litellm/.github/workflows/monitor_databricks_pricing.yml
leecoder 9bb64b1120 ci(workflow): drop the PAT - use the built-in token per repo
The monitor used to run on the fork and open PRs against upstream,
which structurally requires a cross-repo PAT. Two changes remove it:

- PRs are created in whichever repo the workflow runs in
  (GITHUB_REPOSITORY), so the built-in github.token covers both push
  and pr create - same pattern as upstream's
  auto_update_price_and_context_window workflow
- the job guard flips: upstream owns the merged schedule
  (github.repository == BerriAI/litellm), the fork stays dispatch-only,
  so the two never race on the same base

The script bootstrap from the fork branch stays until #38950 lands
upstream. DBX_MONITOR_TOKEN secret is no longer referenced.
2026-09-08 14:57:05 +09:00

85 lines
3.6 KiB
YAML

name: Monitor Databricks Pricing
# Daily monitor of the Databricks Foundation Model Serving pricing pages.
# Before PR #38950 merges this workflow only lives on the leecoder/litellm
# fork (manual dispatch); after the merge it runs on BerriAI/litellm's cron.
# PRs are always created in the repository the workflow runs in, so the
# built-in GITHUB_TOKEN is sufficient - no PAT or secret required.
on:
schedule:
- cron: "0 2 * * *" # daily 02:00 UTC
workflow_dispatch:
permissions:
contents: write
pull-requests: write
env:
UPSTREAM_REPO: BerriAI/litellm
UPSTREAM_BASE: litellm_internal_staging
# branch that carries the monitor script until PR #38950 lands upstream
SCRIPT_REF: feat/dbx-pricing-monitor-clean
jobs:
monitor-db-pricing:
# once merged the cron fires on both repos; upstream owns the schedule,
# the fork stays dispatch-only so the two never race on the same base
if: github.repository == 'BerriAI/litellm' || github.event_name == 'workflow_dispatch'
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@08eba0b27e820071cde6df949e0beb9ba4906955 # v4.3.0
with:
persist-credentials: false
fetch-depth: 0
repository: ${{ env.UPSTREAM_REPO }}
ref: ${{ env.UPSTREAM_BASE }}
- name: Bootstrap monitor script until #38950 lands upstream
run: |
if [ ! -f scripts/monitor_databricks_pricing.py ]; then
mkdir -p scripts
curl -fsSL "https://raw.githubusercontent.com/leecoder/litellm/${SCRIPT_REF}/scripts/monitor_databricks_pricing.py" \
-o scripts/monitor_databricks_pricing.py
fi
- name: Set up Python
uses: actions/setup-python@42375524e23c412d93fb67b49958b491fce71c38 # v5.4.0
with:
python-version: "3.12"
- name: Run monitor
id: monitor
shell: bash
run: |
set -o pipefail
python scripts/monitor_databricks_pricing.py | tee /tmp/monitor_out.txt
if grep -q '^NO_CHANGE' /tmp/monitor_out.txt; then
echo "changed=false" >> "$GITHUB_OUTPUT"
else
echo "changed=true" >> "$GITHUB_OUTPUT"
fi
- name: Open PR if changed
if: steps.monitor.outputs.changed == 'true'
env:
GH_TOKEN: ${{ github.token }}
GITHUB_TOKEN_FOR_PUSH: ${{ github.token }}
run: |
BRANCH="monitor-dbx-pricing-$(date +'%Y-%m-%d')"
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git checkout -b "$BRANCH"
git add model_prices_and_context_window.json litellm/model_prices_and_context_window_backup.json
git commit -m "chore(model_prices): refresh Databricks Foundation Model Serving rates - automated monitor detected changed DBU rates on the Databricks pricing pages; refreshed the mapped databricks/* entries."
git push "https://x-access-token:${GITHUB_TOKEN_FOR_PUSH}@github.com/${GITHUB_REPOSITORY}.git" "HEAD:refs/heads/$BRANCH"
{
cat /tmp/dbx_monitor_pr_body.md
echo
echo "---"
echo "Auto-generated by the Databricks pricing monitor. \`PROMO_SKIPPED\`/\`REVIEW\`/\`MISSING_FROM_PAGE\` lines need human attention; \`UPDATED\` lines were applied automatically."
} > /tmp/dbx_pr_body_final.md
gh pr create --repo "$GITHUB_REPOSITORY" \
--base "$UPSTREAM_BASE" \
--head "$BRANCH" \
--title "chore(model_prices): refresh Databricks Foundation Model Serving rates" \
--body-file /tmp/dbx_pr_body_final.md