ci: let the provider base URLs come from secrets - #569
Merged
Merged
Conversation
Every job that passes ANTHROPIC_API_KEY or OPENAI_API_KEY now also passes ANTHROPIC_BASE_URL and OPENAI_BASE_URL from repository secrets, so the live suites can run against a private inference gateway. Both SDKs read those variables themselves; an unset secret is an empty string, which the SDKs treat as unset and fall back to the public hosts.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The live-model jobs in
validate.yml(unit shards, summarization groups, the Anthropic LLM spec) get two more environment lines each:With the secrets set, the suites run against a private OpenAI- and Anthropic-compatible gateway instead of the public APIs. With the secrets unset, nothing changes.
Why secrets and not variables
The gateway host is internal. Repository secrets are masked in job logs; variables are not.
LIBRECHAT_CODE_BASEURLalready follows this rule.How it works
No code change. The Anthropic SDK reads
ANTHROPIC_BASE_URLand the OpenAI SDK readsOPENAI_BASE_URLwhen nobaseURLis passed, and our wrappers pass none by default (src/llm/openai/index.tsdeletes a nullbaseURLbefore constructing the client;CustomAnthropicnever sets one).Verified locally
CustomAnthropic(claude-haiku-4-5)ChatOpenAI(gpt-5.5)"ok""ok"https://127.0.0.1:9, any keyapi.anthropic.comapi.openai.comThe empty-string row is the state of CI until the secrets are added: both SDKs'
readEnvtreats an empty variable as unset.Secrets to add
ANTHROPIC_BASE_URLis the gateway host with no path (the SDK appends/v1/messages).OPENAI_BASE_URLis the host plus/v1(the SDK appends/chat/completionsand/responses). The two API-key secrets take the gateway credentials, ideally two virtual keys scoped to the Anthropic and OpenAI routes respectively.