required"}, + ) + + if not has_token_auth and not has_approle_auth: + raise HTTPException( + status_code=400, + detail={ + "error": "At least one authentication method is required: " + "provide vault_token, or both approle_role_id and approle_secret_id" + }, + ) + # Set environment variables for field_name, value in config_data.items(): env_var_name = HASHICORP_ENV_VAR_MAPPING.get(field_name)