Skip to content

ci: let the provider base URLs come from secrets - #569

Merged
danny-avila merged 1 commit into
mainfrom
ci/gateway-base-urls
Sep 27, 2026
Merged

danny-avila merged 1 commit into
mainfrom
ci/gateway-base-urls

Conversation

@danny-avila

Copy link
Copy Markdown
Collaborator

What

The live-model jobs in validate.yml (unit shards, summarization groups, the Anthropic LLM spec) get two more environment lines each:

ANTHROPIC_BASE_URL: ${{ secrets.ANTHROPIC_BASE_URL }}
OPENAI_BASE_URL: ${{ secrets.OPENAI_BASE_URL }}

With the secrets set, the suites run against a private OpenAI- and Anthropic-compatible gateway instead of the public APIs. With the secrets unset, nothing changes.

Why secrets and not variables

The gateway host is internal. Repository secrets are masked in job logs; variables are not. LIBRECHAT_CODE_BASEURL already follows this rule.

How it works

No code change. The Anthropic SDK reads ANTHROPIC_BASE_URL and the OpenAI SDK reads OPENAI_BASE_URL when no baseURL is passed, and our wrappers pass none by default (src/llm/openai/index.ts deletes a null baseURL before constructing the client; CustomAnthropic never sets one).

Verified locally

Environment CustomAnthropic (claude-haiku-4-5) ChatOpenAI (gpt-5.5)
Base URLs → gateway, gateway credential "ok" "ok"
Base URLs → https://127.0.0.1:9, any key connection error connection error
Base URLs empty, bogus key 401 from api.anthropic.com 401 from api.openai.com

The empty-string row is the state of CI until the secrets are added: both SDKs' readEnv treats an empty variable as unset.

Secrets to add

ANTHROPIC_BASE_URL is the gateway host with no path (the SDK appends /v1/messages). OPENAI_BASE_URL is the host plus /v1 (the SDK appends /chat/completions and /responses). The two API-key secrets take the gateway credentials, ideally two virtual keys scoped to the Anthropic and OpenAI routes respectively.

Every job that passes ANTHROPIC_API_KEY or OPENAI_API_KEY now also passes ANTHROPIC_BASE_URL
and OPENAI_BASE_URL from repository secrets, so the live suites can run against a private
inference gateway. Both SDKs read those variables themselves; an unset secret is an empty
string, which the SDKs treat as unset and fall back to the public hosts.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant