mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
* feat(tracing): bring current ingestion prerequisite onto main
Port the prerequisite implementation from BerriAI/litellm#43915 at 5aacd57455 so Lens does not depend on the retired tracing stack.
* feat(lens): add trace analysis and standalone worker
* fix(lens): clarify review limits and finalize main integration
* fix(lens): simplify worker setup and show the next check
* fix(lens): simplify analyzer setup and resolve integration failures
* fix(lens): preserve durations and evidence from later trace reads
* fix(lens): trust server context for internal analysis exclusion
* fix(lens): pin reviewed analyzer image and verify request inclusion
* test(lens): select time units before entering custom duration
* test(lens): allow the standalone analyzer lifetime HTTP client
* test(lens): run analyzer tests in active proxy coverage shard
54 lines
1.8 KiB
YAML
54 lines
1.8 KiB
YAML
name: Lens Worker Image
|
|
|
|
on:
|
|
pull_request:
|
|
branches: [main, litellm_oss_branch, "litellm_**"]
|
|
paths:
|
|
- deploy/lens/**
|
|
- litellm/proxy/engine/**
|
|
- .github/workflows/lens-worker.yml
|
|
push:
|
|
branches: [main, litellm_agent_engine]
|
|
paths:
|
|
- deploy/lens/**
|
|
- litellm/proxy/engine/**
|
|
- .github/workflows/lens-worker.yml
|
|
workflow_dispatch:
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
lens-worker-image:
|
|
permissions:
|
|
contents: read
|
|
packages: write
|
|
runs-on: ubuntu-latest
|
|
timeout-minutes: 10
|
|
steps:
|
|
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
|
|
with:
|
|
persist-credentials: false
|
|
- name: Build Lens worker
|
|
run: docker build -f deploy/lens/Dockerfile -t lens-worker:${{ github.sha }} .
|
|
- name: Verify standalone imports with a read-only filesystem
|
|
run: >-
|
|
docker run --rm --network none --read-only --cap-drop ALL
|
|
--security-opt no-new-privileges --entrypoint python
|
|
lens-worker:${{ github.sha }}
|
|
-c 'import os; import engine.worker; assert os.getuid() == 65532'
|
|
- name: Publish versioned Lens worker
|
|
if: github.event_name != 'pull_request' && github.repository == 'BerriAI/litellm'
|
|
env:
|
|
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
|
REGISTRY_USER: ${{ github.actor }}
|
|
IMAGE: ghcr.io/berriai/litellm-lens-worker:sha-${{ github.sha }}
|
|
run: |
|
|
printf '%s' "$REGISTRY_TOKEN" | docker login ghcr.io -u "$REGISTRY_USER" --password-stdin
|
|
docker tag lens-worker:${{ github.sha }} "$IMAGE"
|
|
docker push "$IMAGE"
|
|
printf 'Lens worker image: `%s`\n' "$IMAGE" >> "$GITHUB_STEP_SUMMARY"
|