Remove the Anthropic path; the gateway speaks one wire protocol
Some checks failed
CI / test (push) Failing after 4m38s
CI / fixture (push) Failing after 7s

The platform now runs on Groq by default, through the OpenAI-compatible
chat-completions shape. That shape is not one vendor — Gemini, OpenRouter,
Together, vLLM and a local Ollama serve it too — so moving again stays
configuration rather than code.

Two things in the deleted file were not Anthropic's and would have gone
with it silently:

  withRetry / MaxAttempts / retryBackoff were defined in anthropic.go and
  CALLED BY openai.go. Deleting the file wholesale would have removed the
  retry policy of the provider that survived, and nothing in openai.go
  mentions it, so the loss would have been invisible until the next 429.
  The policy is a property of this platform's runs, not of a vendor's API;
  it now lives in retry.go where no provider can carry it off.

  StreamComplete had the same problem and moves to gateway.go, beside the
  Streamer interface whose comment already referenced it.

Three stale-configuration failures are now refused at startup instead of
being ignored. Each was verified firing through the real config.Load():

  MODEL_PROVIDER=anthropic — named separately from every other wrong value
  because it used to be correct. Ignoring it gives a stack that believes it
  is on Claude while every run goes to Groq and is billed there.

  ANTHROPIC_API_KEY set while MODEL_API_KEY is empty. Ignoring a key an
  operator did set is the worst version of this: they fail every run on a
  missing credential they are looking straight at.

  A leftover claude-* model id, naming the tier that carries it. This is
  the check the previous commit's error-detail work was diagnosing: such an
  id is accepted by this process, rejected by the provider, and 400s on
  EVERY run. "A model is wrong" does not say which of three lines to edit.

Defaults ship as a matched pair. defaultBaseURL and the three tier ids are
one decision, not four: an id is only meaningful against the service that
serves it, and a Groq id on an OpenAI base URL is the same failure from the
other side. The tiers also stop being one model — a tier whose cost does
not differ is a distinction that buys nothing.

Verified end to end against a stub of the wire, driving the real wiring
(config.Load in production mode, gateway.New, StreamComplete): streamed
deltas, tool-call decoding, the loopback credential exemption, and usage
totalling 150 rather than 190 — the cached-prefix subtraction still holds.

gofmt clean, go vet clean, 14/14 non-DB packages pass. httpserver still
needs a reachable database.

NOT verified: the I7 planted-injection eval. Removing this path removed the
only model whose refusal behaviour had been measured against it, so the new
default is unproven there until `make eval-live` runs with a real key. The
Groq model ids should also be confirmed against Groq's current lineup.
Flagged in CLAUDE.md §12 and docs/handover.md.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
This commit is contained in:
2026-09-05 11:52:21 +05:30
parent cf99866e12
commit 34fa58a6b9
18 changed files with 391 additions and 765 deletions

View File

@@ -64,46 +64,49 @@ SEED_FIXTURE_PATH=./seed/fixtures/seed.json
# mapping below is a deployment decision and changes without editing a single
# definition.
#
# WHICH PROVIDER ANSWERS is a deployment decision. Two wire protocols:
# WHICH PROVIDER ANSWERS is a deployment decision, but the wire protocol is no
# longer one. There is a single implementation:
#
# anthropic the Claude API. The default, and what an unset value means.
# openai the chat-completions shape — which is NOT only OpenAI. Groq,
# Gemini (through its OpenAI-compatible endpoint), OpenRouter,
# Together, vLLM and a local Ollama all serve it, so moving
# between them is MODEL_BASE_URL and MODEL_* ids, nothing more.
MODEL_PROVIDER=anthropic
# Where the openai-compatible provider points. IGNORED — and refused at
# startup — unless MODEL_PROVIDER=openai, because a base URL set against the
# anthropic provider is a deployment that believes it has switched and has not:
# every run would still go to Anthropic, and still be billed there.
#
# Groq https://api.groq.com/openai/v1
# The anthropic path was REMOVED. MODEL_PROVIDER=anthropic is refused at
# startup rather than ignored, because a stack still carrying it would
# otherwise run on a vendor it never chose. Leave this empty or set "openai".
MODEL_PROVIDER=openai
# Where the provider is. Defaults to Groq when unset — the model ids below are
# Groq ids, and an id is only meaningful against the service that serves it, so
# these two settings move together or not at all.
#
# Groq https://api.groq.com/openai/v1 (the default)
# Gemini https://generativelanguage.googleapis.com/v1beta/openai
# OpenRouter https://openrouter.ai/api/v1
# Ollama http://localhost:11434/v1 (no key needed)
MODEL_BASE_URL=
MODEL_BASE_URL=https://api.groq.com/openai/v1
# The credential. MODEL_API_KEY is the provider-neutral name and wins;
# ANTHROPIC_API_KEY still works so no existing deployment needs an edit.
# Either may be empty outside production: migrations, seeding and every
# endpoint that is not an agent run work without one, and an agent run fails
# with a structured `gateway.not_configured` rather than the service refusing
# to boot. APP_ENV=production requires one — unless the model is on localhost,
# which needs no credential at all.
# The credential. ANTHROPIC_API_KEY is NO LONGER READ — if it is set while this
# is empty, startup fails rather than silently ignoring it.
# May be empty outside production: migrations, seeding and every endpoint that
# is not an agent run work without one, and an agent run fails with a
# structured `gateway.not_configured` rather than the service refusing to boot.
# APP_ENV=production requires one — unless the model is on localhost, which
# needs no credential at all.
MODEL_API_KEY=
ANTHROPIC_API_KEY=
# All three tiers default to the same model. They differ by *effort*, which the
# gateway fixes (fast=low, balanced=high, deep=xhigh) so that "deep" cannot
# mean two different things in two deployments. Point a tier at a different
# model only as a deliberate choice — never as a silent cost downgrade.
MODEL_FAST=claude-opus-5
MODEL_BALANCED=claude-opus-5
MODEL_DEEP=claude-opus-5
# The tiers differ by model AND by *effort*, which the gateway fixes
# (fast=low, balanced=high, deep=xhigh) so that "deep" cannot mean two
# different things in two deployments.
#
# These must be ids your MODEL_BASE_URL actually serves. A leftover claude-*
# id is refused at startup: it would be accepted by this process, rejected by
# the provider, and fail every single run with a 400.
MODEL_FAST=llama-3.1-8b-instant
MODEL_BALANCED=llama-3.3-70b-versatile
MODEL_DEEP=llama-3.3-70b-versatile
# Hard ceiling on a single unstreamed response. Not the run's token budget —
# that spans every call in a run and belongs to the runtime.
MODEL_MAX_OUTPUT_TOKENS=16000
# Send the tier's effort level as `reasoning_effort` on the openai-compatible