mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-02 02:11:58 +00:00
* fix(secrets): verify provider API request and payload contracts * wip * fix(secrets): unify backend reads and route secret resolution * feat(secrets): bind built-in managers to retained Rust backends * refactor(secrets): centralize catalog dispatch and native binding * test(secrets): split provider integration tests * refactor(secrets): enforce cache and rotation contracts * test(secrets): stub parent packages in failing resolver fixture Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * refactor(secrets): pass manager settings through the interop boundary Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): align cloud KMS auth and harden provider reads * ci(rust): raise native wheel size gate to 40 MB for secrets backends Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(proxy): treat unset google kms flag as disabled like the old loader Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve certificate credentials and disabled KMS flags * test(secrets): cover certificate validation and bounded auth retries * test(secrets): cover Python dispatch without the native extension * test(proxy): skip legacy secret manager cases when the optional SDK is missing Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): port Python parity tests and preserve provider behavior * fix(secrets): store the captured native config without setattr to satisfy the strict lint budget Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve missing Azure manager values Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * test(secrets): pin typed values and recovery failure precedence * refactor(secrets): organize provider internals and behavioral test suites * refactor(secrets): simplify recovery and isolate Python compatibility * fix(secrets): distinguish Azure callback absence from HTTP not found * fix(secrets): preserve Python AWS read results at the bridge * fix(secrets): route public reads through the native catalog bridge * fix(secrets): keep JSON selection outside the bridge Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve provider JSON reads at the bridge Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve Python primary JSON semantics Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> * fix(secrets): preserve CyberArk mutation behavior through the native bridge * docs(secrets): record public API replacement gaps * refactor(secrets): share Vault write payload preparation * feat(secrets): route Vault mutations through the native bridge * fix(secrets): preserve typed Vault rotation failures * refactor(secrets): move Python dispatch into bridge * refactor(secrets): move CyberArk Python policy into bridge * refactor(secrets): move Vault Python policy into bridge * test(secrets): assert Vault rotation request paths * fix(secrets): keep bridge JSON interop centralized Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Yujong Lee <yujong@berri.ai> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
73 lines
2 KiB
Rust
73 lines
2 KiB
Rust
use std::{collections::HashMap, sync::Arc};
|
|
|
|
use futures_util::future::{BoxFuture, try_join_all};
|
|
use litellm_core_utils::settings::Lookup;
|
|
|
|
use crate::{Error, SecretResolver, SecretValue};
|
|
|
|
pub type Secrets = Arc<dyn Lookup + Send + Sync>;
|
|
|
|
pub trait SecretSource: Send + Sync {
|
|
fn get_secret_str<'a>(
|
|
&'a self,
|
|
name: &'a str,
|
|
) -> BoxFuture<'a, Result<Option<SecretValue>, Error>>;
|
|
|
|
fn resolve<'a>(&'a self, names: &'a [&str]) -> BoxFuture<'a, Result<Secrets, Error>> {
|
|
Box::pin(async move {
|
|
let values = try_join_all(names.iter().map(|name| async move {
|
|
self.get_secret_str(name)
|
|
.await
|
|
.map(|value| ((*name).to_owned(), value))
|
|
}))
|
|
.await?
|
|
.into_iter()
|
|
.collect();
|
|
Ok(Arc::new(SecretSnapshot { values }) as Secrets)
|
|
})
|
|
}
|
|
}
|
|
|
|
impl SecretSource for SecretResolver {
|
|
fn get_secret_str<'a>(
|
|
&'a self,
|
|
name: &'a str,
|
|
) -> BoxFuture<'a, Result<Option<SecretValue>, Error>> {
|
|
Box::pin(SecretResolver::get_secret_str(self, name, None))
|
|
}
|
|
}
|
|
|
|
#[derive(Default)]
|
|
pub struct EnvironmentSecrets(SecretResolver);
|
|
|
|
impl EnvironmentSecrets {
|
|
pub fn python_compatible() -> Self {
|
|
Self(SecretResolver::new_python_compatible(
|
|
Arc::new(crate::SecretManagerState::default()),
|
|
Arc::new(litellm_core_utils::settings::ProcessEnvironment),
|
|
crate::OidcResolver::default(),
|
|
))
|
|
}
|
|
}
|
|
|
|
impl SecretSource for EnvironmentSecrets {
|
|
fn get_secret_str<'a>(
|
|
&'a self,
|
|
name: &'a str,
|
|
) -> BoxFuture<'a, Result<Option<SecretValue>, Error>> {
|
|
Box::pin(self.0.get_secret_str(name, None))
|
|
}
|
|
}
|
|
|
|
struct SecretSnapshot {
|
|
values: HashMap<String, Option<SecretValue>>,
|
|
}
|
|
|
|
impl Lookup for SecretSnapshot {
|
|
fn get(&self, name: &str) -> Option<String> {
|
|
self.values
|
|
.get(name)
|
|
.and_then(Option::as_ref)
|
|
.map(|value| value.expose().to_owned())
|
|
}
|
|
}
|