mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-28 01:32:17 +00:00
* fix(secrets): verify provider API request and payload contracts * wip * fix(secrets): unify backend reads and route secret resolution * feat(secrets): bind built-in managers to retained Rust backends * refactor(secrets): centralize catalog dispatch and native binding * test(secrets): split provider integration tests * refactor(secrets): enforce cache and rotation contracts * test(secrets): stub parent packages in failing resolver fixture Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * refactor(secrets): pass manager settings through the interop boundary Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): align cloud KMS auth and harden provider reads * ci(rust): raise native wheel size gate to 40 MB for secrets backends Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(proxy): treat unset google kms flag as disabled like the old loader Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve certificate credentials and disabled KMS flags * test(secrets): cover certificate validation and bounded auth retries * test(secrets): cover Python dispatch without the native extension * test(proxy): skip legacy secret manager cases when the optional SDK is missing Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): port Python parity tests and preserve provider behavior * fix(secrets): store the captured native config without setattr to satisfy the strict lint budget Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve missing Azure manager values Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * test(secrets): pin typed values and recovery failure precedence * refactor(secrets): organize provider internals and behavioral test suites * refactor(secrets): simplify recovery and isolate Python compatibility * fix(secrets): distinguish Azure callback absence from HTTP not found * fix(secrets): preserve Python AWS read results at the bridge * fix(secrets): route public reads through the native catalog bridge * fix(secrets): keep JSON selection outside the bridge Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve provider JSON reads at the bridge Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve Python primary JSON semantics Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve CyberArk mutation behavior through the native bridge * docs(secrets): record public API replacement gaps * refactor(secrets): share Vault write payload preparation * feat(secrets): route Vault mutations through the native bridge * fix(secrets): preserve typed Vault rotation failures * refactor(secrets): move Python dispatch into bridge * refactor(secrets): move CyberArk Python policy into bridge * refactor(secrets): move Vault Python policy into bridge * test(secrets): assert Vault rotation request paths * fix(secrets): keep bridge JSON interop centralized Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Yujong Lee <yujong@berri.ai> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
101 lines
3.1 KiB
Rust
101 lines
3.1 KiB
Rust
use aws_sdk_kms::{
|
|
Client,
|
|
config::{BehaviorVersion, Credentials, Region, retry::RetryConfig},
|
|
};
|
|
use base64::{Engine, engine::general_purpose::STANDARD};
|
|
use litellm_secrets_aws::{AwsKms, Error, load_aws_kms};
|
|
use litellm_secrets_types::KeyManagementSettings;
|
|
use rstest::rstest;
|
|
use wiremock::{
|
|
Mock, MockServer, ResponseTemplate,
|
|
matchers::{body_json, header},
|
|
};
|
|
|
|
#[rstest]
|
|
#[tokio::test]
|
|
async fn kms_decrypt_calls_the_sdk_without_applying_lookup_policy() {
|
|
let server = MockServer::start().await;
|
|
let plaintext = " private-value\n";
|
|
Mock::given(header("x-amz-target", "TrentService.Decrypt"))
|
|
.and(body_json(
|
|
serde_json::json!({"CiphertextBlob": STANDARD.encode("encrypted")}),
|
|
))
|
|
.respond_with(
|
|
ResponseTemplate::new(200)
|
|
.set_body_json(serde_json::json!({"Plaintext": STANDARD.encode(plaintext)})),
|
|
)
|
|
.expect(1)
|
|
.mount(&server)
|
|
.await;
|
|
let client = Client::from_conf(
|
|
aws_sdk_kms::Config::builder()
|
|
.behavior_version(BehaviorVersion::latest())
|
|
.region(Region::new("us-east-1"))
|
|
.credentials_provider(Credentials::new("test", "test", None, None, "test"))
|
|
.endpoint_url(server.uri())
|
|
.retry_config(RetryConfig::disabled())
|
|
.build(),
|
|
);
|
|
let manager = AwsKms::new(client);
|
|
assert_eq!(
|
|
manager.decrypt(b"encrypted".to_vec()).await.unwrap(),
|
|
plaintext.as_bytes()
|
|
);
|
|
}
|
|
|
|
#[rstest]
|
|
#[case::unset(None)]
|
|
#[case::disabled(Some(false))]
|
|
fn disabled_kms_loader_does_not_require_environment_configuration(#[case] enabled: Option<bool>) {
|
|
use std::sync::Arc;
|
|
assert!(
|
|
load_aws_kms(
|
|
enabled,
|
|
&KeyManagementSettings::default(),
|
|
Arc::new(|_: &str| None)
|
|
)
|
|
.unwrap()
|
|
.is_none()
|
|
);
|
|
}
|
|
|
|
#[rstest]
|
|
#[case::settings(Some("configured-region"), None, None)]
|
|
#[case::region_name(None, Some("AWS_REGION_NAME"), Some("environment-region"))]
|
|
#[case::region(None, Some("AWS_REGION"), Some("environment-region"))]
|
|
#[case::default_region(None, Some("AWS_DEFAULT_REGION"), Some("environment-region"))]
|
|
fn enabled_kms_loader_accepts_supported_region_sources(
|
|
#[case] configured_region: Option<&'static str>,
|
|
#[case] environment_region_name: Option<&'static str>,
|
|
#[case] environment_region: Option<&'static str>,
|
|
) {
|
|
use std::sync::Arc;
|
|
let settings = KeyManagementSettings {
|
|
aws_region_name: configured_region.map(str::to_owned),
|
|
..KeyManagementSettings::default()
|
|
};
|
|
let environment = Arc::new(move |name: &str| {
|
|
(Some(name) == environment_region_name)
|
|
.then(|| environment_region.map(str::to_owned))
|
|
.flatten()
|
|
});
|
|
|
|
assert!(
|
|
load_aws_kms(Some(true), &settings, environment)
|
|
.unwrap()
|
|
.is_some()
|
|
);
|
|
}
|
|
|
|
#[rstest]
|
|
fn enabled_kms_loader_rejects_missing_region() {
|
|
use std::sync::Arc;
|
|
assert!(matches!(
|
|
load_aws_kms(
|
|
Some(true),
|
|
&KeyManagementSettings::default(),
|
|
Arc::new(|_: &str| None),
|
|
),
|
|
Err(Error::MissingRegion)
|
|
));
|
|
}
|