Fleet changelogs · dev.ecs0.net
rdmsm4x-changelog-20260827-0518-litellm-loopback-canary

rdmsm4x-changelog-20260827-0518-litellm-loopback-canary

Implemented and verified the approved LiteLLM credential-free loopback canary so the local routing design has a reversible, content-free acceptance path before any provider, database, key, or client work.

Scope

Project files changed

The project was initialized as a standalone Git repository. Baseline main commit 6bd49b71103d8a0b03365e919050372235f20319 preserved the approved documentation checkpoint; implementation was isolated in the linked task worktree and branch above.

The exact implementation and evidence tree was committed as e9a837b03cf7d9a894f51b493be83b9f9c44d041. A final independent read-only review returned CLEAN, reproduced the static/syntax/whitespace checks, confirmed the platform-aware ARM64 index/child image policy, and found no remaining Critical or Important blocker in scope.

The accepted branch was then fast-forwarded, without a merge commit or history rewrite, into canonical main at 74caa92e3bacae28b33d61cd16140204099ad70a. Canonical-root verification showed a clean working tree, 60 passing static/structural checks, valid syntax and Compose rendering, no redacted-scan leak, no canary container/network/listener, and the pre-existing PostgreSQL container still healthy.

Runtime and configuration changes

The existing local-llm-postgres container was neither connected to nor changed and remained healthy. No provider key, master key, database URL, cloud model, fallback, client profile, secret store, or provider account was accessed.

Commands run

Verification evidence

Before, after, and rollback

Outstanding owner-gated actions

  1. Revoke and replace the provider credential previously exposed in chat. The disclosed value was not used, inspected, copied, or saved here.
  2. Create and restore-test a recoverable backup of the existing PostgreSQL state before any database connection, schema, virtual-key, or budget work.
  3. Select exact per-harness caps within the approved aggregate policy and provide approved secret references before a provider-backed canary.
  4. Prove database-backed budget rejection and a maximum 90-day key lifetime with one isolated cloud alias before any real client reroute.
  5. Canary each compatible client separately; consumer/subscription lanes remain separate.
  6. Mirror this changelog to the rdmsm4x Apple Notes folder only after the shared Notes publisher's unresolved deletion/count hazard is fixed and verified. Notes was not called in this run.