diff --git a/stacks/litellm/conf/config.yaml b/stacks/litellm/conf/config.yaml index 93a501c..3750fe9 100644 --- a/stacks/litellm/conf/config.yaml +++ b/stacks/litellm/conf/config.yaml @@ -1078,8 +1078,17 @@ general_settings: # scalar-judge → Skywork-Reward-V2-Llama-3.1-8B (AWQ; vLLM pooling on esh-ml1 # :8003, moved from fv-ml1 2026-09-25, same files, verdicts identical 149/150). # LiteLLM has no reward/pooling MODE, so this is a passthrough, - # not a model_list alias. Gateway-key-gated. Consumers POST the reward body to + # not a model_list alias. Consumers POST the reward body to # /scalar-judge/ (e.g. /classify), forwarded to :8003. + # ACCESS (semantics verified against v1.97.0 source, 2026-09-26): auth=true + # (the default) means ANY valid virtual key authenticates, but only keys + # whose DB metadata carries allowed_passthrough_routes: ["/scalar-judge"] + # are authorized; unauthenticated calls get 401. NOT an admin-only route. + # Grants are per-key DB metadata (set via /key/update "metadata" field — the + # top-level allowed_passthrough_routes param is Enterprise-gated; the + # metadata dict is not, and the authZ check reads it). Granted so far: + # all-agents-local, worldtree vastblueai-gateway key. No proxy restart + # needed for grants; key info is hydrated from Postgres per request. # SWAP-SENSITIVE: a different reward model shifts the score scale, so consumers # must recalibrate thresholds after a backing swap. # ⚠ Send already-templated text with "add_special_tokens": false. Otherwise vLLM