Skip to content

LiteLLM without Traefik basic auth: only LiteLLM's own authentication - #7

Merged
mkotelnikov merged 1 commit into
mainfrom
fix/litellm-no-basic-auth
Sep 18, 2026
Merged

mkotelnikov merged 1 commit into
mainfrom
fix/litellm-no-basic-auth

Conversation

@mkotelnikov

Copy link
Copy Markdown
Contributor

The user asked to remove basic auth from LiteLLM and keep only its internal authentication.

  • New litellm router (priority 100) for /peers/<hub>/llm/*: door secret only, no basic auth. LiteLLM's dashboard login (UI_USERNAME/UI_PASSWORD) and its keys are the gate; the hub's passthrough never adds a credential.
  • Exception: /peers/<hub>/llm/keys stays behind basic auth. It is the hub's route, minting with the master key and authenticating no caller itself.
  • Checked on traefik v3.6.4 with a stub backend: LiteLLM paths 200 without auth; /llm/keys, /hub/api/*, / → 401. Path tricks (./, x/../, %2e, %2e%2e, %6b, //) on /llm/keys → 401. KEYS and keys;x pass Traefik, but the hub's exact-match check sends them to LiteLLM without the master key.
  • Live LiteLLM answers 401 on /key/list and /v1/models without a key.
  • health.sh (which gates each deploy) now checks all of the above.

🤖 Generated with Claude Code

…s own login and keys guard them

A second router passes /peers/<hub>/llm/* with the door secret only. The
hub's /llm/keys route stays behind basic auth: it mints with the master key
and authenticates no caller itself. Traefik cleans ./, ../, %2e, %6b and //
before matching, so those spellings of /llm/keys land on the admin router
(checked on traefik v3.6.4). health.sh now checks LiteLLM without basic auth,
/llm/keys and /hub/api refused without it, and LiteLLM refusing a keyless
admin call.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@mkotelnikov
mkotelnikov merged commit 980ccf5 into main Sep 18, 2026
3 checks passed
@mkotelnikov
mkotelnikov deleted the fix/litellm-no-basic-auth branch September 20, 2026 07:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant