* feat(vertex_ai): support explicit AWS credentials for WIF auth The current Vertex AI AWS Workload Identity Federation implementation exclusively uses google.auth.aws.Credentials.from_info(), which requires EC2 instance metadata access to obtain AWS credentials. In environments where the metadata service is blocked for security reasons, this makes WIF unusable. Add support for explicit AWS credentials by implementing a custom AwsSecurityCredentialsSupplier (google-auth >= 2.29.0). When aws_* keys (e.g. aws_role_name, aws_region_name) are present in the WIF credential JSON, LiteLLM uses BaseAWSLLM.get_credentials() to obtain AWS creds via STS AssumeRole (or any other supported AWS auth flow), wraps them in the custom supplier, and passes them to aws.Credentials() — bypassing the metadata service entirely. When no aws_* keys are present, the existing from_info() flow is used unchanged, preserving full backward compatibility. * refactor(vertex_ai): extract AWS WIF auth to own class + add docs Address PR review feedback: - Move _AWS_CREDENTIAL_KEYS, _extract_aws_params(), and _credentials_from_aws_with_explicit_auth() from VertexBase into new VertexAIAwsWifAuth class in vertex_ai_aws_wif.py - Add documentation for explicit AWS credentials WIF auth method in vertex.md (supported params, JSON example, SDK/Proxy tabs) Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com> * fix(vertex_ai): use lazy credentials provider to prevent stale STS tokens --------- Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| blog | ||
| docs | ||
| img | ||
| release_notes | ||
| src | ||
| static | ||
| .gitignore | ||
| .trivyignore | ||
| babel.config.js | ||
| Dockerfile | ||
| docusaurus.config.js | ||
| index.md | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| sidebars.js | ||
Website
This website is built using Docusaurus 2, a modern static website generator.
Installation
$ yarn
Local Development
$ yarn start
This command starts a local development server and opens up a browser window. Most changes are reflected live without having to restart the server.
Build
$ yarn build
This command generates static content into the build directory and can be served using any static contents hosting service.
Deployment
Using SSH:
$ USE_SSH=true yarn deploy
Not using SSH:
$ GIT_USER=<Your GitHub username> yarn deploy
If you are using GitHub pages for hosting, this command is a convenient way to build the website and push to the gh-pages branch.