mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
feat: add ai_providers table, queries, dbauthz, audit, RBAC (#24892)
This commit is contained in:
@@ -9,6 +9,11 @@ const (
|
||||
APIKeyScopeAiModelPriceAll APIKeyScope = "ai_model_price:*"
|
||||
APIKeyScopeAiModelPriceRead APIKeyScope = "ai_model_price:read"
|
||||
APIKeyScopeAiModelPriceUpdate APIKeyScope = "ai_model_price:update"
|
||||
APIKeyScopeAiProviderAll APIKeyScope = "ai_provider:*"
|
||||
APIKeyScopeAiProviderCreate APIKeyScope = "ai_provider:create"
|
||||
APIKeyScopeAiProviderDelete APIKeyScope = "ai_provider:delete"
|
||||
APIKeyScopeAiProviderRead APIKeyScope = "ai_provider:read"
|
||||
APIKeyScopeAiProviderUpdate APIKeyScope = "ai_provider:update"
|
||||
APIKeyScopeAiSeatAll APIKeyScope = "ai_seat:*"
|
||||
APIKeyScopeAiSeatCreate APIKeyScope = "ai_seat:create"
|
||||
APIKeyScopeAiSeatRead APIKeyScope = "ai_seat:read"
|
||||
|
||||
+11
-5
@@ -43,11 +43,13 @@ const (
|
||||
ResourceTypeWorkspaceAgent ResourceType = "workspace_agent"
|
||||
// Deprecated: Workspace App connections are now included in the
|
||||
// connection log.
|
||||
ResourceTypeWorkspaceApp ResourceType = "workspace_app"
|
||||
ResourceTypeTask ResourceType = "task"
|
||||
ResourceTypeAISeat ResourceType = "ai_seat"
|
||||
ResourceTypeChat ResourceType = "chat"
|
||||
ResourceTypeUserSecret ResourceType = "user_secret"
|
||||
ResourceTypeWorkspaceApp ResourceType = "workspace_app"
|
||||
ResourceTypeTask ResourceType = "task"
|
||||
ResourceTypeAISeat ResourceType = "ai_seat"
|
||||
ResourceTypeAIProvider ResourceType = "ai_provider"
|
||||
ResourceTypeAIProviderKey ResourceType = "ai_provider_key"
|
||||
ResourceTypeChat ResourceType = "chat"
|
||||
ResourceTypeUserSecret ResourceType = "user_secret"
|
||||
)
|
||||
|
||||
func (r ResourceType) FriendlyString() string {
|
||||
@@ -108,6 +110,10 @@ func (r ResourceType) FriendlyString() string {
|
||||
return "task"
|
||||
case ResourceTypeAISeat:
|
||||
return "ai seat"
|
||||
case ResourceTypeAIProvider:
|
||||
return "ai provider"
|
||||
case ResourceTypeAIProviderKey:
|
||||
return "ai provider key"
|
||||
case ResourceTypeChat:
|
||||
return "chat"
|
||||
case ResourceTypeUserSecret:
|
||||
|
||||
@@ -4005,7 +4005,7 @@ Write out the current server config as YAML to stdout.`,
|
||||
},
|
||||
{
|
||||
Name: "AI Bridge Proxy Domain Allowlist",
|
||||
Description: "Deprecated: This value is now derived automatically from the configured AI Bridge providers' base URLs. Setting this value has no effect. This option will be removed in a future release.",
|
||||
Description: "Deprecated: This value is now derived automatically from the configured AI providers' base URLs. Setting this value has no effect. This option will be removed in a future release.",
|
||||
Flag: "aibridge-proxy-domain-allowlist",
|
||||
Env: "CODER_AIBRIDGE_PROXY_DOMAIN_ALLOWLIST",
|
||||
Value: &c.AI.BridgeProxyConfig.DomainAllowlist,
|
||||
@@ -4147,7 +4147,7 @@ type AIBridgeConfig struct {
|
||||
LegacyBedrock AIBridgeBedrockConfig `json:"bedrock" typescript:",notnull"`
|
||||
// Providers holds provider instances populated from CODER_AIBRIDGE_PROVIDER_<N>_<KEY>
|
||||
// env vars and/or the deprecated LegacyOpenAI/LegacyAnthropic/LegacyBedrock fields above.
|
||||
Providers []AIBridgeProviderConfig `json:"providers,omitempty"`
|
||||
Providers []AIProviderConfig `json:"providers,omitempty"`
|
||||
// Deprecated: Injected MCP in AI Bridge is deprecated and will be removed in a future release.
|
||||
InjectCoderMCPTools serpent.Bool `json:"inject_coder_mcp_tools" typescript:",notnull"`
|
||||
Retention serpent.Duration `json:"retention" typescript:",notnull"`
|
||||
@@ -4187,10 +4187,10 @@ type AIBridgeBedrockConfig struct {
|
||||
SmallFastModel serpent.String `json:"small_fast_model" typescript:",notnull"`
|
||||
}
|
||||
|
||||
// AIBridgeProviderConfig represents a single AI Bridge provider instance,
|
||||
// AIProviderConfig represents a single AI provider instance,
|
||||
// parsed from CODER_AIBRIDGE_PROVIDER_<N>_<KEY> environment variables.
|
||||
// This follows the same indexed pattern as ExternalAuthConfig.
|
||||
type AIBridgeProviderConfig struct {
|
||||
type AIProviderConfig struct {
|
||||
// Type is the provider type: "openai", "anthropic", or "copilot".
|
||||
Type string `json:"type"`
|
||||
// Name is the unique instance identifier used for routing.
|
||||
|
||||
@@ -6,6 +6,7 @@ type RBACResource string
|
||||
const (
|
||||
ResourceWildcard RBACResource = "*"
|
||||
ResourceAiModelPrice RBACResource = "ai_model_price"
|
||||
ResourceAIProvider RBACResource = "ai_provider"
|
||||
ResourceAiSeat RBACResource = "ai_seat"
|
||||
ResourceAibridgeInterception RBACResource = "aibridge_interception"
|
||||
ResourceApiKey RBACResource = "api_key"
|
||||
@@ -80,6 +81,7 @@ const (
|
||||
var RBACResourceActions = map[RBACResource][]RBACAction{
|
||||
ResourceWildcard: {},
|
||||
ResourceAiModelPrice: {ActionRead, ActionUpdate},
|
||||
ResourceAIProvider: {ActionCreate, ActionDelete, ActionRead, ActionUpdate},
|
||||
ResourceAiSeat: {ActionCreate, ActionRead},
|
||||
ResourceAibridgeInterception: {ActionCreate, ActionRead, ActionUpdate},
|
||||
ResourceApiKey: {ActionCreate, ActionDelete, ActionRead, ActionUpdate},
|
||||
|
||||
Reference in New Issue
Block a user