chore: add aibridge database resources & define RBAC policies (#19796)

Closes https://github.com/coder/internal/issues/986
This commit is contained in:
Danny Kopping
2025-09-16 21:31:17 +02:00
committed by GitHub
parent 348a2e0285
commit 422bba44d9
26 changed files with 770 additions and 0 deletions
@@ -0,0 +1,4 @@
DROP TABLE IF EXISTS aibridge_tool_usages CASCADE;
DROP TABLE IF EXISTS aibridge_user_prompts CASCADE;
DROP TABLE IF EXISTS aibridge_token_usages CASCADE;
DROP TABLE IF EXISTS aibridge_interceptions CASCADE;
@@ -0,0 +1,68 @@
CREATE TABLE IF NOT EXISTS aibridge_interceptions (
id UUID PRIMARY KEY,
initiator_id uuid NOT NULL,
provider TEXT NOT NULL,
model TEXT NOT NULL,
started_at TIMESTAMP WITH TIME ZONE NOT NULL
);
COMMENT ON TABLE aibridge_interceptions IS 'Audit log of requests intercepted by AI Bridge';
COMMENT ON COLUMN aibridge_interceptions.initiator_id IS 'Relates to a users record, but FK is elided for performance.';
CREATE INDEX idx_aibridge_interceptions_initiator_id ON aibridge_interceptions (initiator_id);
CREATE TABLE IF NOT EXISTS aibridge_token_usages (
id UUID PRIMARY KEY,
interception_id UUID NOT NULL,
provider_response_id TEXT NOT NULL,
input_tokens BIGINT NOT NULL,
output_tokens BIGINT NOT NULL,
metadata JSONB DEFAULT NULL,
created_at TIMESTAMP WITH TIME ZONE NOT NULL
);
COMMENT ON TABLE aibridge_token_usages IS 'Audit log of tokens used by intercepted requests in AI Bridge';
COMMENT ON COLUMN aibridge_token_usages.provider_response_id IS 'The ID for the response in which the tokens were used, produced by the provider.';
CREATE INDEX idx_aibridge_token_usages_interception_id ON aibridge_token_usages (interception_id);
CREATE INDEX idx_aibridge_token_usages_provider_response_id ON aibridge_token_usages (provider_response_id);
CREATE TABLE IF NOT EXISTS aibridge_user_prompts (
id UUID PRIMARY KEY,
interception_id UUID NOT NULL,
provider_response_id TEXT NOT NULL,
prompt TEXT NOT NULL,
metadata JSONB DEFAULT NULL,
created_at TIMESTAMP WITH TIME ZONE NOT NULL
);
COMMENT ON TABLE aibridge_user_prompts IS 'Audit log of prompts used by intercepted requests in AI Bridge';
COMMENT ON COLUMN aibridge_user_prompts.provider_response_id IS 'The ID for the response to the given prompt, produced by the provider.';
CREATE INDEX idx_aibridge_user_prompts_interception_id ON aibridge_user_prompts (interception_id);
CREATE INDEX idx_aibridge_user_prompts_provider_response_id ON aibridge_user_prompts (provider_response_id);
CREATE TABLE IF NOT EXISTS aibridge_tool_usages (
id UUID PRIMARY KEY,
interception_id UUID NOT NULL,
provider_response_id TEXT NOT NULL,
server_url TEXT NULL,
tool TEXT NOT NULL,
input TEXT NOT NULL,
injected BOOLEAN NOT NULL DEFAULT FALSE,
invocation_error TEXT NULL,
metadata JSONB DEFAULT NULL,
created_at TIMESTAMP WITH TIME ZONE NOT NULL
);
COMMENT ON TABLE aibridge_tool_usages IS 'Audit log of tool calls in intercepted requests in AI Bridge';
COMMENT ON COLUMN aibridge_tool_usages.provider_response_id IS 'The ID for the response in which the tools were used, produced by the provider.';
COMMENT ON COLUMN aibridge_tool_usages.server_url IS 'The name of the MCP server against which this tool was invoked. May be NULL, in which case the tool was defined by the client, not injected.';
COMMENT ON COLUMN aibridge_tool_usages.injected IS 'Whether this tool was injected; i.e. Bridge injected these tools into the request from an MCP server. If false it means a tool was defined by the client and already existed in the request (MCP or built-in).';
COMMENT ON COLUMN aibridge_tool_usages.invocation_error IS 'Only injected tools are invoked.';
CREATE INDEX idx_aibridge_tool_usages_interception_id ON aibridge_tool_usages (interception_id);
CREATE INDEX idx_aibridge_tool_usagesprovider_response_id ON aibridge_tool_usages (provider_response_id);
@@ -0,0 +1,79 @@
INSERT INTO
aibridge_interceptions (
id,
initiator_id,
provider,
model,
started_at
)
VALUES (
'be003e1e-b38f-43bf-847d-928074dd0aa8',
'30095c71-380b-457a-8995-97b8ee6e5307',
'openai',
'gpt-5',
'2025-09-15 12:45:13.921148+00'
);
INSERT INTO
aibridge_token_usages (
id,
interception_id,
provider_response_id,
input_tokens,
output_tokens,
metadata,
created_at
)
VALUES (
'c56ca89d-af65-47b0-871f-0b9cd2af6575',
'be003e1e-b38f-43bf-847d-928074dd0aa8',
'chatcmpl-CG2s28QlpKIoooUtXuLTmGbdtyS1k',
10950,
118,
'{"prompt_audio": 0, "prompt_cached": 5376, "completion_audio": 0, "completion_reasoning": 64, "completion_accepted_prediction": 0, "completion_rejected_prediction": 0}',
'2025-09-15 12:45:21.674413+00'
);
INSERT INTO
aibridge_tool_usages (
id,
interception_id,
provider_response_id,
server_url,
tool,
input,
injected,
invocation_error,
metadata,
created_at
)
VALUES (
'613b4cfa-a257-4e88-99e6-4d2e99ea25f0',
'be003e1e-b38f-43bf-847d-928074dd0aa8',
'chatcmpl-CG2ryDxMp6n53aMjgo7P6BHno3fTr',
'http://localhost:3000/api/experimental/mcp/http',
'coder_list_workspaces',
'{}',
true,
NULL,
'{}',
'2025-09-15 12:45:17.65274+00'
);
INSERT INTO
aibridge_user_prompts (
id,
interception_id,
provider_response_id,
prompt,
metadata,
created_at
)
VALUES (
'ac1ea8c3-5109-4105-9b62-489fca220ef7',
'be003e1e-b38f-43bf-847d-928074dd0aa8',
'chatcmpl-CG2s28QlpKIoooUtXuLTmGbdtyS1k',
'how many workspaces do i have',
'{}',
'2025-09-15 12:45:21.674335+00'
);