Remove the Anthropic path; the gateway speaks one wire protocol
The platform now runs on Groq by default, through the OpenAI-compatible chat-completions shape. That shape is not one vendor — Gemini, OpenRouter, Together, vLLM and a local Ollama serve it too — so moving again stays configuration rather than code. Two things in the deleted file were not Anthropic's and would have gone with it silently: withRetry / MaxAttempts / retryBackoff were defined in anthropic.go and CALLED BY openai.go. Deleting the file wholesale would have removed the retry policy of the provider that survived, and nothing in openai.go mentions it, so the loss would have been invisible until the next 429. The policy is a property of this platform's runs, not of a vendor's API; it now lives in retry.go where no provider can carry it off. StreamComplete had the same problem and moves to gateway.go, beside the Streamer interface whose comment already referenced it. Three stale-configuration failures are now refused at startup instead of being ignored. Each was verified firing through the real config.Load(): MODEL_PROVIDER=anthropic — named separately from every other wrong value because it used to be correct. Ignoring it gives a stack that believes it is on Claude while every run goes to Groq and is billed there. ANTHROPIC_API_KEY set while MODEL_API_KEY is empty. Ignoring a key an operator did set is the worst version of this: they fail every run on a missing credential they are looking straight at. A leftover claude-* model id, naming the tier that carries it. This is the check the previous commit's error-detail work was diagnosing: such an id is accepted by this process, rejected by the provider, and 400s on EVERY run. "A model is wrong" does not say which of three lines to edit. Defaults ship as a matched pair. defaultBaseURL and the three tier ids are one decision, not four: an id is only meaningful against the service that serves it, and a Groq id on an OpenAI base URL is the same failure from the other side. The tiers also stop being one model — a tier whose cost does not differ is a distinction that buys nothing. Verified end to end against a stub of the wire, driving the real wiring (config.Load in production mode, gateway.New, StreamComplete): streamed deltas, tool-call decoding, the loopback credential exemption, and usage totalling 150 rather than 190 — the cached-prefix subtraction still holds. gofmt clean, go vet clean, 14/14 non-DB packages pass. httpserver still needs a reachable database. NOT verified: the I7 planted-injection eval. Removing this path removed the only model whose refusal behaviour had been measured against it, so the new default is unproven there until `make eval-live` runs with a real key. The Groq model ids should also be confirmed against Groq's current lineup. Flagged in CLAUDE.md §12 and docs/handover.md. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
This commit is contained in:
19
CLAUDE.md
19
CLAUDE.md
@@ -224,7 +224,7 @@ depends on the curated-versus-self-serve decision and is not settled.
|
||||
| Registry | 9 agents + 24 skills as rows; published versions immutable (append-only, trigger-enforced); runs pin the version they started with |
|
||||
| Tools | 19, two of which write (`move_application`, `assign_worker`), behind a bound single-use confirmation |
|
||||
| Knowledge | ACL-tagged ingest, hybrid dense + BM25 fused with RRF, pre-filtered |
|
||||
| Gateway | tier → model + effort, token accounting, refusal as an outcome; two providers behind one interface — `anthropic`, and `openai` for the chat-completions shape that Groq, Gemini, OpenRouter, vLLM and a local Ollama all serve |
|
||||
| Gateway | tier → model + effort, token accounting, refusal as an outcome; one wire protocol — `openai`, the chat-completions shape that Groq (the default), Gemini, OpenRouter, Together, vLLM and a local Ollama all serve. The Anthropic path was removed; `MODEL_PROVIDER=anthropic`, a stale `ANTHROPIC_API_KEY` and a leftover `claude-*` id are each refused at startup rather than ignored |
|
||||
|
||||
**Conversational writes are not agent tool calls.** Two skills — `create-position`
|
||||
and `create-employee-role` — collect a record through the chat panel and then
|
||||
@@ -261,12 +261,17 @@ Do not resolve these unilaterally. Flag them and ask.
|
||||
|
||||
- **Who authors agents?** Curated (the team ships specs) vs. self-serve (tenants author their own). Self-serve requires prompt-injection hardening at the authoring boundary, per-tenant cost caps, an approval workflow, and a sandbox — roughly 3× the platform. Current assumption: **curated**, with the registry designed so self-serve is additive later.
|
||||
- **Model hosting.** Self-hosted vs. API vs. mixed by tier. **Still open** —
|
||||
but no longer expensive to change: `MODEL_PROVIDER` + `MODEL_BASE_URL` move
|
||||
the whole platform between Anthropic, Groq, Gemini, OpenRouter and a local
|
||||
Ollama without a code change, and `make eval-live` runs the suite against
|
||||
whichever is configured. Decide it on the eval evidence, and weigh the I7
|
||||
case heaviest: a cheaper model that follows the planted injection is a
|
||||
security regression, not a saving.
|
||||
but no longer expensive to change: `MODEL_BASE_URL` + the three `MODEL_*` ids
|
||||
move the whole platform between Groq (the default), Gemini, OpenRouter,
|
||||
Together, vLLM and a local Ollama without a code change, and `make eval-live`
|
||||
runs the suite against whichever is configured. Decide it on the eval
|
||||
evidence, and weigh the I7 case heaviest: a cheaper model that follows the
|
||||
planted injection is a security regression, not a saving.
|
||||
|
||||
**This is now urgent rather than open.** Removing the Anthropic path also
|
||||
removed the only model whose behaviour on that I7 case had actually been
|
||||
measured here, so the current default is unproven against it until
|
||||
`make eval-live` has been run with a real key.
|
||||
- **Confirmation UX.** Inline in-chat vs. an approval queue.
|
||||
|
||||
---
|
||||
|
||||
Reference in New Issue
Block a user