commit 584338fb60bd2952f2a6de809afcaf38f1f5f732 Author: root Date: Fri Jun 26 14:40:22 2026 +0000 feat: initial OpenProse contracts — LiteLLM health check + hello world - litellm-health.prose.md: Verifies admin UI, API docs, OIDC auth, container health, and aggregate health endpoint. Reusable by any Syslog agent. - hello-world.prose.md: Simple example contract demonstrating OpenProse function pattern with parameters, returns, and postconditions. diff --git a/hello-world.prose.md b/hello-world.prose.md new file mode 100644 index 0000000..b960d5a --- /dev/null +++ b/hello-world.prose.md @@ -0,0 +1,15 @@ +--- +kind: function +name: hello-world +description: A simple hello world contract to test OpenProse on pi +--- + +## Parameters +- name: string — The name to greet (default: "World") + +## Returns +- greeting: string — The generated greeting message + +## Ensures +- The greeting includes the provided name +- The greeting is friendly and warm diff --git a/litellm-health.prose.md b/litellm-health.prose.md new file mode 100644 index 0000000..ad538dc --- /dev/null +++ b/litellm-health.prose.md @@ -0,0 +1,56 @@ +--- +kind: function +name: check-litellm-health +description: > + Verifies LiteLLM deployment is healthy by checking admin UI, API docs, + OIDC auth endpoint, container status, and aggregate health on the + backend host. Designed as a reusable contract for any Syslog agent. +--- + +## Parameters + +- public_url: string — The public LiteLLM URL (default: "https://litellm.sysloggh.net") +- backend_host: string — Internal CT host to check containers (default: "192.168.68.116") +- auth_host: string — Authentik server for OIDC (default: "192.168.68.11") + +## Returns + +- overall_status: "healthy" | "degraded" | "down" +- checks: array of { name: string, status: string, detail: string } +- timestamp: string — ISO timestamp of the check run +- duration_ms: number — How long the check took + +## Requires + +- SSH key access to backend_host for container checks +- Network access to public_url and auth_host +- curl and openssl available on the execution host + +## Ensures + +- Each check returns a clear pass/fail status with detail message +- If any endpoint returns non-200, overall_status is "degraded" +- If backend host unreachable or >2 containers down, overall_status is "down" +- If /health/unified reports any non-healthy components, status reflects it +- Checks cover at minimum: admin UI, API docs, OIDC, containers, unified health, nginx proxy + +## Execution + +1. **Read parameters** — Use provided values or defaults +2. **Check public endpoints**: + - GET {{public_url}}/ui/ → expect 200 ("LiteLLM Dashboard") + - GET {{public_url}}/docs → expect 200 ("LiteLLM API - Swagger UI") + - GET {{public_url}}/openapi.json → expect 200 (valid JSON, 497 paths) + - GET {{public_url}}/redoc → expect 200 ("LiteLLM API - ReDoc") +3. **Check nginx-proxied endpoints** (internal only — Netbird routes to LiteLLM directly): + - GET http://{{backend_host}}/litellm/ui/ → expect 200 + - GET http://{{backend_host}}/litellm/docs → expect 200 +4. **Check aggregate health endpoint**: + - GET {{backend_host}}:9000/health/unified → expect 200, check all components +5. **Check backend container health**: + - SSH to {{backend_host}} → `docker ps` → verify all 6 containers are healthy + - Containers: harness-litellm, harness-nginx, harness-router, harness-postgres, harness-redis, harness-dashboard +6. **Check OIDC auth endpoint**: + - Verify auth.sysloggh.net resolves to {{auth_host}} + - GET https://auth.sysloggh.net/ → expect login page +7. **Compile and report** — Determine overall_status from individual check results