Skip to content

Automations: per-run LiteLLM tags on community (filter caller tags in usage hook + allow_client_tags on workspace keys only) #165

Description

@sre-helmcode

Part of #160 / follow-up of #162 (T0 spike, 2026-10-10).

LiteLLM 1.83.14 drops the x-litellm-tags header unless the key/team has metadata.allow_client_tags: true (litellm_pre_call_utils.py L1151-1191, L1385). Community has the flag on 0/998 keys and 0/7 teams, so per-run tags (nan-run:<uuid>) never reach SpendLogs; Phase 1 settles usage from agent-reported usage instead.

Security constraint: enabling allow_client_tags as-is would let a member spoof client_ip: / country: tags, because the API-key-sharing ETL (docker/abuse-detection-etl/etl.py:79-91) takes the FIRST such tag and caller tags come first.

Tasks:

  • Community usage hook: drop every caller-supplied tag except ^nan-run:[0-9a-f-]{36}$ (with tests, including known-bad spoof attempts), before the hook appends its own tags
  • Set metadata.allow_client_tags: true ONLY on workspace keys (those with metadata.workspace_uuid), never on the team or member main keys; include it in EnsureWorkspaceKeys
  • Hermes: add model.extra_headers: {x-litellm-tags: '${NAN_RUN_TAGS}'} in render_hermes_config (cloud-api) and buildHermesConfigYAML (nan-vmd)
  • Verify end to end on community with >= 30 requests per route that every row is tagged and that spoofed client_ip/country tags are dropped
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions