Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 22 additions & 1 deletion helm-charts/bifrost/templates/_helpers.tpl
Original file line number Diff line number Diff line change
Expand Up @@ -443,6 +443,18 @@ false
{{- end }}
{{- $_ := set $governance "business_units" $businessUnits }}
{{- end }}
{{- if .Values.bifrost.governance.roles }}
{{- $roles := list }}
{{- range .Values.bifrost.governance.roles }}
{{- $role := dict "name" .name }}
{{- if .description }}{{- $_ := set $role "description" .description }}{{- end }}
{{- if .dac }}{{- $_ := set $role "dac" .dac }}{{- end }}
{{- if .access_profile }}{{- $_ := set $role "access_profile" .access_profile }}{{- end }}
{{- if .permissions }}{{- $_ := set $role "permissions" .permissions }}{{- end }}
{{- $roles = append $roles $role }}
{{- end }}
{{- $_ := set $governance "roles" $roles }}
{{- end }}
Comment thread
BearTS marked this conversation as resolved.
Comment thread
coderabbitai[bot] marked this conversation as resolved.
{{- if .Values.bifrost.governance.virtualKeys }}
{{- $vks := list }}
{{- range .Values.bifrost.governance.virtualKeys }}
Expand Down Expand Up @@ -494,7 +506,7 @@ false
{{- $_ := set $governance "auth_config" $authConfig }}
{{- end }}
{{- end }}
{{- if or $governance.budgets $governance.rate_limits $governance.customers $governance.teams $governance.business_units $governance.virtual_keys $governance.routing_rules $governance.model_configs $governance.providers $governance.pricing_overrides $governance.auth_config }}
{{- if or $governance.budgets $governance.rate_limits $governance.customers $governance.teams $governance.business_units $governance.roles $governance.virtual_keys $governance.routing_rules $governance.model_configs $governance.providers $governance.pricing_overrides $governance.auth_config }}
{{- $_ := set $config "governance" $governance }}
{{- end }}
{{- end }}
Expand Down Expand Up @@ -1617,6 +1629,15 @@ Call this template at the beginning of deployment/stateful templates
{{- end }}
{{- end }}

{{/* Validate governance roles */}}
{{- if .Values.bifrost.governance.roles }}
{{- range $idx, $role := .Values.bifrost.governance.roles }}
{{- if not $role.name }}
{{- fail (printf "ERROR: bifrost.governance.roles[%d].name is required." $idx) }}
{{- end }}
{{- end }}
{{- end }}

{{/* Validate guardrails rules */}}
{{- if .Values.bifrost.guardrails.rules }}
{{- range $idx, $rule := .Values.bifrost.guardrails.rules }}
Expand Down
36 changes: 36 additions & 0 deletions helm-charts/bifrost/values.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -1135,6 +1135,42 @@
"required": ["id", "name"]
}
},
"roles": {
"type": "array",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string"
},
"description": {
"type": "string"
},
"dac": {
"type": "string",
"enum": ["own-data", "team-data", "all-data"],
"default": "all-data"
},
"access_profile": {
"type": "string"
},
"permissions": {
"type": "array",
"items": {
"type": "object",
"properties": {
"resource": { "type": "string" },
"operation": { "type": "string" }
},
"required": ["resource", "operation"],
"additionalProperties": false
}
}
},
"required": ["name"],
"additionalProperties": false
}
Comment thread
coderabbitai[bot] marked this conversation as resolved.
},
"virtualKeys": {
"type": "array",
"items": {
Expand Down
21 changes: 21 additions & 0 deletions helm-charts/bifrost/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -383,6 +383,15 @@ bifrost:
# tlsConfig:
# insecureSkipVerify: false # Disable TLS verification (dev/test only — takes priority over caCertPem)
# caCertPem: "env.MY_MCP_CA_CERT" # PEM string or env.VAR_NAME reference
#
# - name: "example-oauth-mcp"
# connectionType: "http"
# connectionString: "https://my-mcp.corp/mcp"
# # authType "oauth": shared OAuth token; provide oauthConfigId referencing an existing oauth_config.
# # authType "per_user_oauth": each user authenticates individually via OAuth flow;
# # oauth_config is registered via the API (POST /api/mcp/clients), not configured here.
# authType: "oauth"
# oauthConfigId: "my-oauth-config-id" # ID of the OAuth config created in Bifrost
# toolSyncInterval: "10m" # Global tool sync interval (Go duration string, e.g. "10m", "1h", "0s")
# Tool manager configuration
toolManagerConfig:
Expand Down Expand Up @@ -526,6 +535,18 @@ bifrost:
# profile: {} # Team profile data
# config: {} # Team configuration data
# claims: {} # Team claims data
roles: []
# - name: "data-analyst"
# description: "Read-only access for data analysts"
# dac: "team-data" # own-data | team-data | all-data (default: all-data)
# access_profile: "analyst-profile" # Optional: name of an access_profile to attach
# permissions:
# - resource: "Logs"
# operation: "View"
# - resource: "Metrics"
# operation: "View"
# - resource: "VirtualKeys"
# operation: "View"
Comment thread
BearTS marked this conversation as resolved.
virtualKeys: []
# - id: "vk-1"
# name: "Virtual Key 1"
Expand Down
48 changes: 48 additions & 0 deletions transports/config.schema.json
Original file line number Diff line number Diff line change
Expand Up @@ -605,6 +605,54 @@
"additionalProperties": false
}
},
"roles": {
"type": "array",
"description": "RBAC role definitions. Roles are created or updated on startup if the config hash changes; system roles and dashboard-created roles are never deleted.",
"items": {
"type": "object",
"properties": {
"name": {
"type": "string",
"description": "Unique role name"
},
"description": {
"type": "string",
"description": "Human-readable description of the role"
},
"dac": {
"type": "string",
"description": "Data Access Control scope: own-data (user's own records), team-data (user's team records), all-data (unrestricted). Defaults to all-data.",
"enum": ["own-data", "team-data", "all-data"],
"default": "all-data"
},
"access_profile": {
"type": "string",
"description": "Name of the access profile (defined in access_profiles) to attach as the default for this role. Changing this field triggers a re-sync on next startup. Leave unset to let the dashboard manage the assignment."
},
"permissions": {
"type": "array",
"description": "List of resource+operation permission pairs to grant to this role",
"items": {
"type": "object",
"properties": {
"resource": {
"type": "string",
"description": "Permission resource (e.g. Logs, VirtualKeys, Users, ModelProvider, Metrics, Guardrails, AccessProfiles, MCPToolGroups, Roles, BusinessUnits, AuditLogs, Billing)"
},
"operation": {
"type": "string",
"description": "Permission operation (e.g. View, Create, Update, Delete, Download, RunInference, ManageInference, ViewInference)"
}
},
Comment thread
greptile-apps[bot] marked this conversation as resolved.
"required": ["resource", "operation"],
"additionalProperties": false
}
}
},
"required": ["name"],
"additionalProperties": false
}
},
Comment thread
coderabbitai[bot] marked this conversation as resolved.
"virtual_keys": {
"type": "array",
"description": "Virtual key configurations",
Expand Down
Loading