mirror of
				https://github.com/meta-llama/llama-stack.git
				synced 2025-10-23 00:27:26 +00:00 
			
		
		
		
	**This PR changes configurations in a backward incompatible way.**
Run configs today repeat full SQLite/Postgres snippets everywhere a
store is needed, which means duplicated credentials, extra connection
pools, and lots of drift between files. This PR introduces named storage
backends so the stack and providers can share a single catalog and
reference those backends by name.
## Key Changes
- Add `storage.backends` to `StackRunConfig`, register each KV/SQL
backend once at startup, and validate that references point to the right
family.
- Move server stores under `storage.stores` with lightweight references
(backend + namespace/table) instead of full configs.
- Update every provider/config/doc to use the new reference style;
docs/codegen now surface the simplified YAML.
## Migration
Before:
```yaml
metadata_store:
  type: sqlite
  db_path: ~/.llama/distributions/foo/registry.db
inference_store:
  type: postgres
  host: ${env.POSTGRES_HOST}
  port: ${env.POSTGRES_PORT}
  db: ${env.POSTGRES_DB}
  user: ${env.POSTGRES_USER}
  password: ${env.POSTGRES_PASSWORD}
conversations_store:
  type: postgres
  host: ${env.POSTGRES_HOST}
  port: ${env.POSTGRES_PORT}
  db: ${env.POSTGRES_DB}
  user: ${env.POSTGRES_USER}
  password: ${env.POSTGRES_PASSWORD}
```
After:
```yaml
storage:
  backends:
    kv_default:
      type: kv_sqlite
      db_path: ~/.llama/distributions/foo/kvstore.db
    sql_default:
      type: sql_postgres
      host: ${env.POSTGRES_HOST}
      port: ${env.POSTGRES_PORT}
      db: ${env.POSTGRES_DB}
      user: ${env.POSTGRES_USER}
      password: ${env.POSTGRES_PASSWORD}
  stores:
    metadata:
      backend: kv_default
      namespace: registry
    inference:
      backend: sql_default
      table_name: inference_store
      max_write_queue_size: 10000
      num_writers: 4
    conversations:
      backend: sql_default
      table_name: openai_conversations
```
Provider configs follow the same pattern—for example, a Chroma vector
adapter switches from:
```yaml
providers:
  vector_io:
  - provider_id: chromadb
    provider_type: remote::chromadb
    config:
      url: ${env.CHROMADB_URL}
      kvstore:
        type: sqlite
        db_path: ~/.llama/distributions/foo/chroma.db
```
to:
```yaml
providers:
  vector_io:
  - provider_id: chromadb
    provider_type: remote::chromadb
    config:
      url: ${env.CHROMADB_URL}
      persistence:
        backend: kv_default
        namespace: vector_io::chroma_remote
```
Once the backends are declared, everything else just points at them, so
rotating credentials or swapping to Postgres happens in one place and
the stack reuses a single connection pool.
		
	
			
		
			
				
	
	
		
			132 lines
		
	
	
	
		
			4 KiB
		
	
	
	
		
			Python
		
	
	
	
	
	
			
		
		
	
	
			132 lines
		
	
	
	
		
			4 KiB
		
	
	
	
		
			Python
		
	
	
	
	
	
| # Copyright (c) Meta Platforms, Inc. and affiliates.
 | |
| # All rights reserved.
 | |
| #
 | |
| # This source code is licensed under the terms described in the LICENSE file in
 | |
| # the root directory of this source tree.
 | |
| 
 | |
| from uuid import uuid4
 | |
| 
 | |
| import pytest
 | |
| from fastapi import FastAPI, Request
 | |
| from fastapi.testclient import TestClient
 | |
| from starlette.middleware.base import BaseHTTPMiddleware
 | |
| 
 | |
| from llama_stack.core.datatypes import QuotaConfig, QuotaPeriod
 | |
| from llama_stack.core.server.quota import QuotaMiddleware
 | |
| from llama_stack.core.storage.datatypes import KVStoreReference, SqliteKVStoreConfig
 | |
| from llama_stack.providers.utils.kvstore import register_kvstore_backends
 | |
| 
 | |
| 
 | |
| class InjectClientIDMiddleware(BaseHTTPMiddleware):
 | |
|     """
 | |
|     Middleware that injects 'authenticated_client_id' to mimic AuthenticationMiddleware.
 | |
|     """
 | |
| 
 | |
|     def __init__(self, app, client_id="client1"):
 | |
|         super().__init__(app)
 | |
|         self.client_id = client_id
 | |
| 
 | |
|     async def dispatch(self, request: Request, call_next):
 | |
|         request.scope["authenticated_client_id"] = self.client_id
 | |
|         return await call_next(request)
 | |
| 
 | |
| 
 | |
| def build_quota_config(db_path) -> QuotaConfig:
 | |
|     backend_name = f"kv_quota_{uuid4().hex}"
 | |
|     register_kvstore_backends({backend_name: SqliteKVStoreConfig(db_path=str(db_path))})
 | |
|     return QuotaConfig(
 | |
|         kvstore=KVStoreReference(backend=backend_name, namespace="quota"),
 | |
|         anonymous_max_requests=1,
 | |
|         authenticated_max_requests=2,
 | |
|         period=QuotaPeriod.DAY,
 | |
|     )
 | |
| 
 | |
| 
 | |
| @pytest.fixture
 | |
| def auth_app(tmp_path, request):
 | |
|     """
 | |
|     FastAPI app with InjectClientIDMiddleware and QuotaMiddleware for authenticated testing.
 | |
|     Each test gets its own DB file.
 | |
|     """
 | |
|     inner_app = FastAPI()
 | |
| 
 | |
|     @inner_app.get("/test")
 | |
|     async def test_endpoint():
 | |
|         return {"message": "ok"}
 | |
| 
 | |
|     db_path = tmp_path / f"quota_{request.node.name}.db"
 | |
|     quota = build_quota_config(db_path)
 | |
| 
 | |
|     app = InjectClientIDMiddleware(
 | |
|         QuotaMiddleware(
 | |
|             inner_app,
 | |
|             kv_config=quota.kvstore,
 | |
|             anonymous_max_requests=quota.anonymous_max_requests,
 | |
|             authenticated_max_requests=quota.authenticated_max_requests,
 | |
|             window_seconds=86400,
 | |
|         ),
 | |
|         client_id=f"client_{request.node.name}",
 | |
|     )
 | |
|     return app
 | |
| 
 | |
| 
 | |
| def test_authenticated_quota_allows_up_to_limit(auth_app):
 | |
|     client = TestClient(auth_app)
 | |
|     assert client.get("/test").status_code == 200
 | |
|     assert client.get("/test").status_code == 200
 | |
| 
 | |
| 
 | |
| def test_authenticated_quota_blocks_after_limit(auth_app):
 | |
|     client = TestClient(auth_app)
 | |
|     client.get("/test")
 | |
|     client.get("/test")
 | |
|     resp = client.get("/test")
 | |
|     assert resp.status_code == 429
 | |
|     assert resp.json()["error"]["message"] == "Quota exceeded"
 | |
| 
 | |
| 
 | |
| def test_anonymous_quota_allows_up_to_limit(tmp_path, request):
 | |
|     inner_app = FastAPI()
 | |
| 
 | |
|     @inner_app.get("/test")
 | |
|     async def test_endpoint():
 | |
|         return {"message": "ok"}
 | |
| 
 | |
|     db_path = tmp_path / f"quota_anon_{request.node.name}.db"
 | |
|     quota = build_quota_config(db_path)
 | |
| 
 | |
|     app = QuotaMiddleware(
 | |
|         inner_app,
 | |
|         kv_config=quota.kvstore,
 | |
|         anonymous_max_requests=quota.anonymous_max_requests,
 | |
|         authenticated_max_requests=quota.authenticated_max_requests,
 | |
|         window_seconds=86400,
 | |
|     )
 | |
| 
 | |
|     client = TestClient(app)
 | |
|     assert client.get("/test").status_code == 200
 | |
| 
 | |
| 
 | |
| def test_anonymous_quota_blocks_after_limit(tmp_path, request):
 | |
|     inner_app = FastAPI()
 | |
| 
 | |
|     @inner_app.get("/test")
 | |
|     async def test_endpoint():
 | |
|         return {"message": "ok"}
 | |
| 
 | |
|     db_path = tmp_path / f"quota_anon_{request.node.name}.db"
 | |
|     quota = build_quota_config(db_path)
 | |
| 
 | |
|     app = QuotaMiddleware(
 | |
|         inner_app,
 | |
|         kv_config=quota.kvstore,
 | |
|         anonymous_max_requests=quota.anonymous_max_requests,
 | |
|         authenticated_max_requests=quota.authenticated_max_requests,
 | |
|         window_seconds=86400,
 | |
|     )
 | |
| 
 | |
|     client = TestClient(app)
 | |
|     client.get("/test")
 | |
|     resp = client.get("/test")
 | |
|     assert resp.status_code == 429
 | |
|     assert resp.json()["error"]["message"] == "Quota exceeded"
 |