elky
579f2c7cc1
feat(security): harden gateway boundaries and usage policies
...
Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change.
Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
2026-09-04 03:45:52 +08:00
ZheFox
3dfc15963c
Merge pull request #789 from zhefox/codex/fix-antigravity-quota
...
Codex/fix antigravity quota
2026-09-03 18:48:58 +08:00
elky
4291a91dc0
test(gateway): pass routing policy to affinity effects
2026-09-03 15:50:53 +08:00
ZheFox
587486ab0c
Merge remote-tracking branch 'upstream/main' into codex/fix-antigravity-quota
2026-09-03 13:24:39 +08:00
fawney
2cb4d554aa
feat(routing): consolidate scheduling strategy configuration
2026-09-03 11:05:59 +08:00
zhefox
dbbe7b22ab
fix(pool): isolate dynamic model quota buckets and 429 scheduling
2026-09-02 15:23:23 +08:00
AAEE86
71b54070e8
feat(gateway): Codex/OpenAI Responses WebSocket 代理模式
...
在 /v1/responses 上支持 WebSocket 升级,把客户端帧中继到上游 Codex /
OpenAI Responses WebSocket 端点,同时保持既有的路由、鉴权、配额与用量
语义:
- 路由与准入:control/route/ai.rs 识别 WebSocket 升级请求;
websocket/ingress.rs 复用 API Key 鉴权、IP 规则与并发许可,并引入
独立的 WebSocket 连接许可
- 中继:websocket/responses/* 按 connection / session / turn 分层,
帧解析归一化、socket 写入有界、continuation 保持调度亲和性
- 配额:orchestration/codex_quota_breaker.rs 在账号配额耗尽时熔断并
自动恢复,不再直接断开客户端连接
- 用量:每个 turn 的终态用量落库,request_metadata 记录
websocket_mode / websocket_transport,管理端与 usage 视图暴露
is_websocket
- 管理端:provider 可配置 Responses WebSocket 开关
2026-08-17 14:50:33 +08:00
elky
5b0c763086
fix(codex): fence concurrent quota updates
2026-08-14 09:28:07 +08:00
ZheFox
9d9316e434
Merge branch 'fawney19:main' into main
2026-07-28 13:56:34 +08:00
ZheFox
f0f87b56a3
feat(providers): add credential-fenced OAuth key cleanup
2026-07-28 11:32:11 +08:00
elky
4148ab1931
fix(routing): harden routed pool scheduling
2026-07-27 22:06:28 +08:00
elky
531cf11025
feat(gateway): harden provider request execution
...
Preserve exact request payloads and model client surface and API operation explicitly.
Add Anthropic compatibility profiles, bounded stream commitment, and scoped OAuth retry behavior across provider transports.
2026-07-27 09:36:31 +08:00
elky
3606290ac8
fix(provider): harden Agent Identity OAuth lifecycle
2026-07-23 09:33:00 +08:00
elky
fc92c4f431
perf(gateway): scale request hot paths for 20k streams
...
Shard and singleflight hot-path caches, batch and prioritize candidate and usage lifecycle persistence, and extend database and pressure-test instrumentation for 20k concurrent streams.
2026-07-22 02:11:08 +08:00
elky
8616fe6ee2
refactor(workspace): enforce layered crate boundaries
2026-07-15 23:47:19 +08:00
MMEXA
2316df5c9a
feat(codex): align Search and execution protocol
2026-07-12 03:04:15 +08:00
elky
6f00e9fc67
Improve gateway transport and usage runtime
2026-06-25 22:36:27 +08:00
elky
d336d1a7fa
Improve gateway scheduling and runtime admission
2026-06-24 01:53:45 +08:00
elky
5b7805181b
perf: queue request candidate persistence
2026-06-22 02:49:17 +08:00
elky
f75894acbb
perf: reduce gateway db pressure under load
2026-06-22 00:08:48 +08:00
elky
61bdd304b7
Handle inactive PAT owner as invalid OAuth token
2026-06-21 11:39:20 +08:00
zhefox
628a3a0d8d
fix(ai-formats): support cyber policy failover and custom tool/audio passthrough
2026-06-17 02:33:14 +08:00
elky
68038c182b
Distinguish expired OAuth token status
2026-06-12 19:43:59 +08:00
fawney19
1658925f52
Disable key circuit breaker for pool providers
2026-05-29 15:16:06 +08:00
fawney19
ccfc4cbddc
Cache provider catalog lookups
2026-05-27 13:56:39 +08:00
RWDai
9859aec16c
fix(gateway): evict pooled affinity after sibling key failures
2026-05-21 23:50:34 +08:00
RWDai
18fe5a4f11
fix(gateway): preserve affinity during adaptive retries
2026-05-21 21:56:26 +08:00
RWDai
965a8c79af
fix(gateway): preserve cache affinity during health updates
2026-05-21 15:51:56 +08:00
fawney19
7e9ca88e00
fix: restore provider key circuit breaker backoff
2026-05-19 13:57:36 +08:00
MMEXA
b480f3aaff
fix(gateway): normalize Gemini Vertex embedding transport
2026-05-18 15:39:29 +00:00
fawney19
fa73655134
refactor: isolate dispatch scheduling core
2026-05-12 13:15:41 +08:00
fawney19
b9e62d1667
Implement generic pool member scoring and probing
2026-05-12 01:46:22 +08:00
fawney19
247ea9d1bd
Restrict scheduler affinity to cache affinity mode
2026-05-11 14:06:49 +08:00
fawney19
e3574e1918
Track scheduler affinity epochs and key sorting
2026-05-11 01:45:49 +08:00
fawney19
bacb14e5f0
refactor: lazy pool key scheduling
2026-05-11 00:12:05 +08:00
fawney19
6247ac3edc
refactor: extract runtime state backends
2026-05-08 00:18:12 +08:00
fawney19
10e679bb2f
Add provider key cycle stats reset handling
2026-05-07 03:23:20 +08:00
fawney19
6dd7464793
Merge remote-tracking branch 'origin/aether-rust-pioneer' into pr-375-session-scope
2026-05-05 22:34:47 +08:00
fawney19
f959f02d40
Implement transport profile routing
2026-05-05 22:21:23 +08:00
fawney19
98421126f2
refactor: carry normalized client session affinity
2026-05-05 21:34:17 +08:00
fawney19
fce7e959e5
Add multi-database data layer
...
Introduce aether-data-schema and driver-specific schema generation for Postgres, MySQL, and SQLite.
Split data backends, lifecycle, repositories, and gateway runtime integration across database drivers.
Verified with cargo fmt --all --check, cargo clippy --workspace --all-targets -- -D warnings, and cargo test --workspace.
2026-05-05 18:27:36 +08:00
RWDai
628329e493
fix: scope scheduler effects by session
2026-05-05 12:25:07 +08:00
fawney19
099653f732
Cap Codex pool cooldowns and add key circuit breaker
2026-05-04 02:15:32 +08:00
fawney19
c130d0e2c9
refactor ai serving modules and crates
2026-05-02 13:23:54 +08:00
fawney19
33aa70c22b
fix scheduler affinity candidate selection
2026-04-30 16:27:24 +08:00
fawney19
5b914aa78c
migrate ai format conversion to responses adapters
2026-04-26 23:59:53 +08:00
fawney19
4374f53315
fix(adaptive): 修复 429 计数归零写入及 reset 语义
...
- sql.rs: UPDATE 时对 concurrent_429_count / rpm_429_count 加 COALESCE(, 0),避免 None 覆写为 NULL
- effects.rs: rpm_429_count 始终写入 Some(projection.rpm_429_count),不再过滤零值;新增 unknown-429 场景下零值持久化的单元测试
- adaptive.rs: reset 接口将两个计数字段置为 Some(0) 而非 None,与数据库默认语义对齐;同步修正集成测试断言
- docker-compose.build.yml: 补充 AETHER_GATEWAY_AUTO_PREPARE_DATABASE 默认开启
- README.md: 同步说明 build compose 也已默认开启自动迁移
2026-04-22 22:16:51 +08:00
fawney19
c1b9d94c84
feat(adaptive): 完善自适应 RPM 学习并将 Pool 调度状态与健康分解耦
...
- orchestration 新增 AdaptiveSuccess 效果,在成功回报路径上根据利用率窗口扩张 learned_rpm_limit
- 429 路径改用 429_observation/adjustment 记录以及基于历史的置信度评估,新增 last_rpm_peak 边界字段
- Pool 调度状态不再因 health_score 低或熔断而降级/拦截,前端同步移除相关按钮与文案兜底
- 新增前端 poolTrace 工具(附测试)承接原 HorizontalRequestTimeline 内的候选合并逻辑
2026-04-20 00:27:48 +08:00
fawney19
569242d72f
refactor gateway orchestration and failover effects
2026-04-18 11:35:11 +08:00