-
-
Notifications
You must be signed in to change notification settings - Fork 34
Expand file tree
/
Copy pathinference_v1alpha1_modelrouter.yaml
More file actions
113 lines (107 loc) · 3.85 KB
/
Copy pathinference_v1alpha1_modelrouter.yaml
File metadata and controls
113 lines (107 loc) · 3.85 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
# Sample ModelRouter that exposes a single OpenAI-compatible endpoint
# fronting a local InferenceService and an external Anthropic backend.
#
# This sample shows the three things that make ModelRouter useful for
# regulated-industry enterprise adopters:
#
# 1. Per-rule routing by data classification, task complexity, and
# capabilities.
# 2. The fail-closed gate: sensitive-data requests can only ever
# reach local backends, regardless of upstream availability.
# 3. Composition with LiteLLM-style cloud-provider abstraction via a
# single Secret per credential.
#
# Apply order:
# 1. Create the InferenceService that local-qwen references.
# 2. Create the Secret with your Anthropic API key.
# 3. kubectl apply -f this file.
#
# Verify:
# kubectl describe modelrouter coding-router
# kubectl get configmap coding-router-router-proxy -o yaml
# curl -X POST http://coding-router-router-proxy.<ns>.svc.cluster.local:8080/v1/chat/completions \
# -H 'Content-Type: application/json' \
# -d '{"model":"any","messages":[{"role":"user","content":"hello"}]}'
---
# Stub Secret. Replace the placeholder with a real ANTHROPIC_API_KEY before
# applying, or omit the cloud-opus backend entirely until you have one.
apiVersion: v1
kind: Secret
metadata:
name: anthropic-key
type: Opaque
stringData:
ANTHROPIC_API_KEY: "REPLACE_WITH_YOUR_ANTHROPIC_API_KEY"
---
apiVersion: inference.llmkube.dev/v1alpha1
kind: ModelRouter
metadata:
name: coding-router
spec:
backends:
# Local InferenceService. The controller resolves this to its
# cluster URL automatically. The named InferenceService must exist
# in the same namespace.
- name: local-qwen
tier: local
inferenceServiceRef:
name: qwen3-coder
capabilities:
- code
- tools
# External Anthropic backend. The controller looks up the named
# Secret and injects ANTHROPIC_API_KEY into the router-proxy pod;
# the proxy reads it at request time and adds the right
# provider-specific auth header (x-api-key + anthropic-version for
# Anthropic).
- name: cloud-opus
tier: cloud
external:
provider: anthropic
model: claude-opus-4-7
url: https://api.anthropic.com
credentialsSecretRef:
name: anthropic-key
capabilities:
- code
- vision
- long-context
rules:
# The regulated-data gate. Any request carrying
# x-llmkube-classification: pii (or x-llmkube-classification: phi)
# routes ONLY to the local backend, with failClosed=true. If the
# local backend is unhealthy or scaled to zero, the router returns
# HTTP 503 rather than falling through. Sensitive data never
# leaves the cluster.
- name: pii-stays-local
match:
dataClassification: ["pii", "phi"]
route:
backends: ["local-qwen"]
failClosed: true
# Hard problems get the cloud model first, with the local backend
# as fallback. Header: x-llmkube-task-complexity: complex
- name: complex-to-cloud
match:
taskComplexity: complex
route:
backends: ["cloud-opus", "local-qwen"]
strategy: primary-fallback
# Catch-all when no rule fires. Most traffic should land here.
defaultRoute: local-qwen
policy:
classification:
# MVP supports header-only mode. The bundled detector (regex +
# optional NER) lands with the classifier feature.
mode: header-only
headerKey: x-llmkube-classification
# Override the default sensitive set ({pii, phi}) if your
# organization classifies data differently.
sensitiveClassifications: ["pii", "phi"]
auditLog:
sink: stdout
# Optional: per-ModelRouter overrides for the managed proxy
# Deployment. Omit the block entirely to use the controller defaults.
proxy:
replicas: 1
# image: registry.internal/llmkube-router-proxy:v0.8.0