feat(aiproxy): add authenticated proxy for OpenAI-compatible APIs and MCP servers

Hides upstream URLs and keys behind the security layer. Per-upstream roles,
model/tool allowlists, per-user rate limits, Before/AfterProxy hooks, audit
sink, Prometheus metrics (metrics.AIProxyRecorder) and upstreams loaded from
the resolvespec_ai_proxies stored procedure.
This commit is contained in:
2026-10-07 23:39:40 +02:00
parent e4c4315f4b
commit 63cb0d22eb
14 changed files with 2088 additions and 0 deletions
+8
View File
@@ -47,6 +47,14 @@ type Provider interface {
Handler() http.Handler
}
// AIProxyRecorder is optionally implemented by providers that record aiproxy traffic.
// pkg/aiproxy uses it when the global provider implements it.
type AIProxyRecorder interface {
// RecordAIProxy records one proxied (or refused) request. statusClass is "2xx".."5xx",
// outcome is ok, upstream_error, denied or rate_limited, model may be empty.
RecordAIProxy(upstream, kind, model, statusClass, outcome string, duration time.Duration, promptTokens, completionTokens int64)
}
// Resetter is optionally implemented by providers that can clear their recorded stats.
type Resetter interface {
Reset()