Keep OpenWebUI provider credentials synchronized
This commit is contained in:
@@ -105,7 +105,11 @@ sudo /opt/mike-ai/stack/platform/openwebui/install-models.sh
|
||||
|
||||
Danach sind nur die vier benannten MikeAI-Presets sichtbar; die rohen
|
||||
Router-Aliase sind ausgeblendet und Medium ist die Standardauswahl. Beide
|
||||
Skripte sichern die OpenWebUI-Datenbank vor jeder Änderung.
|
||||
Skripte sichern die OpenWebUI-Datenbank vor jeder Änderung. Der Modellinstaller
|
||||
synchronisiert außerdem OpenWebUIs persistente OpenAI-kompatible Verbindung mit
|
||||
dem internen Router und dessen aktuellem Schlüssel. Das ist erforderlich, weil
|
||||
persistente Providerwerte nach einer Schlüsselrotation Vorrang vor den
|
||||
Container-Umgebungsvariablen haben.
|
||||
|
||||
## Werkzeug-Container
|
||||
|
||||
|
||||
@@ -4,6 +4,7 @@ umask 077
|
||||
|
||||
CONTAINER=${OPENWEBUI_CONTAINER:-mike-ai-open-webui}
|
||||
VOLUME=${OPENWEBUI_VOLUME:-mike-ai_open-webui-data}
|
||||
ROUTER_KEY_FILE=${ROUTER_KEY_FILE:-/etc/mike-ai/router-api-key}
|
||||
|
||||
die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; }
|
||||
[[ $EUID -eq 0 ]] || die "Bitte als root ausführen."
|
||||
@@ -29,8 +30,17 @@ backup=$volume_path/webui.db.before-model-install-$stamp
|
||||
cp -a "$db" "$backup"
|
||||
rm -f "$volume_path/webui.db-wal" "$volume_path/webui.db-shm"
|
||||
|
||||
# Keep Open WebUI's persistent provider connection in sync with the rotated
|
||||
# router credential. Once a database exists, Open WebUI gives these values
|
||||
# precedence over the container environment.
|
||||
if [[ -r $ROUTER_KEY_FILE ]]; then
|
||||
export OPENWEBUI_ROUTER_API_KEY
|
||||
OPENWEBUI_ROUTER_API_KEY=$(<"$ROUTER_KEY_FILE")
|
||||
fi
|
||||
|
||||
python3 - "$db" "${OPENWEBUI_MODEL_OWNER_ID:-}" <<'PY'
|
||||
import json
|
||||
import os
|
||||
import sqlite3
|
||||
import sys
|
||||
import time
|
||||
@@ -191,7 +201,38 @@ def upsert(model_id, base_model_id, name, model_params, meta, active=True):
|
||||
),
|
||||
)
|
||||
|
||||
def set_config(key, value):
|
||||
con.execute(
|
||||
"""
|
||||
insert into config (key,value,updated_at) values (?,?,?)
|
||||
on conflict(key) do update set
|
||||
value=excluded.value,
|
||||
updated_at=excluded.updated_at
|
||||
""",
|
||||
(key, json.dumps(value, ensure_ascii=False), now),
|
||||
)
|
||||
|
||||
with con:
|
||||
router_api_key = os.environ.get("OPENWEBUI_ROUTER_API_KEY", "")
|
||||
if router_api_key:
|
||||
set_config("openai.enable", True)
|
||||
set_config("openai.api_base_urls", ["http://router:8081/v1"])
|
||||
set_config("openai.api_keys", [router_api_key])
|
||||
set_config(
|
||||
"openai.api_configs",
|
||||
{
|
||||
"0": {
|
||||
"enable": True,
|
||||
"tags": [],
|
||||
"prefix_id": "",
|
||||
"model_ids": [],
|
||||
"connection_type": "external",
|
||||
"auth_type": "bearer",
|
||||
"passthrough_params": [],
|
||||
}
|
||||
},
|
||||
)
|
||||
|
||||
# Hide the raw router aliases while keeping them resolvable as bases for
|
||||
# the user-facing workspace presets.
|
||||
for raw_id in ("qwen-fast", "qwen-medium", "qwen-large", "qwen-ultra"):
|
||||
|
||||
Reference in New Issue
Block a user