ai: migrate LLM backbone from Kimi CLI to Codex CLI
Retires the Moonshot/Kimi subscription in favour of the already-paid ChatGPT plan. Both CLI wrappers now run `codex exec`; the kimi-agent container is gone. adolf-llm + hindsight-llm: - runKimi -> runCodex (`codex exec --json --skip-git-repo-check`), resume via `codex exec resume <thread_id>`. - MCP moves from a per-session .mcp.json (a workaround for Kimi having no --mcp-config-file flag) to a $CODEX_HOME/config.toml generated once at startup from shared-mcp.json. Field translation is load-bearing: bearerTokenEnvVar -> bearer_token_env_var, enabledTools -> enabled_tools. - approval_policy="never" + sandbox_mode required, or unattended turns block on an approval prompt nobody can answer. kimi-agent removed. It was the ONLY large-tier deployment behind LiteLLM, so deleting it outright would have silently degraded every large-tier request to the local 4B model via the existing fallbacks. tier-large, the auto_router complex-reasoning route and their fallbacks now point at the codex-backed adolf-llm wrapper (model_name: codex-agent). Three environment blockers fixed along the way: - OpenAI geo-blocks this host (403 unsupported_country_region_territory). Both containers now egress via the host xray proxy, with NO_PROXY keeping MCP and *.alogins.net traffic off the tunnel. - node:22-slim ships no system CA store; the Rust codex binary validates TLS against it, so every HTTPS call failed with a generic transport error while Node's own fetch worked. ca-certificates added to both images. - `codex exec resume` rejects -C/--cd (plain `codex exec` accepts it), which broke follow-up turns while first turns succeeded. Known regression: Kimi's managed-usage API has no Codex equivalent, so the /usage route returns 501 and there is no quota probe for the codex model. The two quota plugins degrade quietly to no output. Also: stop tracking cognee.env (live LLM + JWT secrets) and gitignore it. The secrets remain in earlier history and should be rotated. Verified live: plain turn, SSE streaming, session resume, MCP tool call, bearer-token MCP call, and completions through both LiteLLM routes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Y5QPagv4iun1ghpwM96Ff
This commit is contained in:
47
ai/backup-llm-dbs.sh
Executable file
47
ai/backup-llm-dbs.sh
Executable file
@@ -0,0 +1,47 @@
|
||||
#!/bin/bash
|
||||
# Backup script for litellm-db and langfuse-db (openai stack postgres containers).
|
||||
# litellm-db holds provisioned virtual keys + spend; langfuse-db holds all traces.
|
||||
# Mirrors the seafile/vaultwarden backup.sh pattern (same repo): dump via
|
||||
# `docker exec <container> pg_dump`, gzip, retention of last 5. Uses pg_dump (safe
|
||||
# against a live/running DB, no downtime needed — unlike gitea's stop-the-world dump).
|
||||
# Backup-freshness monitored via .age items.
|
||||
#
|
||||
# Run every 3 days via root crontab (same schedule as vaultwarden/seafile), e.g.:
|
||||
# 0 3 */3 * * /home/alvis/agap_git/ai/backup-llm-dbs.sh >> /mnt/backups/openai-llm-dbs/backup.log 2>&1
|
||||
#
|
||||
# Restore (litellm-db example, langfuse-db is identical with its own container/user/db):
|
||||
# gunzip -c /mnt/backups/openai-llm-dbs/<DATE>/litellm-db.sql.gz | \
|
||||
# docker exec -i litellm-db psql -U litellm -d litellm
|
||||
# # For langfuse-db:
|
||||
# gunzip -c /mnt/backups/openai-llm-dbs/<DATE>/langfuse-db.sql.gz | \
|
||||
# docker exec -i langfuse-db psql -U langfuse -d langfuse
|
||||
# # If restoring into a fresh/empty DB, first drop+recreate the DB (or restore
|
||||
# # to a new container) since the dump is a plain SQL dump, not --clean.
|
||||
|
||||
set -euo pipefail
|
||||
|
||||
BACKUP_DIR="/mnt/backups/openai-llm-dbs"
|
||||
|
||||
DATE=$(date '+%Y%m%d-%H%M')
|
||||
DEST="$BACKUP_DIR/$DATE"
|
||||
|
||||
mkdir -p "$DEST"
|
||||
# Backup-freshness monitoring is now done via .age items (calculated fields showing
|
||||
# age of the backup). The .ts (timestamp) trappers were unreliable (history.push not
|
||||
# landing); removed in kb#189 in favor of .age overdue triggers.
|
||||
|
||||
# --- litellm-db ---
|
||||
echo "Dumping litellm-db..."
|
||||
docker exec litellm-db pg_dump -U litellm litellm | gzip > "$DEST/litellm-db.sql.gz"
|
||||
echo "Dumped: litellm-db -> $DEST/litellm-db.sql.gz"
|
||||
|
||||
# --- langfuse-db ---
|
||||
echo "Dumping langfuse-db..."
|
||||
docker exec langfuse-db pg_dump -U langfuse langfuse | gzip > "$DEST/langfuse-db.sql.gz"
|
||||
echo "Dumped: langfuse-db -> $DEST/langfuse-db.sql.gz"
|
||||
|
||||
echo "$(date): Backup complete: $DEST"
|
||||
ls -la "$DEST/"
|
||||
|
||||
# Rotate: keep last 5 backups
|
||||
ls -1dt "$BACKUP_DIR"/[0-9]*-[0-9]* 2>/dev/null | tail -n +6 | xargs -r rm -rf
|
||||
Reference in New Issue
Block a user