Repository navigation
fix(ci): let the install smoke test boot its key-less proxy config - #42296
Conversation
The install smoke test starts the proxy on test_config_no_auth.yaml, which has no master key on purpose, and #42019's boot check now refuses that, so the three installing_litellm_on_python jobs have been red on main since 2026-09-20. Pass the documented local-dev override to the proxy child so the test keeps its no-auth config and the boot check stays as it is
|
I'll fix CI failures and address comments from users with write access. I'll skip comments containing "(aside)".
|
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
bugbot run |
There was a problem hiding this comment.
✅ Bugbot reviewed your changes and found no new issues!
Comment @cursor review or bugbot run to trigger another review on this PR
Reviewed by Cursor Bugbot for commit a8745f2. Configure here.
TLDR
Problem this solves:
installing_litellm_on_pythonx3 red on main since 2026-09-20test_config_no_auth.yaml, which has no master keyGET /health/livelinessgets connection refusedHow it solves it:
LITELLM_DANGEROUSLY_PERMIT_WEAK_OR_UNSET_MASTER_KEY=trueto the proxy it startsUser Flow
Before: a contributor pushes any commit to main or a
run-ciPR and CircleCI reports the threeinstalling_litellm_on_pythonjobs red, although their change touched nothing near the proxy's installinstalling_litellm_on_python,installing_litellm_on_python_3_13, andinstalling_litellm_on_python_v2_migration_resolverredFAILED tests/local_testing/test_basic_python_version.py::test_litellm_proxy_server_config_no_general_settings - Failed: Failed to connect to the serverLiteLLM proxy refused to start: no master key is set, so every request would be accepted without authenticationand exited, so the test'sGET http://localhost:4000/health/livelinessgot connection refusedAfter: the same push turns the three jobs green
test_litellm_proxy_server_config_no_general_settings PASSEDand7 passed, 1 deselectedGET http://localhost:4000/health/livelinessreturns 200"I'm alive!", and itsPOST http://localhost:4000/chat/completionswithAuthorization: Bearer 1234567890returns 200Relevant issues
Follow-up to #42019 (the boot check). #42120 fixed the same class for the Google proxy fixture by giving its config a real key; this test cannot take that shape, since it asserts a made-up bearer token is accepted by the key-less proxy and ten other tests share its yaml, so it uses the documented local-dev override in the child's env instead
Affected release
Linear ticket
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/test_litellm/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more@greptileaito re-request a review after pushing changes)Delays in PR merge?
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).
Screenshots / Proof of Fix
The smoke test hardcodes
http://localhost:4000and the proxy it starts reads the repo's.env, so both runs happened in a throwaway Linux container that replays the CircleCI job as is: python 3.12, uv 0.10.9 and rust 1.98.0 installed the way.circleci/config.ymldoes (sha256-checked), the repo copied in without.env,.git, or.venv, and only the env names the CircleCI project also defines (OPENAI_API_KEY,AZURE_AI_API_KEY,AZURE_AI_API_BASE). NoLITELLM_*variable is set anywhere in the container; the run prints that before pytest starts. Install step, identical on both sides:The three CircleCI jobs on this PR's tip are the x86_64 run of the same thing; their links are in the After section.
Before (9a90ada)
env | grep -E "^LITELLM_" | cut -d= -f1 || echo "(none)"printed(none), andss -ltnp | grep ":4000 "printed(none)uv run --no-sync python -m pytest -vv tests/local_testing/test_basic_python_version.py -k "not legacy_resolver"Observed: the proxy the test started exited before the health check, with this in its stderr
Observed: the test's
GET http://localhost:4000/health/livelinessgot connection refusedAfter (a8745f2)
env | grep -E "^LITELLM_" | cut -d= -f1 || echo "(none)"printed(none), andss -ltnp | grep ":4000 "printed(none)uv run --no-sync python -m pytest -vv tests/local_testing/test_basic_python_version.py -k "not legacy_resolver"Observed: the proxy stayed up,
GET http://localhost:4000/health/livelinessreturned 200"I'm alive!", andPOST http://localhost:4000/chat/completionswithAuthorization: Bearer 1234567890returned 200 (a realgpt-3.5-turbocall through the test'stest_openai_modelsdeployment)CircleCI on this tip, x86_64
cimg/python: installing_litellm_on_python, installing_litellm_on_python_3_13, and installing_litellm_on_python_v2_migration_resolver are all green, where the same three jobs were red on every main pipeline since 2026-09-20Type
🐛 Bug Fix
✅ Test
Caveats (if any)
Low
run-cibuildlitellmat collection timecimg/python:3.12; the CI jobs on this PR's tip are the x86_64 runlocal_testing_part1is red on this tip ontest_get_model_info_bedrock_cross_region_capability_parityandtest_get_model_info_bedrock_models(supports_audio_inputmissing from two Bedrock cost map rows). Main's own pipeline 89979 (job 2196579) fails the same two tests, so it is fleet-wide and not from this PR, which touches no cost map rowllm_translation_testingis red on this tip on tentests/llm_translation/test_fireworks_ai_translation.pytests; main's pipeline 89979 (job 2196570) fails the same ten, so it is fleet-wide and not from this PRtest_bad_database_urlis red on this tip withExpected error not found. Test failed.after the proxy printed Prisma'sP1001: Can't reach database server; main's pipeline 89979 (job 2196551) fails the same way with the same output, so it is fleet-wide and not from this PR, which touches no proxy codeunitis red on this tip on twelvetests/unit/router_strategy/complexity_router/test_jev_classifier.pytests (RuntimeError: <asyncio.locks.Event> is bound to a different event loopfromGLOBAL_LOGGING_WORKER.flush()). Those tests landed on main in feat(auto-router): add JEV classifier alongside LLM classifier #41886 (a83773c, six minutes before this branch's merge base 9a90ada), no main pipeline has run a tip containing it yet (the latest, 89979, is at cc1a315), and the three other branches whose merge base contains it (pipelines 895046cf, 62b51c91, 16e36045) fail the same twelve while every branch based before it fails none. This PR touches no unit test and nothing the unit job runsFinal Attestation
The tests check the right things, including the edge cases, and regressions in the respective real-world customer use-cases are not possible after this PR
a8745f2 passes /live-pr-risk