chore(ct116): capture production state (LiteLLM 1.99.1, nginx /ui //docs, router decommission, trove agent)
This commit is contained in:
+63
-59
@@ -8,28 +8,20 @@ http {
|
||||
sendfile on;
|
||||
keepalive_timeout 65;
|
||||
|
||||
# Docker DNS resolver — forces request-time resolution for variable-based proxy_pass.
|
||||
# Without this, nginx resolves upstream hostnames at config load time,
|
||||
# which fails when Docker DNS (127.0.0.11) isn't ready yet on container start.
|
||||
resolver 127.0.0.11 valid=30s;
|
||||
|
||||
# Dynamic upstream resolution via nginx variables.
|
||||
# Using $var in proxy_pass forces request-time resolution through the resolver.
|
||||
# Without this, 'host not found in upstream' crashes nginx when Docker DNS is slow.
|
||||
map $host $router_api_url {
|
||||
default http://harness-router:9000;
|
||||
}
|
||||
map $host $dashboard_ui_url {
|
||||
default http://harness-dashboard:3000;
|
||||
}
|
||||
map $host $litellm_backend_url {
|
||||
default http://harness-litellm:4000;
|
||||
}
|
||||
# ════════════════════════════════════════════════════════════════
|
||||
# Server :80 — harness entrypoint
|
||||
# dashboard (/), router API (/v1/, /admin/, /stream, /api/, /metrics),
|
||||
# router fallback, health
|
||||
# ════════════════════════════════════════════════════════════════
|
||||
|
||||
# ════════════════════════════════════════════════════════════
|
||||
# Server :80 — Lean single-layer entrypoint
|
||||
# All API paths route directly to LiteLLM.
|
||||
# harness-router fully deprecated.
|
||||
# ════════════════════════════════════════════════════════════
|
||||
server {
|
||||
listen 80;
|
||||
|
||||
@@ -43,67 +35,72 @@ http {
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
}
|
||||
|
||||
# 2-Layer: /v1/ → router (existing keys work unchanged)
|
||||
# ── LiteLLM API (replaces router /v1/) ──
|
||||
location /v1/ {
|
||||
proxy_pass $router_api_url;
|
||||
proxy_pass $litellm_backend_url;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header Authorization $http_authorization;
|
||||
proxy_connect_timeout 10s;
|
||||
proxy_read_timeout 600s;
|
||||
proxy_buffering off;
|
||||
error_page 502 503 = @router_fallback;
|
||||
}
|
||||
|
||||
location @router_fallback {
|
||||
proxy_pass $router_api_url;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header Authorization $http_authorization;
|
||||
proxy_read_timeout 600s;
|
||||
}
|
||||
|
||||
# ── LiteLLM admin (replaces router /admin/) ──
|
||||
location /admin/ {
|
||||
proxy_pass $router_api_url;
|
||||
proxy_pass $litellm_backend_url;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header Authorization $http_authorization;
|
||||
proxy_read_timeout 600s;
|
||||
}
|
||||
|
||||
# ── LiteLLM stream ──
|
||||
location /stream {
|
||||
proxy_pass $router_api_url/stream;
|
||||
proxy_pass $litellm_backend_url/stream;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_buffering off;
|
||||
}
|
||||
|
||||
# ── API passthrough ──
|
||||
location /api/ {
|
||||
proxy_pass $router_api_url/;
|
||||
proxy_pass $litellm_backend_url/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
}
|
||||
|
||||
|
||||
|
||||
# ── Dashboard ──
|
||||
location /dashboard/ {
|
||||
proxy_pass $dashboard_ui_url/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
}
|
||||
|
||||
# LiteLLM redirect target /litellm (no trailing slash) -> add slash back
|
||||
# ── GPU Fleet Dashboard ──
|
||||
location /gpu/ {
|
||||
proxy_pass http://192.168.68.24:9100/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_read_timeout 60s;
|
||||
}
|
||||
|
||||
# ── LiteLLM redirect ──
|
||||
location = /litellm {
|
||||
return 301 /litellm/;
|
||||
}
|
||||
|
||||
# LiteLLM static assets (Next.js chunks, CSS, fonts)
|
||||
# ── Health: redirect /health (auth-required) → /health/liveliness (no-auth) ──
|
||||
location = /litellm/health {
|
||||
return 301 /litellm/health/liveliness;
|
||||
}
|
||||
|
||||
# ── LiteLLM static assets ──
|
||||
location /litellm-asset-prefix/ {
|
||||
proxy_pass $litellm_backend_url;
|
||||
proxy_http_version 1.1;
|
||||
@@ -113,20 +110,22 @@ http {
|
||||
proxy_read_timeout 60s;
|
||||
}
|
||||
|
||||
# LiteLLM admin UI and API proxy — strip /litellm prefix so /litellm/ui/ → /ui/
|
||||
# ── LiteLLM admin UI and API (strips /litellm prefix) ──
|
||||
location /litellm/ {
|
||||
rewrite ^/litellm(/.*)$ $1 break;
|
||||
proxy_pass $litellm_backend_url;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_buffering off;
|
||||
proxy_read_timeout 600s;
|
||||
proxy_set_header Authorization $http_authorization;
|
||||
}
|
||||
|
||||
# Auth proxy to Authentik — accepts HTTP from LiteLLM, proxies HTTPS to .11 with SSL verify off
|
||||
# ── Auth proxy to Authentik ──
|
||||
location /application/o/ {
|
||||
proxy_pass https://192.168.68.11;
|
||||
proxy_ssl_verify off;
|
||||
@@ -136,40 +135,45 @@ http {
|
||||
proxy_read_timeout 30s;
|
||||
}
|
||||
|
||||
# All other requests → 404
|
||||
location / {
|
||||
return 404;
|
||||
}
|
||||
|
||||
location /metrics/ {
|
||||
proxy_pass $router_api_url/metrics/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
}
|
||||
|
||||
location /metrics/circuit-breaker {
|
||||
proxy_pass $router_api_url/metrics/circuit-breaker;
|
||||
# ── Prometheus metrics (LiteLLM exposes at /metrics) ──
|
||||
location /metrics {
|
||||
proxy_pass $litellm_backend_url/metrics;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
}
|
||||
|
||||
# ── Router paths — deprecated, redirect to equivalents ──
|
||||
location /router/ {
|
||||
proxy_pass $router_api_url/;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
return 301 /litellm/;
|
||||
}
|
||||
|
||||
location /health/unified {
|
||||
proxy_pass $router_api_url/health/unified;
|
||||
return 301 /gpu/gpu-data;
|
||||
}
|
||||
|
||||
location /metrics/circuit-breaker {
|
||||
return 410;
|
||||
}
|
||||
|
||||
# ── Health: no-auth LiteLLM liveliness ──
|
||||
location /health {
|
||||
proxy_pass $litellm_backend_url/health/liveliness;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
}
|
||||
|
||||
location /health {
|
||||
proxy_pass $router_api_url/health;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Host $host;
|
||||
|
||||
# ── UI / Docs convenience redirects (additive 2026-09-11) ──
|
||||
# Canonical app path is /litellm/. These 301s make bare
|
||||
# /ui/ and /docs resolve. No new auth surface; no OIDC impact.
|
||||
location = /ui { return 301 /litellm/ui/; }
|
||||
location /ui/ { return 301 /litellm$request_uri; }
|
||||
location = /docs { return 301 /litellm/docs; }
|
||||
location = /docs/ { return 301 /litellm/docs; }
|
||||
|
||||
# ── 404 for everything else ──
|
||||
location / {
|
||||
return 404;
|
||||
}
|
||||
}
|
||||
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user