From e9c901f177cc474897efa5e6b89bb74affad9e49 Mon Sep 17 00:00:00 2001 From: jenkins Date: Mon, 28 Sep 2026 18:07:53 -0500 Subject: [PATCH] ai: add curl access for the private batch API --- scripts/ops/hermes_batch_curl.sh | 39 ++++++++++++++++++++++++++++++ scripts/ops/test_planning/NOTES.md | 5 ++++ 2 files changed, 44 insertions(+) create mode 100755 scripts/ops/hermes_batch_curl.sh diff --git a/scripts/ops/hermes_batch_curl.sh b/scripts/ops/hermes_batch_curl.sh new file mode 100755 index 00000000..b05d82d5 --- /dev/null +++ b/scripts/ops/hermes_batch_curl.sh @@ -0,0 +1,39 @@ +#!/usr/bin/env bash +# Query the pinned batch API over LAN TLS without cluster or Vault credentials. +set -euo pipefail + +if [[ ${1:-} == --help ]]; then + cat <<'USAGE' +Usage: HERMES_LAN_TOKEN_FILE=/private/token hermes_batch_curl.sh --models + HERMES_LAN_TOKEN_FILE=/private/token hermes_batch_curl.sh < request.json +Generation input is the API request object, not the Python client's scope envelope. +The roster application must first filter FA01 and permitted fields on the laptop. +USAGE + exit 0 +fi +if [[ $# -gt 1 || ( $# -eq 1 && $1 != --models ) ]]; then + printf 'Only --models or a generation request on stdin is supported\n' >&2 + exit 2 +fi +: "${HERMES_LAN_TOKEN_FILE:?Set HERMES_LAN_TOKEN_FILE to the private scoped token file}" +umask 077 +scratch=$(mktemp -d) +trap 'rm -rf -- "$scratch"' EXIT +token=$(cat -- "$HERMES_LAN_TOKEN_FILE") +if [[ ! $token =~ ^[0-9a-f]{64}$ ]]; then + printf 'Invalid LAN API credential\n' >&2 + exit 1 +fi +printf 'header = "Authorization: Bearer %s"\n' "$token" > "$scratch/curl.conf" +unset token +arguments=(--fail-with-body --silent --show-error --connect-timeout 10 --max-time 1810 + --noproxy worker.bstein.dev --resolve worker.bstein.dev:443:192.168.22.50 + --config "$scratch/curl.conf" --header 'Content-Type: application/json') +operation=models +if [[ ${1:-} != --models ]]; then + operation=generate + cat > "$scratch/request.json" + arguments+=(--data-binary "@$scratch/request.json") +fi +# No redirect following, automatic retry, or alternative destination. +curl "${arguments[@]}" "https://worker.bstein.dev/local-model/api/batch/$operation" diff --git a/scripts/ops/test_planning/NOTES.md b/scripts/ops/test_planning/NOTES.md index d3bd29e4..cad2f13c 100644 --- a/scripts/ops/test_planning/NOTES.md +++ b/scripts/ops/test_planning/NOTES.md @@ -57,6 +57,11 @@ catalog. Add `--request ENVELOPE.json` to run a locally prepared request. The cl connects directly to the LAN address while verifying the worker TLS hostname; it never uses public DNS, HTTP proxies, redirects or an alternate endpoint. +For curl, use `HERMES_LAN_TOKEN_FILE=TOKEN scripts/ops/hermes_batch_curl.sh --models`. +Omit `--models` and provide a generation request object on stdin for inference. +The curl helper writes the result to stdout; redirect it to a private local file +when using real cases. The Python client caches results privately by default. + An envelope contains `campaign_id` (`FA01`, or `SYNTHETIC` for fixtures), `suite_id`, `source_sha256`, `prompt_version` and `request`. The request contains `model`, `prompt`, `stream:false`, `think`, `format` (JSON schema or `"json"`), and exactly