feat: add ai_providers table, queries, dbauthz, audit, RBAC (#24892)

This commit is contained in:
Danny Kopping
2026-05-14 16:10:46 +02:00
committed by GitHub
parent acf57b3b35
commit 841b777ccd
43 changed files with 1960 additions and 232 deletions
+6
View File
@@ -12,6 +12,12 @@ export const RBACResourceActions: Partial<
read: "read AI model prices",
update: "update AI model prices",
},
ai_provider: {
create: "create an AI provider",
delete: "delete an AI provider",
read: "read AI provider configuration",
update: "update an AI provider",
},
ai_seat: {
create: "record AI seat usage",
read: "read AI seat state",
+46 -30
View File
@@ -57,7 +57,7 @@ export interface AIBridgeConfig {
* Providers holds provider instances populated from CODER_AIBRIDGE_PROVIDER_<N>_<KEY>
* env vars and/or the deprecated LegacyOpenAI/LegacyAnthropic/LegacyBedrock fields above.
*/
readonly providers?: readonly AIBridgeProviderConfig[];
readonly providers?: readonly AIProviderConfig[];
/**
* @deprecated Injected MCP in AI Bridge is deprecated and will be removed in a future release.
*/
@@ -129,35 +129,6 @@ export interface AIBridgeOpenAIConfig {
readonly key: string;
}
// From codersdk/deployment.go
/**
* AIBridgeProviderConfig represents a single AI Bridge provider instance,
* parsed from CODER_AIBRIDGE_PROVIDER_<N>_<KEY> environment variables.
* This follows the same indexed pattern as ExternalAuthConfig.
*/
export interface AIBridgeProviderConfig {
/**
* Type is the provider type: "openai", "anthropic", or "copilot".
*/
readonly type: string;
/**
* Name is the unique instance identifier used for routing.
* Defaults to Type if not provided.
*/
readonly name: string;
/**
* BaseURL is the base URL of the upstream provider API.
*/
readonly base_url: string;
/**
* DumpDir is the directory path for dumping API requests and responses.
*/
readonly dump_dir?: string;
readonly bedrock_region?: string;
readonly bedrock_model?: string;
readonly bedrock_small_fast_model?: string;
}
// From codersdk/deployment.go
export interface AIBridgeProxyConfig {
readonly enabled: boolean;
@@ -327,6 +298,35 @@ export interface AIConfig {
readonly chat?: ChatConfig;
}
// From codersdk/deployment.go
/**
* AIProviderConfig represents a single AI provider instance,
* parsed from CODER_AIBRIDGE_PROVIDER_<N>_<KEY> environment variables.
* This follows the same indexed pattern as ExternalAuthConfig.
*/
export interface AIProviderConfig {
/**
* Type is the provider type: "openai", "anthropic", or "copilot".
*/
readonly type: string;
/**
* Name is the unique instance identifier used for routing.
* Defaults to Type if not provided.
*/
readonly name: string;
/**
* BaseURL is the base URL of the upstream provider API.
*/
readonly base_url: string;
/**
* DumpDir is the directory path for dumping API requests and responses.
*/
readonly dump_dir?: string;
readonly bedrock_region?: string;
readonly bedrock_model?: string;
readonly bedrock_small_fast_model?: string;
}
// From codersdk/allowlist.go
/**
* APIAllowListTarget represents a single allow-list entry using the canonical
@@ -362,6 +362,11 @@ export type APIKeyScope =
| "ai_model_price:*"
| "ai_model_price:read"
| "ai_model_price:update"
| "ai_provider:*"
| "ai_provider:create"
| "ai_provider:delete"
| "ai_provider:read"
| "ai_provider:update"
| "ai_seat:*"
| "ai_seat:create"
| "ai_seat:read"
@@ -577,6 +582,11 @@ export const APIKeyScopes: APIKeyScope[] = [
"ai_model_price:*",
"ai_model_price:read",
"ai_model_price:update",
"ai_provider:*",
"ai_provider:create",
"ai_provider:delete",
"ai_provider:read",
"ai_provider:update",
"ai_seat:*",
"ai_seat:create",
"ai_seat:read",
@@ -6432,6 +6442,7 @@ export const RBACActions: RBACAction[] = [
// From codersdk/rbacresources_gen.go
export type RBACResource =
| "ai_provider"
| "ai_model_price"
| "ai_seat"
| "aibridge_interception"
@@ -6480,6 +6491,7 @@ export type RBACResource =
| "workspace_proxy";
export const RBACResources: RBACResource[] = [
"ai_provider",
"ai_model_price",
"ai_seat",
"aibridge_interception",
@@ -6639,6 +6651,8 @@ export interface ResolveAutostartResponse {
// From codersdk/audit.go
export type ResourceType =
| "ai_provider"
| "ai_provider_key"
| "ai_seat"
| "api_key"
| "chat"
@@ -6670,6 +6684,8 @@ export type ResourceType =
| "workspace_proxy";
export const ResourceTypes: ResourceType[] = [
"ai_provider",
"ai_provider_key",
"ai_seat",
"api_key",
"chat",