mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-15 23:31:29 +00:00
Add an e2e suite at tests/e2e/mcp/ that proves MCP authorization over the api_key auth family. An admin registers an upstream MCP server through the management API (POST /v1/mcp/server, persisted in the DB and picked up without a restart) and queues its deletion. Two keys are created against that one server: one granted access through object_permission.mcp_servers and one with no MCP grant. The permitted key is a live control proving the upstream is reachable and the tool is callable, so a denial on the ungranted key is an authorization decision rather than a dead server. The denied key then sees none of the server's tools on tools/list and is refused a tools/call with a 403 access_denied. A deterministic self-hosted FastMCP upstream (add/multiply over streamable-http) is added to the e2e compose stack so the suite runs offline with a known tool set. KeyGenerateBody gains an optional typed object_permission so the shared gateway can create a key with an MCP grant.
187 lines
6.5 KiB
YAML
187 lines
6.5 KiB
YAML
# local setup to run e2e tests
|
|
configs:
|
|
mcp_upstream_server:
|
|
file: ../mcp_tests/mcp_e2e_upstream_server.py
|
|
litellm_config:
|
|
content: |
|
|
general_settings:
|
|
master_key: os.environ/LITELLM_MASTER_KEY
|
|
database_url: os.environ/DATABASE_URL
|
|
store_prompts_in_spend_logs: true
|
|
proxy_budget_rescheduler_min_time: 5
|
|
proxy_budget_rescheduler_max_time: 10
|
|
|
|
litellm_settings:
|
|
drop_params: true
|
|
num_retries: 3
|
|
request_timeout: 600
|
|
cache: true
|
|
cache_params:
|
|
type: redis
|
|
host: redis
|
|
port: 6379
|
|
# OTEL v2 trace destination for the logging suite's trace-completeness
|
|
# tests: the arize_phoenix preset is OTLP with a configurable endpoint
|
|
# (PHOENIX_COLLECTOR_HTTP_ENDPOINT below points it at the jaeger service),
|
|
# so gen-AI spans export through a preset-owned provider - the code path
|
|
# where trace splits actually happen - with no cloud credentials needed.
|
|
callbacks: ["arize_phoenix", "datadog"]
|
|
|
|
router_settings:
|
|
routing_strategy: simple-shuffle
|
|
num_retries: 3
|
|
allowed_fails: 5
|
|
cooldown_time: 30
|
|
fallbacks:
|
|
- gemini-2.5-flash: ["gpt-5.5", "claude-haiku-4-5"]
|
|
|
|
finetune_settings:
|
|
- custom_llm_provider: openai
|
|
api_key: os.environ/OPENAI_API_KEY
|
|
|
|
files_settings:
|
|
- custom_llm_provider: openai
|
|
api_key: os.environ/OPENAI_API_KEY
|
|
- custom_llm_provider: azure
|
|
api_base: os.environ/AZURE_API_BASE
|
|
api_key: os.environ/AZURE_API_KEY
|
|
api_version: "2024-05-01-preview"
|
|
|
|
model_list:
|
|
- model_name: gpt-5.5
|
|
litellm_params:
|
|
model: openai/gpt-5.5
|
|
api_key: os.environ/OPENAI_API_KEY
|
|
|
|
- model_name: claude-haiku-4-5
|
|
litellm_params:
|
|
model: anthropic/claude-haiku-4-5
|
|
api_key: os.environ/ANTHROPIC_API_KEY
|
|
|
|
- model_name: gemini-2.5-flash
|
|
litellm_params:
|
|
model: gemini/gemini-2.5-flash
|
|
api_key: os.environ/GEMINI_API_KEY
|
|
|
|
- model_name: openai-text-embedding-3-small
|
|
litellm_params:
|
|
model: openai/text-embedding-3-small
|
|
api_key: os.environ/OPENAI_API_KEY
|
|
|
|
# v2 auto-router with the LLM complexity classifier. SIMPLE stays on the
|
|
# openai backend; every higher tier routes to the anthropic backend, so the
|
|
# served deployment (read back from the spend log's model) reveals whether
|
|
# the LLM classifier actually ran or silently fell back to heuristic scoring.
|
|
- model_name: complexity-smart-router
|
|
litellm_params:
|
|
model: auto_router/complexity_router
|
|
complexity_router_config:
|
|
classifier_type: llm
|
|
classifier_llm_config:
|
|
model: gpt-5.5
|
|
tiers:
|
|
SIMPLE: gpt-5.5
|
|
MEDIUM: claude-haiku-4-5
|
|
COMPLEX: claude-haiku-4-5
|
|
REASONING: claude-haiku-4-5
|
|
|
|
services:
|
|
litellm:
|
|
image: ghcr.io/berriai/litellm:main-latest
|
|
depends_on:
|
|
db:
|
|
condition: service_healthy
|
|
redis:
|
|
condition: service_healthy
|
|
jaeger:
|
|
condition: service_healthy
|
|
env_file: .env
|
|
environment:
|
|
LITELLM_MASTER_KEY: sk-1234
|
|
STORE_MODEL_IN_DB: "True"
|
|
# Real DataDog delivery (no local sink): the key comes from the
|
|
# environment - the cluster's secret manager injects it, locally
|
|
# tests/e2e/.env provides it. Tests read delivery back via the DataDog
|
|
# Logs Search API (DD_APP_KEY, test-side only - see logging/datadog_reader.py).
|
|
DD_API_KEY: ${DD_API_KEY:-}
|
|
DD_SITE: ${DD_SITE:-datadoghq.com}
|
|
LITELLM_OTEL_V2: "true"
|
|
PHOENIX_COLLECTOR_HTTP_ENDPOINT: http://jaeger:4318/v1/traces
|
|
PHOENIX_API_KEY: local-jaeger-noauth
|
|
DATABASE_URL: postgresql://litellm:litellm@db:5432/litellm
|
|
UI_USERNAME: admin
|
|
UI_PASSWORD: sk-1234
|
|
AWS_S3_BUCKET_NAME: ${AWS_S3_BUCKET_NAME:-${AWS_BATCH_S3_BUCKET:-}}
|
|
AWS_BATCH_S3_BUCKET: ${AWS_BATCH_S3_BUCKET:-${AWS_S3_BUCKET_NAME:-}}
|
|
AWS_BATCH_ROLE_ARN: ${AWS_BATCH_ROLE_ARN:-}
|
|
AWS_ACCESS_KEY_ID: ${AWS_ACCESS_KEY_ID:-}
|
|
AWS_SECRET_ACCESS_KEY: ${AWS_SECRET_ACCESS_KEY:-}
|
|
AWS_REGION: ${AWS_REGION:-us-east-1}
|
|
GCS_BUCKET_NAME: ${GCS_BUCKET_NAME:-}
|
|
VERTEXAI_PROJECT: ${VERTEXAI_PROJECT:-}
|
|
VERTEXAI_CREDENTIALS: ${VERTEXAI_CREDENTIALS:-}
|
|
GOOGLE_APPLICATION_CREDENTIALS: ${GOOGLE_APPLICATION_CREDENTIALS:-}
|
|
MISTRAL_API_KEY: ${MISTRAL_API_KEY:-}
|
|
AZURE_API_BASE: ${AZURE_API_BASE:-}
|
|
AZURE_API_KEY: ${AZURE_API_KEY:-}
|
|
AZURE_AI_API_BASE: ${AZURE_AI_API_BASE:-}
|
|
AZURE_AI_API_KEY: ${AZURE_AI_API_KEY:-}
|
|
ports:
|
|
- "4000:4000"
|
|
configs:
|
|
- source: litellm_config
|
|
target: /app/config.yaml
|
|
command: ["--config", "/app/config.yaml", "--port", "4000"]
|
|
|
|
# deterministic self-hosted upstream MCP server (FastMCP add/multiply over
|
|
# streamable-http), reachable by the litellm container at mcp-upstream:8090/mcp.
|
|
# Not a depends_on of litellm on purpose: only the mcp suite needs it, and it
|
|
# boots long before the proxy is live, so it must not gate the other suites'
|
|
# stack. The suite registers it through /v1/mcp/server at test time.
|
|
mcp-upstream:
|
|
image: ghcr.io/berriai/litellm:main-latest
|
|
entrypoint: ["python3", "/app/mcp_upstream_server.py"]
|
|
environment:
|
|
MCP_HOST: 0.0.0.0
|
|
MCP_PORT: "8090"
|
|
configs:
|
|
- source: mcp_upstream_server
|
|
target: /app/mcp_upstream_server.py
|
|
healthcheck:
|
|
test: ["CMD", "python3", "-c", "import socket; socket.create_connection(('127.0.0.1', 8090), 2).close()"]
|
|
interval: 3s
|
|
timeout: 3s
|
|
retries: 40
|
|
|
|
# throwaway db
|
|
db:
|
|
image: postgres:16
|
|
environment:
|
|
POSTGRES_USER: litellm
|
|
POSTGRES_PASSWORD: litellm
|
|
POSTGRES_DB: litellm
|
|
healthcheck:
|
|
test: ["CMD-SHELL", "pg_isready -U litellm"]
|
|
interval: 3s
|
|
timeout: 3s
|
|
retries: 20
|
|
|
|
redis:
|
|
image: redis:7
|
|
healthcheck:
|
|
test: ["CMD", "redis-cli", "ping"]
|
|
interval: 3s
|
|
timeout: 3s
|
|
retries: 20
|
|
|
|
# throwaway OTEL trace destination (OTLP ingest on 4318 inside the network,
|
|
# query API on host 16686 for test read-back; see E2E_OTEL_QUERY_URL)
|
|
jaeger:
|
|
image: jaegertracing/all-in-one:1.62.0
|
|
ports:
|
|
- "16686:16686"
|
|
healthcheck:
|
|
test: ["CMD", "wget", "-qO-", "http://localhost:14269/"]
|
|
interval: 3s
|
|
timeout: 3s
|
|
retries: 20
|