ai: add curl access for the private batch API

This commit is contained in:
jenkins 2026-09-28 18:07:53 -05:00
parent ff64e27aec
commit e9c901f177
2 changed files with 44 additions and 0 deletions

View File

@ -0,0 +1,39 @@
#!/usr/bin/env bash
# Query the pinned batch API over LAN TLS without cluster or Vault credentials.
set -euo pipefail
if [[ ${1:-} == --help ]]; then
cat <<'USAGE'
Usage: HERMES_LAN_TOKEN_FILE=/private/token hermes_batch_curl.sh --models
HERMES_LAN_TOKEN_FILE=/private/token hermes_batch_curl.sh < request.json
Generation input is the API request object, not the Python client's scope envelope.
The roster application must first filter FA01 and permitted fields on the laptop.
USAGE
exit 0
fi
if [[ $# -gt 1 || ( $# -eq 1 && $1 != --models ) ]]; then
printf 'Only --models or a generation request on stdin is supported\n' >&2
exit 2
fi
: "${HERMES_LAN_TOKEN_FILE:?Set HERMES_LAN_TOKEN_FILE to the private scoped token file}"
umask 077
scratch=$(mktemp -d)
trap 'rm -rf -- "$scratch"' EXIT
token=$(cat -- "$HERMES_LAN_TOKEN_FILE")
if [[ ! $token =~ ^[0-9a-f]{64}$ ]]; then
printf 'Invalid LAN API credential\n' >&2
exit 1
fi
printf 'header = "Authorization: Bearer %s"\n' "$token" > "$scratch/curl.conf"
unset token
arguments=(--fail-with-body --silent --show-error --connect-timeout 10 --max-time 1810
--noproxy worker.bstein.dev --resolve worker.bstein.dev:443:192.168.22.50
--config "$scratch/curl.conf" --header 'Content-Type: application/json')
operation=models
if [[ ${1:-} != --models ]]; then
operation=generate
cat > "$scratch/request.json"
arguments+=(--data-binary "@$scratch/request.json")
fi
# No redirect following, automatic retry, or alternative destination.
curl "${arguments[@]}" "https://worker.bstein.dev/local-model/api/batch/$operation"

View File

@ -57,6 +57,11 @@ catalog. Add `--request ENVELOPE.json` to run a locally prepared request. The cl
connects directly to the LAN address while verifying the worker TLS hostname;
it never uses public DNS, HTTP proxies, redirects or an alternate endpoint.
For curl, use `HERMES_LAN_TOKEN_FILE=TOKEN scripts/ops/hermes_batch_curl.sh --models`.
Omit `--models` and provide a generation request object on stdin for inference.
The curl helper writes the result to stdout; redirect it to a private local file
when using real cases. The Python client caches results privately by default.
An envelope contains `campaign_id` (`FA01`, or `SYNTHETIC` for fixtures), `suite_id`,
`source_sha256`, `prompt_version` and `request`. The request contains `model`,
`prompt`, `stream:false`, `think`, `format` (JSON schema or `"json"`), and exactly