From 89301a89fe98514fb8ac4eced40a15b01c12c448 Mon Sep 17 00:00:00 2001 From: Vuong Hoang Date: Sun, 27 Sep 2026 09:29:50 -0700 Subject: [PATCH] docs(litellm): correct scalar-judge passthrough access semantics The comment claimed 'gateway-key-gated'; v1.97.0 actually gates auth=true passthrough routes on per-key metadata allowed_passthrough_routes (OSS path, not Enterprise), 401 unauthenticated. Grants applied live via /key/update for all-agents-local and the worldtree gateway key; comment-only change here, picks up with the next conf deploy. --- stacks/litellm/conf/config.yaml | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/stacks/litellm/conf/config.yaml b/stacks/litellm/conf/config.yaml index 93a501c..3750fe9 100644 --- a/stacks/litellm/conf/config.yaml +++ b/stacks/litellm/conf/config.yaml @@ -1078,8 +1078,17 @@ general_settings: # scalar-judge → Skywork-Reward-V2-Llama-3.1-8B (AWQ; vLLM pooling on esh-ml1 # :8003, moved from fv-ml1 2026-09-25, same files, verdicts identical 149/150). # LiteLLM has no reward/pooling MODE, so this is a passthrough, - # not a model_list alias. Gateway-key-gated. Consumers POST the reward body to + # not a model_list alias. Consumers POST the reward body to # /scalar-judge/ (e.g. /classify), forwarded to :8003. + # ACCESS (semantics verified against v1.97.0 source, 2026-09-26): auth=true + # (the default) means ANY valid virtual key authenticates, but only keys + # whose DB metadata carries allowed_passthrough_routes: ["/scalar-judge"] + # are authorized; unauthenticated calls get 401. NOT an admin-only route. + # Grants are per-key DB metadata (set via /key/update "metadata" field — the + # top-level allowed_passthrough_routes param is Enterprise-gated; the + # metadata dict is not, and the authZ check reads it). Granted so far: + # all-agents-local, worldtree vastblueai-gateway key. No proxy restart + # needed for grants; key info is hydrated from Postgres per request. # SWAP-SENSITIVE: a different reward model shifts the score scale, so consumers # must recalibrate thresholds after a backing swap. # ⚠ Send already-templated text with "add_special_tokens": false. Otherwise vLLM