Skip to content

Gateway - Check new settings against new secrets - #138

Open
awheeler294 wants to merge 2 commits into
masterfrom
gateway-restart-to-apply
Open

awheeler294 wants to merge 2 commits into
masterfrom
gateway-restart-to-apply

Conversation

@awheeler294

Copy link
Copy Markdown
Contributor

This is the first part of a series of improvements to config handling in the Gateway, the full plan is in vibe/2026-10-06-1-restart-to-apply.md

Check new settings against new secrets

Currently, adding a model from the Cloud Models page fails if its provider's API key was entered on the Secrets tab after the gateway started, even once that key has been applied. After this change config edits will be checked against both current keys and any pending 'Saved' or 'Applied' keys, so the model can be added straight with its key without a restart.

Problem

A new provider's API key cannot be used until the gateway has restarted with it:

  1. Start with no ANTHROPIC_API_KEY defined on the secrets tab.
  2. Add an ANTHROPIC_API_KEY and save. Optionally click 'Apply'
  3. On the Cloud Models page, pick an Anthropic model and click Add Model.
  4. The save is refused with UnresolvedVar for ANTHROPIC_API_KEY, and nothing is staged.

After 'Save' the value is stored in gateway.env.next, and after 'Apply' it's in gateway.env, but in either case the running process has not read it. The Gateway only reads it's config at startup, and does not "remember" newly added keys, and only validates cloud providers against the keys it read at boot.

Solution

This change adds a PendingEnv struct that allows the validation to check against pending values that have been 'Saved' and 'Applied'. Functions responsible for interpolating config variables get an argument that lets the inject a function to control what environment they are reading from (current or pending)

@awheeler294 awheeler294 self-assigned this Oct 9, 2026

Copy link
Copy Markdown
Member

This sounds ok, I wouldn't overthink it, we know the Gateway has significant problems in its config model.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants