mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-29 01:42:19 +00:00
Some checks are pending
LiteLLM Rust / rust-lint (push) Waiting to run
LiteLLM Rust / rust-test (push) Waiting to run
LiteLLM Rust / rust-wheel (push) Waiting to run
Terraform Provider / gofmt, vet, build, test (push) Waiting to run
Terraform Provider / Provider endpoints vs proxy OpenAPI schema (push) Waiting to run
Bumps the github-actions group with 21 updates in the / directory: | Package | From | To | | --- | --- | --- | | [actions/checkout](https://github.com/actions/checkout) | `4.2.2` | `7.0.1` | | [actions/setup-python](https://github.com/actions/setup-python) | `5.6.0` | `7.0.0` | | [actions/cache](https://github.com/actions/cache) | `4.3.0` | `6.1.0` | | [actions/upload-artifact](https://github.com/actions/upload-artifact) | `4.6.1` | `7.0.1` | | [actions/download-artifact](https://github.com/actions/download-artifact) | `4.2.1` | `8.0.1` | | [codecov/codecov-action](https://github.com/codecov/codecov-action) | `5.5.4` | `7.1.1` | | [actions/setup-node](https://github.com/actions/setup-node) | `4.4.0` | `7.0.0` | | [github/codeql-action/init](https://github.com/github/codeql-action) | `3.34.1` | `4.38.2` | | [github/codeql-action/analyze](https://github.com/github/codeql-action) | `3.34.1` | `4.38.2` | | [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) | `3.34.1` | `4.38.2` | | [CodSpeedHQ/action](https://github.com/codspeedhq/action) | `4.12.1` | `5.2.1` | | [actions/github-script](https://github.com/actions/github-script) | `7.0.1` | `9.0.0` | | [openai/codex-action](https://github.com/openai/codex-action) | `1.9` | `1.12` | | [azure/setup-helm](https://github.com/azure/setup-helm) | `4.3.1` | `5.0.1` | | [ossf/scorecard-action](https://github.com/ossf/scorecard-action) | `2.4.1` | `2.4.4` | | [actions/stale](https://github.com/actions/stale) | `8.0.0` | `11.0.0` | | [aws-actions/configure-aws-credentials](https://github.com/aws-actions/configure-aws-credentials) | `6.2.0` | `6.3.0` | | [taiki-e/install-action](https://github.com/taiki-e/install-action) | `2.87.8` | `2.87.21` | | [hashicorp/setup-terraform](https://github.com/hashicorp/setup-terraform) | `3.1.2` | `4.0.1` | | [actions/setup-go](https://github.com/actions/setup-go) | `6.2.0` | `7.0.0` | | [zizmorcore/zizmor-action](https://github.com/zizmorcore/zizmor-action) | `0.5.6` | `0.6.4` | Updates `actions/checkout` from 4.2.2 to 7.0.1 - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](https://github.com/actions/checkout/compare/v4.2.2...3d3c42e5aac5ba805825da76410c181273ba90b1) Updates `actions/setup-python` from 5.6.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](a26af69be9...5fda3b95a4) Updates `actions/cache` from 4.3.0 to 6.1.0 - [Release notes](https://github.com/actions/cache/releases) - [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md) - [Commits](0057852bfa...55cc834586) Updates `actions/upload-artifact` from 4.6.1 to 7.0.1 - [Release notes](https://github.com/actions/upload-artifact/releases) - [Commits](4cec3d8aa0...043fb46d1a) Updates `actions/download-artifact` from 4.2.1 to 8.0.1 - [Release notes](https://github.com/actions/download-artifact/releases) - [Commits](95815c38cf...3e5f45b2cf) Updates `codecov/codecov-action` from 5.5.4 to 7.1.1 - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](75cd11691c...303a32d7a5) Updates `actions/setup-node` from 4.4.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-node/releases) - [Commits](https://github.com/actions/setup-node/compare/v4.4.0...820762786026740c76f36085b0efc47a31fe5020) Updates `github/codeql-action/init` from 3.34.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](ebcb5b36de...2892aa5e19) Updates `github/codeql-action/analyze` from 3.34.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](ebcb5b36de...2892aa5e19) Updates `github/codeql-action/upload-sarif` from 3.34.1 to 4.38.2 - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](https://github.com/github/codeql-action/compare/v3.34.1...2892aa5e19bbd11bc0cff5427e3b750a04d9e3c2) Updates `CodSpeedHQ/action` from 4.12.1 to 5.2.1 - [Release notes](https://github.com/codspeedhq/action/releases) - [Changelog](https://github.com/CodSpeedHQ/action/blob/main/CHANGELOG.md) - [Commits](1c8ae48435...373d686892) Updates `actions/github-script` from 7.0.1 to 9.0.0 - [Release notes](https://github.com/actions/github-script/releases) - [Commits](https://github.com/actions/github-script/compare/v7.0.1...3a2844b7e9c422d3c10d287c895573f7108da1b3) Updates `openai/codex-action` from 1.9 to 1.12 - [Changelog](https://github.com/openai/codex-action/blob/main/CHANGELOG.md) - [Commits](10cb888d2e...86365089eb) Updates `azure/setup-helm` from 4.3.1 to 5.0.1 - [Release notes](https://github.com/azure/setup-helm/releases) - [Changelog](https://github.com/Azure/setup-helm/blob/main/CHANGELOG.md) - [Commits](1a275c3b69...9bc31f4ebc) Updates `ossf/scorecard-action` from 2.4.1 to 2.4.4 - [Release notes](https://github.com/ossf/scorecard-action/releases) - [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md) - [Commits](f49aabe0b5...2d1146689b) Updates `actions/stale` from 8.0.0 to 11.0.0 - [Release notes](https://github.com/actions/stale/releases) - [Changelog](https://github.com/actions/stale/blob/main/CHANGELOG.md) - [Commits](1160a22402...4391f3da66) Updates `aws-actions/configure-aws-credentials` from 6.2.0 to 6.3.0 - [Release notes](https://github.com/aws-actions/configure-aws-credentials/releases) - [Changelog](https://github.com/aws-actions/configure-aws-credentials/blob/main/CHANGELOG.md) - [Commits](e7f100cf4c...e1253824e5) Updates `taiki-e/install-action` from 2.87.8 to 2.87.21 - [Release notes](https://github.com/taiki-e/install-action/releases) - [Changelog](https://github.com/taiki-e/install-action/blob/main/CHANGELOG.md) - [Commits](d438492cf8...4cef1412cc) Updates `hashicorp/setup-terraform` from 3.1.2 to 4.0.1 - [Release notes](https://github.com/hashicorp/setup-terraform/releases) - [Changelog](https://github.com/hashicorp/setup-terraform/blob/main/CHANGELOG.md) - [Commits](b9cd54a3c3...dfe3c3f878) Updates `actions/setup-go` from 6.2.0 to 7.0.0 - [Release notes](https://github.com/actions/setup-go/releases) - [Commits](7a3fe6cf4c...b7ad1dad31) Updates `zizmorcore/zizmor-action` from 0.5.6 to 0.6.4 - [Release notes](https://github.com/zizmorcore/zizmor-action/releases) - [Commits](5f14fd08f7...cc914d7f37) --- updated-dependencies: - dependency-name: actions/cache dependency-version: 6.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/checkout dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/download-artifact dependency-version: 8.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/github-script dependency-version: 9.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-go dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-node dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/setup-python dependency-version: 7.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/stale dependency-version: 11.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: actions/upload-artifact dependency-version: 7.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: aws-actions/configure-aws-credentials dependency-version: 6.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: azure/setup-helm dependency-version: 5.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: codecov/codecov-action dependency-version: 7.1.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: CodSpeedHQ/action dependency-version: 5.2.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action/analyze dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action/init dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: github/codeql-action/upload-sarif dependency-version: 4.38.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: hashicorp/setup-terraform dependency-version: 4.0.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: github-actions - dependency-name: openai/codex-action dependency-version: '1.12' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions - dependency-name: ossf/scorecard-action dependency-version: 2.4.4 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: taiki-e/install-action dependency-version: 2.87.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: github-actions - dependency-name: zizmorcore/zizmor-action dependency-version: 0.6.4 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: github-actions ... Signed-off-by: dependabot[bot] <support@github.com>
180 lines
7.2 KiB
YAML
180 lines
7.2 KiB
YAML
name: MCP OAuth happy path
|
|
|
|
on:
|
|
pull_request:
|
|
paths:
|
|
- '.github/workflows/test-mcp-oauth-e2e.yml'
|
|
- '.github/e2e-stack/**'
|
|
- 'tests/e2e/*.py'
|
|
- 'tests/e2e/pytest.ini'
|
|
- 'tests/e2e/idp_realm.json'
|
|
- 'tests/e2e/mcp/**'
|
|
- 'litellm/experimental_mcp_client/**'
|
|
- 'litellm/proxy/_experimental/mcp_server/**'
|
|
- 'litellm/proxy/auth/**'
|
|
- 'litellm/proxy/management_endpoints/mcp_management_endpoints.py'
|
|
- 'litellm/proxy/_types.py'
|
|
- 'litellm/types/mcp_server/mcp_server_manager.py'
|
|
- 'litellm/proxy/management_endpoints/*sso*.py'
|
|
- 'litellm/proxy/management_endpoints/sso/**'
|
|
- 'litellm/proxy/common_utils/encrypt_decrypt_utils.py'
|
|
- 'litellm/proxy/proxy_server.py'
|
|
- 'litellm/proxy/schema.prisma'
|
|
- 'ui/litellm-dashboard/src/app/connect/**'
|
|
- 'ui/litellm-dashboard/src/app/mcp/oauth/**'
|
|
- 'pyproject.toml'
|
|
- 'uv.lock'
|
|
workflow_dispatch:
|
|
|
|
permissions: {}
|
|
|
|
concurrency:
|
|
group: mcp-oauth-${{ github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
oauth:
|
|
if: github.event_name == 'workflow_dispatch' || github.event.pull_request.head.repo.full_name == github.repository
|
|
runs-on: ubuntu-latest
|
|
environment: e2e-changed
|
|
timeout-minutes: 45
|
|
permissions:
|
|
contents: read
|
|
id-token: write
|
|
services:
|
|
postgres:
|
|
image: postgres:16.6
|
|
env:
|
|
POSTGRES_USER: litellm
|
|
POSTGRES_PASSWORD: dbpassword9090
|
|
POSTGRES_DB: litellm
|
|
ports:
|
|
- 5432:5432
|
|
options: >-
|
|
--health-cmd "pg_isready -U litellm"
|
|
--health-interval 5s
|
|
--health-timeout 5s
|
|
--health-retries 10
|
|
env:
|
|
DATABASE_HOST: 127.0.0.1
|
|
DATABASE_PORT: '5432'
|
|
DATABASE_USER: litellm
|
|
DATABASE_PASSWORD: dbpassword9090
|
|
DATABASE_NAME: litellm
|
|
DATABASE_URL: postgresql://litellm:dbpassword9090@127.0.0.1:5432/litellm
|
|
E2E_KEYCLOAK_URL: http://127.0.0.1:8081
|
|
E2E_KEYCLOAK_ADMIN_USER: admin
|
|
E2E_KEYCLOAK_ADMIN_PASSWORD: e2e-ephemeral-idp-not-a-secret
|
|
E2E_FIXTURE_MODE: live
|
|
E2E_PROVIDER_CACHE: '0'
|
|
E2E_MCP_OAUTH_LIVE: '1'
|
|
E2E_REQUIRED_TEST_COUNT: '4'
|
|
steps:
|
|
- name: Checkout the tested source
|
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
ref: ${{ github.event.pull_request.head.sha || github.sha }}
|
|
persist-credentials: false
|
|
|
|
- name: Require and materialize the upstream login
|
|
env:
|
|
STORAGE_STATE: ${{ secrets.E2E_LINEAR_STORAGE_STATE_B64 }}
|
|
run: |
|
|
umask 077
|
|
python3 - <<'PY'
|
|
import base64
|
|
import json
|
|
import os
|
|
import secrets
|
|
from pathlib import Path
|
|
encoded = os.environ.get("STORAGE_STATE", "")
|
|
if not encoded:
|
|
raise SystemExit("E2E_LINEAR_STORAGE_STATE_B64 is required; capture and provision a test-account login")
|
|
state = json.loads(base64.b64decode(encoded, validate=True))
|
|
if not isinstance(state, dict) or not state.get("cookies"):
|
|
raise SystemExit("The captured login must contain browser cookies")
|
|
directory = Path(os.environ["RUNNER_TEMP"]) / "mcp-oauth-private"
|
|
directory.mkdir(mode=0o700)
|
|
path = directory / "linear-state.json"
|
|
path.write_text(json.dumps(state))
|
|
with open(os.environ["GITHUB_ENV"], "a") as output:
|
|
output.write(f"E2E_LINEAR_STORAGE_STATE={path}\n")
|
|
for name in ("LITELLM_MASTER_KEY", "LITELLM_SALT_KEY"):
|
|
value = "sk-e2e-" + secrets.token_hex(24)
|
|
print(f"::add-mask::{value}")
|
|
output.write(f"{name}={value}\n")
|
|
PY
|
|
|
|
- uses: actions/setup-python@5fda3b95a4ea91299a34e894583c3862153e4b97 # v7.0.0
|
|
with:
|
|
python-version: '3.13'
|
|
- uses: ./.github/actions/setup-uv-with-retries
|
|
with:
|
|
version: '0.10.9'
|
|
- uses: ./.github/actions/cache-cargo-build
|
|
- name: Install the frozen E2E environment
|
|
run: |
|
|
.github/scripts/uv_sync_with_retries.sh --frozen --extra proxy --extra proxy-runtime --extra extra_proxy --group ci --group proxy-dev --group e2e-dev
|
|
uv run --no-sync python scripts/prisma_generate_if_needed.py
|
|
uv run --no-sync playwright install --with-deps chromium
|
|
|
|
- name: Configure license access
|
|
id: aws
|
|
uses: aws-actions/configure-aws-credentials@e1253824e5c10ff9df46874f81ed3ec929e19cfd # v6.3.0
|
|
with:
|
|
role-to-assume: ${{ vars.E2E_AWS_ROLE_TO_ASSUME }}
|
|
aws-region: us-east-1
|
|
role-session-name: mcp-oauth-${{ github.run_id }}
|
|
role-duration-seconds: 900
|
|
output-env-credentials: false
|
|
output-credentials: true
|
|
- name: Load the E2E license
|
|
env:
|
|
AWS_ACCESS_KEY_ID: ${{ steps.aws.outputs.aws-access-key-id }}
|
|
AWS_SECRET_ACCESS_KEY: ${{ steps.aws.outputs.aws-secret-access-key }}
|
|
AWS_SESSION_TOKEN: ${{ steps.aws.outputs.aws-session-token }}
|
|
AWS_DEFAULT_REGION: us-east-1
|
|
run: |
|
|
license="$(aws secretsmanager get-secret-value --secret-id litellm-e2e-changed-license --query SecretString --output text)"
|
|
test -n "${license}"
|
|
echo "::add-mask::${license}"
|
|
echo "LITELLM_LICENSE=${license}" >> "${GITHUB_ENV}"
|
|
|
|
- uses: actions/setup-node@820762786026740c76f36085b0efc47a31fe5020 # v7.0.0
|
|
with:
|
|
node-version-file: ui/litellm-dashboard/.nvmrc
|
|
- name: Build the gateway consent UI at the tested commit
|
|
run: |
|
|
cd ui/litellm-dashboard
|
|
../../scripts/with_dashboard_node.sh npm ci
|
|
../../scripts/with_dashboard_node.sh npm run build
|
|
mkdir -p ../../litellm/proxy/_experimental/out
|
|
cp -r out/. ../../litellm/proxy/_experimental/out/
|
|
find ../../litellm/proxy/_experimental/out -name '*.html' ! -name index.html | while read -r page; do
|
|
mkdir -p "${page%.html}"
|
|
mv "${page}" "${page%.html}/index.html"
|
|
done
|
|
|
|
- name: Prepare the isolated database and IdP
|
|
run: |
|
|
umask 077
|
|
bash .github/e2e-stack/start-idp.sh
|
|
uv run --no-sync python migrations/run.py > "${RUNNER_TEMP}/mcp-oauth-private/migrations.log" 2>&1
|
|
|
|
- name: Run every required OAuth variant without retries
|
|
run: |
|
|
umask 077
|
|
uv run --no-sync pytest -c tests/e2e/pytest.ini tests/e2e/mcp/test_mcp_oauth_happy_path_e2e.py \
|
|
--rootdir=. --reruns 0 --tb=short -o junit_family=xunit1 \
|
|
--junitxml="${RUNNER_TEMP}/mcp-oauth-private/results.xml" \
|
|
> "${RUNNER_TEMP}/mcp-oauth-private/pytest.log" 2>&1
|
|
- name: Report JUnit results and reject skipped or missing cases
|
|
if: always()
|
|
run: |
|
|
uv run --no-sync python .github/e2e-stack/assert_tests_ran.py \
|
|
"${RUNNER_TEMP}/mcp-oauth-private/results.xml" tests/e2e/mcp/test_mcp_oauth_happy_path_e2e.py
|
|
- name: Remove private login and logs
|
|
if: always()
|
|
run: |
|
|
docker rm -f e2e-keycloak >/dev/null 2>&1 || true
|
|
rm -rf "${RUNNER_TEMP}/mcp-oauth-private"
|