Skip to content

llm-gateway-stack: demo UI key check passes when the gateway uses an external API-key Secret #2332

Description

@kristinapathak

Describe the bug

deploy/helm/llm-gateway-stack/llm-gateway-stack/templates/secret-demo-ui.yaml checks that demoUiApiKey is registered by looking for a matching demo-ui hash in .Values.apiKeys. When apiKeysSecret.create is false, the gateway reads a Secret the chart does not manage and ignores .Values.apiKeys. The check can then pass even though the external Secret has no demo-ui entry. The chart creates the demo-ui-api-key Secret, and the gateway rejects that key.

Steps or code to reproduce bug

  1. Set apiKeysSecret.create: false and provide your own key-file Secret without a demo-ui entry.
  2. Set demoUiApiKey, and add its demo-ui hash to apiKeys.
  3. Install the chart. The render succeeds and demo-ui-api-key is created.
  4. Call the gateway with the key from demo-ui-api-key. It returns 401.

Expected behavior

Either the chart rejects demoUiApiKey when apiKeysSecret.create is false, or it documents that the external Secret must contain the demo-ui hash, and the demo UI setup verifies that.

Additional context

Introduced with the demo UI key in #2322. Found during review of #2331, which does not change this chart.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingllm-stackLLM Gateway + Stargate Request Router + Vanity Gatewayneeds-triageIssue or PR awaiting maintainer triage

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions