Repository navigation
Gate task-level model routing behind experimental opt-in - #9033
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The gate is consistently enforced across validation, mapping, staging, Compose generation, and runtime orchestration with focused coverage.
Review effort: Balanced
Findings: None
What changed in this PR
Adds an explicit experimental gate for task-level model routing, keeping routing disabled unless both configuration fields are present.
Changes:
- Validates and maps
experimental.modelRouting. - Gates all routing staging, services, mounts, networks, and environment variables.
- Updates schemas, documentation, and focused tests.
| File | Description |
|---|---|
src/types/api-proxy-routing-options.ts |
Adds runtime gate option. |
src/services/optional-services.ts |
Gates router service creation. |
src/services/api-proxy-service-config.ts |
Gates routing mounts and networking. |
src/services/api-proxy-env-config.ts |
Gates proxy routing environment. |
src/services/api-proxy-env-config.test.ts |
Tests routing environment gating. |
src/schema-validator.ts |
Adds actionable gate validation error. |
src/routing/bootstrap.ts |
Gates conversation staging. |
src/routing/bootstrap.test.ts |
Tests default-off staging behavior. |
src/config-mapper.ts |
Maps the experimental setting. |
src/config-file.ts |
Adds the user-facing config type. |
src/config-file-validation.test.ts |
Tests strict gate validation. |
src/config-file-mapping.test.ts |
Tests gate mapping. |
src/compose-generator.ts |
Gates routing network creation. |
src/compose-generator.test.ts |
Tests routing infrastructure omission. |
src/commands/build-config.ts |
Carries the gate into runtime config. |
src/commands/build-config.test.ts |
Tests runtime config assembly. |
src/cli-workflow.ts |
Gates routing lifecycle hooks. |
src/cli-workflow.test.ts |
Tests disabled workflow behavior. |
src/awf-config-schema.json |
Updates the runtime schema. |
docs/awf-config.schema.json |
Updates the canonical public schema. |
docs/awf-config-spec.md |
Documents opt-in and migration syntax. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 7b79687 |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (2 files)
Coverage comparison generated by |
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
❌ Smoke Gemini reports failed. Facets need polishing... Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "play.googleapis.com"See Network Configuration for more information.
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
🚀 Security Guard has started processing this pull request |
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
Smoke Test: Cloud Hypervisor + Copilot
Result: All checks PASSED ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (api.github.com) reachable — HTTP 403 Overall: PASS
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
Smoke Test: Copilot BYOK (Direct) Mode ✅
Overall Status: PASS Running in direct BYOK mode (
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Smoke Test: Copilot Engine — PASS ✅
|
|
Smoke Test: Services Connectivity
Overall: PASS
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environment.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes
Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
Upgrade gh-aw and recompile workflows Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
Smoke Test: API Proxy OpenTelemetry Tracing — All Scenarios ✅
Overall: PASS. OTEL tracing pipeline (module init → span creation → env propagation → OTLP export through Squid) is functioning end-to-end with the live Sentry endpoint. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
Task-level model routing previously activated from
apiProxy.routingalone. This change requires an explicit experimental opt-in and rejects routing requests that omit it.experimental.modelRoutingvalidation and carry the gate into runtime config. The gate alone leaves routing inactive.