feat(queen): an owner switches the model of all their keys of a provider at once - #524
Merged
dmitrii-f-t27 merged 2 commits intoOct 2, 2026
Conversation
…der at once The personal account could add, check and disable keys, but the model was the pool's variable, so moving 24 NVIDIA keys to another model meant an operator edit and a restart. POST /queen/contributor-keys/model sets one model for every key the owner holds of one provider, after one of those keys made the model call a tool; GET /queen/contributor-keys/models/:provider lists the provider's catalog for the picker. A binding row has always recorded the model it was bound under, so applying row models to environment keys would have pinned twelve keys probed on 2026-10-01 to nemotron-3-ultra after the pool moved on. model_chosen marks an owner's explicit choice; only it overrides the pool's model. Spec v2: probe timeout 15 s -> 90 s (z-ai/glm-5.3 on NVIDIA answered in 20-46 s, glm-4.5-flash on Z.ai in up to 87 s), model limits and a bounded two-key check.
✅ Tests passed — 2463/2523
|
dmitrii-f-t27
added a commit
to gHashTag/t27
that referenced
this pull request
Oct 2, 2026
…eys of a provider (#5634) The owner can switch every key they hold of one provider to one model, and only after one of those keys made the model call a tool. The probe waits 90 s instead of 15 s (z-ai/glm-5.3 on NVIDIA answered in 20-46 s), and the render proxy waits 200 s so it outlasts the Queen's two-key check. Hosts carry these bytes already: gHashTag/BrowserOS#524 and gHashTag/999-multibots-telegraf#3429. Closes #5633 phi^2 + 1/phi^2 = 3 | TRINITY
… the next number A key added without a name was stored as an empty label and shown as the bare provider, so the owner's 25th NVIDIA key read "nvidia" above "nvidia #1".."#24". Environment keys are now named by their place in their pool (Z.ai's pool-2 keys become zai #1..#10 instead of #10001..#10010), a key added unnamed or named only after its provider takes the next free number under the add lock, and a managed key saved before numbering is numbered once, compare-and-set, the first time the owner's keys are listed.
dmitrii-f-t27
merged commit Oct 2, 2026
60a81d7
into
fix/queen-worker-provider-and-prompt-size
15 of 16 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
The personal account (app.t27.ai/game/account) can add, check and disable keys, but the model was the pool's Railway variable. Moving 24 NVIDIA keys to another model needed an operator edit and a restart.
POST /queen/contributor-keys/model{provider, model}: one model for every key the owner holds of that provider. First, one of those keys must make the model call a tool. 400/404/410/422 →model_unavailable, a text answer →model_without_tools, busy/refused key → the next key (at mostMODEL_CHECK_ATTEMPTS = 2) →model_check_failed(504). Nothing is written unless the check passed. Returns the account payload.GET /queen/contributor-keys/models/:provider: the provider's/modelscatalog, read with one of the owner's keys and cached for 10 min. A failed read is never cached.ContributorRuntime.models). Other owners and the pool variables are untouched. A key added later joins the chosen model.providers[]now carries the owner's currentmodeland thedefaultModel.Why
model_chosenA binding row has always recorded the model it was bound under. If row models were applied to environment keys as-is, the 12 keys probed on 2026-10-01 would stay pinned to
nemotron-3-ultraafter the pool moved toz-ai/glm-5.3on 2026-10-02. The new columnmodel_chosen(ADD COLUMN IF NOT EXISTS, default false) marks an explicit owner choice. Only that choice overrides the pool model. A managed copy of a secret that the environment later received cannot be bound twice, so its choice is carried to that environment key.Spec v2 (
specs/automation/queen-contributor-keys.t27, regenerated witht27c gen-ts)PROBE_TIMEOUT_MS15 s → 90 s. Measured 2026-10-02:z-ai/glm-5.3on NVIDIA took 20–46 s for a short answer,glm-4.5-flashon Z.ai up to 87 s. With 15 s, every Check would read "unavailable".MODEL_LIMIT,MODEL_PROBE_MAX_TOKENS,MODEL_CHECK_ATTEMPTS,MODEL_LIST_LIMIT,MODEL_LIST_CACHE_SECONDS, plus three laws with tests.Verification (Bun 1.3.6)
t27c typecheckOK;t27c test-report13/13 (Zig 0.16);gen-tsoutput byte-identical to the committed module; the wasm-compiler parity test passes.tsc --noEmitclean; biome clean on changed files (remaining complexity warnings are pre-existing in queen-dispatch.ts).tests/api/queen-contributor-keys.test.ts17/17.tests/pglive/queen-contributor-keys-live.test.ts14/14 against a disposable PostgreSQL 17 (5 new: stale binding never overrides, no write without a tool call, switch scope, managed copy, route).tests/api/queen-*.test.ts: 711 pass.App side: gHashTag/999-multibots-telegraf (proxy + "Model for all keys" block) follows.
🤖 Generated with Claude Code