From 952331cdc7021fd06679e0a0073ab033595afdc2 Mon Sep 17 00:00:00 2001 From: Mikei386 <44135113+Mikei386@users.noreply.github.com> Date: Sat, 22 Aug 2026 18:45:13 +0200 Subject: [PATCH] Keep OpenWebUI provider credentials synchronized --- docs/INSTALLATION.md | 6 +++- platform/openwebui/install-models.sh | 41 ++++++++++++++++++++++++++++ 2 files changed, 46 insertions(+), 1 deletion(-) diff --git a/docs/INSTALLATION.md b/docs/INSTALLATION.md index bcf3efb..75af184 100644 --- a/docs/INSTALLATION.md +++ b/docs/INSTALLATION.md @@ -105,7 +105,11 @@ sudo /opt/mike-ai/stack/platform/openwebui/install-models.sh Danach sind nur die vier benannten MikeAI-Presets sichtbar; die rohen Router-Aliase sind ausgeblendet und Medium ist die Standardauswahl. Beide -Skripte sichern die OpenWebUI-Datenbank vor jeder Änderung. +Skripte sichern die OpenWebUI-Datenbank vor jeder Änderung. Der Modellinstaller +synchronisiert außerdem OpenWebUIs persistente OpenAI-kompatible Verbindung mit +dem internen Router und dessen aktuellem Schlüssel. Das ist erforderlich, weil +persistente Providerwerte nach einer Schlüsselrotation Vorrang vor den +Container-Umgebungsvariablen haben. ## Werkzeug-Container diff --git a/platform/openwebui/install-models.sh b/platform/openwebui/install-models.sh index 1b425b6..3ad82cc 100644 --- a/platform/openwebui/install-models.sh +++ b/platform/openwebui/install-models.sh @@ -4,6 +4,7 @@ umask 077 CONTAINER=${OPENWEBUI_CONTAINER:-mike-ai-open-webui} VOLUME=${OPENWEBUI_VOLUME:-mike-ai_open-webui-data} +ROUTER_KEY_FILE=${ROUTER_KEY_FILE:-/etc/mike-ai/router-api-key} die() { printf 'FEHLER: %s\n' "$*" >&2; exit 1; } [[ $EUID -eq 0 ]] || die "Bitte als root ausführen." @@ -29,8 +30,17 @@ backup=$volume_path/webui.db.before-model-install-$stamp cp -a "$db" "$backup" rm -f "$volume_path/webui.db-wal" "$volume_path/webui.db-shm" +# Keep Open WebUI's persistent provider connection in sync with the rotated +# router credential. Once a database exists, Open WebUI gives these values +# precedence over the container environment. +if [[ -r $ROUTER_KEY_FILE ]]; then + export OPENWEBUI_ROUTER_API_KEY + OPENWEBUI_ROUTER_API_KEY=$(<"$ROUTER_KEY_FILE") +fi + python3 - "$db" "${OPENWEBUI_MODEL_OWNER_ID:-}" <<'PY' import json +import os import sqlite3 import sys import time @@ -191,7 +201,38 @@ def upsert(model_id, base_model_id, name, model_params, meta, active=True): ), ) +def set_config(key, value): + con.execute( + """ + insert into config (key,value,updated_at) values (?,?,?) + on conflict(key) do update set + value=excluded.value, + updated_at=excluded.updated_at + """, + (key, json.dumps(value, ensure_ascii=False), now), + ) + with con: + router_api_key = os.environ.get("OPENWEBUI_ROUTER_API_KEY", "") + if router_api_key: + set_config("openai.enable", True) + set_config("openai.api_base_urls", ["http://router:8081/v1"]) + set_config("openai.api_keys", [router_api_key]) + set_config( + "openai.api_configs", + { + "0": { + "enable": True, + "tags": [], + "prefix_id": "", + "model_ids": [], + "connection_type": "external", + "auth_type": "bearer", + "passthrough_params": [], + } + }, + ) + # Hide the raw router aliases while keeping them resolvable as bases for # the user-facing workspace presets. for raw_id in ("qwen-fast", "qwen-medium", "qwen-large", "qwen-ultra"):