mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-28 01:32:17 +00:00
* test(e2e): add a HashiCorp Vault secret manager lane key_management_system had no end-to-end coverage: the Rust crates and the Python unit tests all run against mocked managers. This adds a secret_manager suite that drives a proxy configured with hashicorp_vault against a real Vault. The tests seed a fresh secret name per test with the runner's OPENAI_API_KEY and register a deployment pointing at os.environ/<name>. The proxy's env never holds that name, so get_secret's os.environ fallback cannot mask a broken manager, and a bogus value in Vault must come back as the provider's 401. Virtual keys are checked written to and removed from Vault under prefix_for_stored_virtual_keys. The setting is global to the proxy, so the lane has its own config and the secret_manager_vault opt-in marker, and stays out of the per-PR selector. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test(e2e): make the secret manager suite backend-agnostic One marker and opt-in (secret_manager / E2E_SECRET_MANAGER=<system>) pick the backend from secret_backends.BACKENDS. The tests reach the manager through a SecretStore protocol, and each backend contributes a secret_store_<system>.py module, a registry entry, and gateway/secret_manager_<system>_ci_config.yml. requires_capability deselects tests a backend cannot support (CyberArk does not delete), and test_secret_backends.py checks every lane config against its backend without a live stack. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * test(e2e): add a CyberArk Conjur secret manager lane Adds cyberark as the second secret_manager backend: a Conjur store over its REST API (policy-declared variables, raw-text values, policy-patch teardown), its lane config, and a registry entry without deletes_stored_keys, since the proxy's CyberArk delete answers not_supported and Conjur keeps the key. secret_manager/backend.sh up|down <system> boots any backend in Docker and writes proxy.env and tests.env, so every lane runs the same way; the registry test checks the script boots exactly the registered backends. e2e_http gains send_text_external for APIs that speak raw text rather than JSON. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> * fix(e2e): give the secret manager suite a client with .proxy and address review The shared resources fixture reads client.proxy, so a bare ProxyClient errored every live test at setup. backend.sh now writes its env under a per-user directory with umask 077, the markerless unit tests are gone per tests/e2e/AGENTS.md, and routine comments are trimmed. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
76 lines
2.6 KiB
Bash
Executable file
76 lines
2.6 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
set -euo pipefail
|
|
umask 077
|
|
|
|
usage() {
|
|
local systems
|
|
systems=$(declare -F | sed -n 's/^declare -f up_//p' | paste -sd '|' -)
|
|
echo "usage: $0 up|down $systems" >&2
|
|
exit 2
|
|
}
|
|
|
|
action=${1:-}
|
|
system=${2:-}
|
|
dir=${E2E_SECRET_MANAGER_DIR:-$HOME/.cache/litellm-e2e-secret-manager}/$system
|
|
name=litellm-e2e-$system
|
|
|
|
wait_for() {
|
|
local url=$1
|
|
for _ in $(seq 1 90); do
|
|
if curl -sf -o /dev/null "$url"; then
|
|
return 0
|
|
fi
|
|
sleep 2
|
|
done
|
|
echo "$system did not answer at $url" >&2
|
|
return 1
|
|
}
|
|
|
|
down() {
|
|
docker rm -f "$name" "$name-db" >/dev/null 2>&1 || true
|
|
docker network rm "$name" >/dev/null 2>&1 || true
|
|
rm -rf "$dir"
|
|
}
|
|
|
|
up_hashicorp_vault() {
|
|
local port=${E2E_SECRET_MANAGER_PORT:-8200}
|
|
local token
|
|
token=e2e-$(openssl rand -hex 16)
|
|
docker run -d --name "$name" -p "127.0.0.1:$port:8200" --cap-add IPC_LOCK \
|
|
-e VAULT_DEV_ROOT_TOKEN_ID="$token" hashicorp/vault:1.20 >/dev/null
|
|
wait_for "http://127.0.0.1:$port/v1/sys/health"
|
|
printf 'HCP_VAULT_ADDR=http://127.0.0.1:%s\nHCP_VAULT_TOKEN=%s\n' "$port" "$token" >"$dir/proxy.env"
|
|
printf 'E2E_VAULT_ADDR=http://127.0.0.1:%s\nE2E_VAULT_TOKEN=%s\n' "$port" "$token" >"$dir/tests.env"
|
|
}
|
|
|
|
up_cyberark() {
|
|
local port=${E2E_SECRET_MANAGER_PORT:-8080}
|
|
local data_key api_key
|
|
docker network create "$name" >/dev/null
|
|
docker run -d --name "$name-db" --network "$name" -e POSTGRES_HOST_AUTH_METHOD=trust postgres:15 >/dev/null
|
|
data_key=$(docker run --rm cyberark/conjur:1.24 data-key generate)
|
|
docker run -d --name "$name" --network "$name" -p "127.0.0.1:$port:80" \
|
|
-e DATABASE_URL="postgres://postgres@$name-db/postgres" -e CONJUR_DATA_KEY="$data_key" \
|
|
-e CONJUR_AUTHENTICATORS=authn cyberark/conjur:1.24 server >/dev/null
|
|
wait_for "http://127.0.0.1:$port/"
|
|
docker exec "$name" conjurctl account create --name default >/dev/null
|
|
api_key=$(docker exec "$name" conjurctl role retrieve-key default:user:admin | tr -d '\r\n')
|
|
printf 'CYBERARK_API_BASE=http://127.0.0.1:%s\nCYBERARK_ACCOUNT=default\nCYBERARK_USERNAME=admin\nCYBERARK_API_KEY=%s\n' \
|
|
"$port" "$api_key" >"$dir/proxy.env"
|
|
printf 'E2E_CYBERARK_API_BASE=http://127.0.0.1:%s\nE2E_CYBERARK_ACCOUNT=default\nE2E_CYBERARK_USERNAME=admin\nE2E_CYBERARK_API_KEY=%s\n' \
|
|
"$port" "$api_key" >"$dir/tests.env"
|
|
}
|
|
|
|
[[ $# -eq 2 && -n $system ]] && declare -F "up_$system" >/dev/null || usage
|
|
|
|
case $action in
|
|
up)
|
|
down
|
|
mkdir -p "$dir"
|
|
"up_$system"
|
|
echo "E2E_SECRET_MANAGER=$system" >>"$dir/tests.env"
|
|
echo "$system is up; env in $dir/proxy.env (proxy) and $dir/tests.env (pytest)"
|
|
;;
|
|
down) down ;;
|
|
*) usage ;;
|
|
esac
|