Re: [PR] docs(ai-request-rewrite): re-port with Admin API, ADC, and Ingress Controller tabs [apisix]
Yilialinn merged PR #13210: URL: https://github.com/apache/apisix/pull/13210 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
Re: [PR] docs(ai-request-rewrite): re-port with Admin API, ADC, and Ingress Controller tabs [apisix]
Yilialinn commented on code in PR #13210:
URL: https://github.com/apache/apisix/pull/13210#discussion_r3116587494
##
docs/en/latest/plugins/ai-request-rewrite.md:
##
@@ -102,66 +119,646 @@ curl "http://127.0.0.1:9180/apisix/admin/routes/1"; -X
PUT \
}'
```
-Now send a request:
+
+
+
+Create a Route with the `ai-request-rewrite` Plugin:
+
+```yaml title="adc.yaml"
+services:
+ - name: ai-request-rewrite-service
+routes:
+ - name: ai-request-rewrite-route
+uris:
+ - /anything
+methods:
+ - POST
+plugins:
+ ai-request-rewrite:
+provider: openai
+auth:
+ header:
+Authorization: "Bearer ${OPENAI_API_KEY}"
+options:
+ model: gpt-4
+prompt: "Given a JSON request body, identify and mask any
sensitive information such as credit card numbers, social security numbers, and
personal identification numbers (e.g., passport or driver's license numbers).
Replace detected sensitive values with a masked format (e.g., \"***
1234\") for credit card numbers. Ensure the JSON structure remains unchanged."
+upstream:
+ type: roundrobin
+ nodes:
+- host: httpbin.org
+ port: 80
+ weight: 1
+```
+
+Synchronize the configuration to the gateway:
```shell
-curl "http://127.0.0.1:9080/anything"; \
+adc sync -f adc.yaml
+```
+
+
+
+
+
+
+
+```yaml title="ai-request-rewrite-gw.yaml"
+apiVersion: v1
+kind: Service
+metadata:
+ namespace: aic
+ name: httpbin-external-domain
+spec:
+ type: ExternalName
+ externalName: httpbin.org
+---
+apiVersion: apisix.apache.org/v1alpha1
+kind: PluginConfig
+metadata:
+ namespace: aic
+ name: ai-request-rewrite-plugin-config
+spec:
+ plugins:
+- name: ai-request-rewrite
+ config:
+provider: openai
+auth:
+ header:
+Authorization: "Bearer your-api-key"
+options:
+ model: gpt-4
+prompt: "Given a JSON request body, identify and mask any sensitive
information such as credit card numbers, social security numbers, and personal
identification numbers (e.g., passport or driver's license numbers). Replace
detected sensitive values with a masked format (e.g., \"*** 1234\")
for credit card numbers. Ensure the JSON structure remains unchanged."
+---
+apiVersion: gateway.networking.k8s.io/v1
+kind: HTTPRoute
+metadata:
+ namespace: aic
+ name: ai-request-rewrite-route
+spec:
+ parentRefs:
+- name: apisix
+ rules:
+- matches:
+- path:
+type: Exact
+value: /anything
+ method: POST
+ filters:
+- type: ExtensionRef
+ extensionRef:
+group: apisix.apache.org
+kind: PluginConfig
+name: ai-request-rewrite-plugin-config
+ backendRefs:
+- name: httpbin-external-domain
+ port: 80
+```
+
+
+
+
+```yaml title="ai-request-rewrite-ic.yaml"
+apiVersion: apisix.apache.org/v2
+kind: ApisixUpstream
+metadata:
+ namespace: aic
+ name: httpbin-external-domain
+spec:
+ ingressClassName: apisix
+ externalNodes:
+ - type: Domain
+name: httpbin.org
+---
+apiVersion: apisix.apache.org/v2
+kind: ApisixRoute
+metadata:
+ namespace: aic
+ name: ai-request-rewrite-route
+spec:
+ ingressClassName: apisix
+ http:
+- name: ai-request-rewrite-route
+ match:
+paths:
+ - /anything
+methods:
+ - POST
+ upstreams:
+ - name: httpbin-external-domain
+ plugins:
+- name: ai-request-rewrite
+ enable: true
+ config:
+provider: openai
+auth:
+ header:
+Authorization: "Bearer your-api-key"
+options:
+ model: gpt-4
+prompt: "Given a JSON request body, identify and mask any
sensitive information such as credit card numbers, social security numbers, and
personal identification numbers (e.g., passport or driver's license numbers).
Replace detected sensitive values with a masked format (e.g., \"***
1234\") for credit card numbers. Ensure the JSON structure remains unchanged."
+```
+
+
+
+
+Apply the configuration to your cluster:
+
+```shell
+kubectl apply -f ai-request-rewrite-ic.yaml
+```
+
+
+
+
+Send a POST request to the Route with some personally identifiable information:
+
+```shell
+curl "http://127.0.0.1:9080/anything"; -X POST \
-H "Content-Type: application/json" \
-d '{
-"name": "John Doe",
-"email": "[email protected]",
-"credit_card": "4111 ",
-"ssn": "123-45-6789",
-"address": "123 Main St"
+"content": "John said his debit card number is 4111 and SIN
is 123-45-6789."
}'
```
-The request body send to the LLM Service is as follows:
+You should receive a response similar to the following:
```json
{
- "messages": [
- {
- "role"
Re: [PR] docs(ai-request-rewrite): re-port with Admin API, ADC, and Ingress Controller tabs [apisix]
kayx23 commented on code in PR #13210:
URL: https://github.com/apache/apisix/pull/13210#discussion_r3109776826
##
docs/en/latest/plugins/ai-request-rewrite.md:
##
@@ -102,66 +119,646 @@ curl "http://127.0.0.1:9180/apisix/admin/routes/1"; -X
PUT \
}'
```
-Now send a request:
+
+
+
+Create a Route with the `ai-request-rewrite` Plugin:
+
+```yaml title="adc.yaml"
+services:
+ - name: ai-request-rewrite-service
+routes:
+ - name: ai-request-rewrite-route
+uris:
+ - /anything
+methods:
+ - POST
+plugins:
+ ai-request-rewrite:
+provider: openai
+auth:
+ header:
+Authorization: "Bearer ${OPENAI_API_KEY}"
+options:
+ model: gpt-4
+prompt: "Given a JSON request body, identify and mask any
sensitive information such as credit card numbers, social security numbers, and
personal identification numbers (e.g., passport or driver's license numbers).
Replace detected sensitive values with a masked format (e.g., \"***
1234\") for credit card numbers. Ensure the JSON structure remains unchanged."
+upstream:
+ type: roundrobin
+ nodes:
+- host: httpbin.org
+ port: 80
+ weight: 1
+```
+
+Synchronize the configuration to the gateway:
```shell
-curl "http://127.0.0.1:9080/anything"; \
+adc sync -f adc.yaml
+```
+
+
+
+
+
+
+
+```yaml title="ai-request-rewrite-gw.yaml"
+apiVersion: v1
+kind: Service
+metadata:
+ namespace: aic
+ name: httpbin-external-domain
+spec:
+ type: ExternalName
+ externalName: httpbin.org
+---
+apiVersion: apisix.apache.org/v1alpha1
+kind: PluginConfig
+metadata:
+ namespace: aic
+ name: ai-request-rewrite-plugin-config
+spec:
+ plugins:
+- name: ai-request-rewrite
+ config:
+provider: openai
+auth:
+ header:
+Authorization: "Bearer your-api-key"
+options:
+ model: gpt-4
+prompt: "Given a JSON request body, identify and mask any sensitive
information such as credit card numbers, social security numbers, and personal
identification numbers (e.g., passport or driver's license numbers). Replace
detected sensitive values with a masked format (e.g., \"*** 1234\")
for credit card numbers. Ensure the JSON structure remains unchanged."
+---
+apiVersion: gateway.networking.k8s.io/v1
+kind: HTTPRoute
+metadata:
+ namespace: aic
+ name: ai-request-rewrite-route
+spec:
+ parentRefs:
+- name: apisix
+ rules:
+- matches:
+- path:
+type: Exact
+value: /anything
+ method: POST
+ filters:
+- type: ExtensionRef
+ extensionRef:
+group: apisix.apache.org
+kind: PluginConfig
+name: ai-request-rewrite-plugin-config
+ backendRefs:
+- name: httpbin-external-domain
+ port: 80
+```
+
+
+
+
+```yaml title="ai-request-rewrite-ic.yaml"
+apiVersion: apisix.apache.org/v2
+kind: ApisixUpstream
+metadata:
+ namespace: aic
+ name: httpbin-external-domain
+spec:
+ ingressClassName: apisix
+ externalNodes:
+ - type: Domain
+name: httpbin.org
+---
+apiVersion: apisix.apache.org/v2
+kind: ApisixRoute
+metadata:
+ namespace: aic
+ name: ai-request-rewrite-route
+spec:
+ ingressClassName: apisix
+ http:
+- name: ai-request-rewrite-route
+ match:
+paths:
+ - /anything
+methods:
+ - POST
+ upstreams:
+ - name: httpbin-external-domain
+ plugins:
+- name: ai-request-rewrite
+ enable: true
+ config:
+provider: openai
+auth:
+ header:
+Authorization: "Bearer your-api-key"
+options:
+ model: gpt-4
+prompt: "Given a JSON request body, identify and mask any
sensitive information such as credit card numbers, social security numbers, and
personal identification numbers (e.g., passport or driver's license numbers).
Replace detected sensitive values with a masked format (e.g., \"***
1234\") for credit card numbers. Ensure the JSON structure remains unchanged."
+```
+
+
+
+
+Apply the configuration to your cluster:
+
+```shell
+kubectl apply -f ai-request-rewrite-ic.yaml
+```
+
+
+
+
+Send a POST request to the Route with some personally identifiable information:
+
+```shell
+curl "http://127.0.0.1:9080/anything"; -X POST \
-H "Content-Type: application/json" \
-d '{
-"name": "John Doe",
-"email": "[email protected]",
-"credit_card": "4111 ",
-"ssn": "123-45-6789",
-"address": "123 Main St"
+"content": "John said his debit card number is 4111 and SIN
is 123-45-6789."
}'
```
-The request body send to the LLM Service is as follows:
+You should receive a response similar to the following:
```json
{
- "messages": [
- {
- "role": "
Re: [PR] docs(ai-request-rewrite): re-port with Admin API, ADC, and Ingress Controller tabs [apisix]
Yilialinn commented on code in PR #13210: URL: https://github.com/apache/apisix/pull/13210#discussion_r3108758547 ## docs/en/latest/plugins/ai-request-rewrite.md: ## @@ -27,70 +27,83 @@ description: The ai-request-rewrite plugin intercepts client requests before the # --> + + https://docs.api7.ai/hub/ai-request-rewrite"; /> + + +import Tabs from '@theme/Tabs'; +import TabItem from '@theme/TabItem'; + ## Description -The `ai-request-rewrite` plugin intercepts client requests before they are forwarded to the upstream service. It sends a predefined prompt, along with the original request body, to a specified LLM service. The LLM processes the input and returns a modified request body, which is then used for the upstream request. This allows dynamic transformation of API requests based on AI-generated content. +The `ai-request-rewrite` Plugin processes client requests by forwarding them to LLM services for transformation before relaying them to Upstream services. This enables LLM-powered modifications such as data redaction, content enrichment, or reformatting. The Plugin supports integration with OpenAI, DeepSeek, Gemini, Vertex AI, Anthropic, OpenRouter, and other OpenAI-compatible APIs. ## Plugin Attributes -| **Field** | **Required** | **Type** | **Description** | -| - | | | | -| prompt| Yes | String | The prompt send to LLM service. | -| provider | Yes | String | Name of the LLM service. Available options: openai, deekseek, azure-openai, aimlapi, anthropic, openrouter, gemini, vertex-ai, and openai-compatible. When `aimlapi` is selected, the plugin uses the OpenAI-compatible driver with a default endpoint of `https://api.aimlapi.com/v1/chat/completions`. | -| provider_conf | No | Object | Configuration for the specific provider. Required when `provider` is set to `vertex-ai` and `override` is not configured. | -| provider_conf.project_id | Yes | String | Google Cloud Project ID. | -| provider_conf.region | Yes | String | Google Cloud Region. | -| auth | Yes | Object | Authentication configuration | -| auth.header | No | Object | Authentication headers. Key must match pattern `^[a-zA-Z0-9._-]+$`. | -| auth.query| No | Object | Authentication query parameters. Key must match pattern `^[a-zA-Z0-9._-]+$`. | -| auth.gcp | No | Object | Configuration for Google Cloud Platform (GCP) authentication. | -| auth.gcp.service_account_json | No | String | Content of the GCP service account JSON file. This can also be configured by setting the `GCP_SERVICE_ACCOUNT` environment variable. | -| auth.gcp.max_ttl | No | Integer | Maximum TTL (in seconds) for caching the GCP access token. Minimum: 1. | -| auth.gcp.expire_early_secs| No | Integer | Seconds to expire the access token before its actual expiration time to avoid edge cases. Minimum: 0. Default: 60. | -| options | No | Object | Key/value settings for the model | -| options.model | No | String | Model to execute. Examples: "gpt-3.5-turbo" for openai, "deepseek-chat" for deekseek, or "qwen-turbo" for openai-compatible or aimlapi services | -| override.endpoint | No | String | Override the default endpoint when using OpenAI-compatible services (e.g., self-hosted models or third-party LLM services). When the provider is 'openai-compatible', the endpoint field is required. | -| timeout | No | Integer | Total timeout in milliseconds for requests to LLM service, including connect, send, and read timeouts. Range: 1 - 6. Default: 3| -| keepalive | No | Boolean | Enable keepalive for requests to LLM service. Default: true | -| keepalive_timeout | No | Integer | Keepalive timeout in milliseconds for requests to LLM service. Minimum: 1000. Default: 6 | -| keepalive_pool| No | Integer | Keepalive pool size for requests to LLM service. Minimum: 1. Default: 30 | -| ssl_verify| No | Boolean | SSL verification for requests to LLM service. Default: true | - -## How it works - -: re-port with Admin API, ADC, and Ingress Controller tabs [apisix]
kayx23 commented on code in PR #13210: URL: https://github.com/apache/apisix/pull/13210#discussion_r3084974717 ## docs/en/latest/plugins/ai-request-rewrite.md: ## @@ -27,70 +27,83 @@ description: The ai-request-rewrite plugin intercepts client requests before the # --> + + https://docs.api7.ai/hub/ai-request-rewrite"; /> + + +import Tabs from '@theme/Tabs'; +import TabItem from '@theme/TabItem'; + ## Description -The `ai-request-rewrite` plugin intercepts client requests before they are forwarded to the upstream service. It sends a predefined prompt, along with the original request body, to a specified LLM service. The LLM processes the input and returns a modified request body, which is then used for the upstream request. This allows dynamic transformation of API requests based on AI-generated content. +The `ai-request-rewrite` Plugin processes client requests by forwarding them to LLM services for transformation before relaying them to Upstream services. This enables LLM-powered modifications such as data redaction, content enrichment, or reformatting. The Plugin supports integration with OpenAI, DeepSeek, Gemini, Vertex AI, Anthropic, OpenRouter, and other OpenAI-compatible APIs. ## Plugin Attributes -| **Field** | **Required** | **Type** | **Description** | -| - | | | | -| prompt| Yes | String | The prompt send to LLM service. | -| provider | Yes | String | Name of the LLM service. Available options: openai, deekseek, azure-openai, aimlapi, anthropic, openrouter, gemini, vertex-ai, and openai-compatible. When `aimlapi` is selected, the plugin uses the OpenAI-compatible driver with a default endpoint of `https://api.aimlapi.com/v1/chat/completions`. | -| provider_conf | No | Object | Configuration for the specific provider. Required when `provider` is set to `vertex-ai` and `override` is not configured. | -| provider_conf.project_id | Yes | String | Google Cloud Project ID. | -| provider_conf.region | Yes | String | Google Cloud Region. | -| auth | Yes | Object | Authentication configuration | -| auth.header | No | Object | Authentication headers. Key must match pattern `^[a-zA-Z0-9._-]+$`. | -| auth.query| No | Object | Authentication query parameters. Key must match pattern `^[a-zA-Z0-9._-]+$`. | -| auth.gcp | No | Object | Configuration for Google Cloud Platform (GCP) authentication. | -| auth.gcp.service_account_json | No | String | Content of the GCP service account JSON file. This can also be configured by setting the `GCP_SERVICE_ACCOUNT` environment variable. | -| auth.gcp.max_ttl | No | Integer | Maximum TTL (in seconds) for caching the GCP access token. Minimum: 1. | -| auth.gcp.expire_early_secs| No | Integer | Seconds to expire the access token before its actual expiration time to avoid edge cases. Minimum: 0. Default: 60. | -| options | No | Object | Key/value settings for the model | -| options.model | No | String | Model to execute. Examples: "gpt-3.5-turbo" for openai, "deepseek-chat" for deekseek, or "qwen-turbo" for openai-compatible or aimlapi services | -| override.endpoint | No | String | Override the default endpoint when using OpenAI-compatible services (e.g., self-hosted models or third-party LLM services). When the provider is 'openai-compatible', the endpoint field is required. | -| timeout | No | Integer | Total timeout in milliseconds for requests to LLM service, including connect, send, and read timeouts. Range: 1 - 6. Default: 3| -| keepalive | No | Boolean | Enable keepalive for requests to LLM service. Default: true | -| keepalive_timeout | No | Integer | Keepalive timeout in milliseconds for requests to LLM service. Minimum: 1000. Default: 6 | -| keepalive_pool| No | Integer | Keepalive pool size for requests to LLM service. Minimum: 1. Default: 30 | -| ssl_verify| No | Boolean | SSL verification for requests to LLM service. Default: true | - -## How it works - -: re-port with Admin API, ADC, and Ingress Controller tabs [apisix]
Copilot commented on code in PR #13210: URL: https://github.com/apache/apisix/pull/13210#discussion_r3076973466 ## docs/zh/latest/plugins/ai-request-rewrite.md: ## @@ -27,70 +27,83 @@ description: ai-request-rewrite 插件在客户端请求转发到上游服务之 # --> + + https://docs.api7.ai/hub/ai-request-rewrite"; /> + + +import Tabs from '@theme/Tabs'; +import TabItem from '@theme/TabItem'; + ## 描述 -`ai-request-rewrite` 插件在客户端请求转发到上游服务之前拦截请求。它将预定义的提示与原始请求体一起发送到指定的 LLM 服务。LLM 处理输入并返回修改后的请求体,然后用于上游请求。这允许基于 AI 生成的内容动态转换 API 请求。 +`ai-request-rewrite` 插件在将客户端请求转发到上游服务之前,先将请求发送到 LLM 服务进行转换处理。这使得 LLM 能够对请求进行数据脱敏、内容增强或格式转换等修改。该插件支持集成 OpenAI、DeepSeek、Gemini、Vertex AI、Anthropic、OpenRouter 以及其他 OpenAI 兼容的 API。 ## 插件属性 -| **字段** | **必选项** | **类型** | **描述** | -| - | | | | -| prompt| 是 | String | 发送到 LLM 服务的提示。 | -| provider | 是 | String | LLM 服务的名称。可用选项:openai、deekseek、azure-openai、aimlapi、anthropic、openrouter、gemini、vertex-ai 和 openai-compatible。当选择 `aimlapi` 时,插件使用 OpenAI 兼容驱动程序,默认端点为 `https://api.aimlapi.com/v1/chat/completions`。 | -| provider_conf | 否 | Object | 特定提供商的配置。当 `provider` 设置为 `vertex-ai` 且未配置 `override` 时必填。 | -| provider_conf.project_id | 是 | String | Google Cloud 项目 ID。 | -| provider_conf.region | 是 | String | Google Cloud 区域。 | -| auth | 是 | Object | 身份验证配置 | -| auth.header | 否 | Object | 身份验证头部。键必须匹配模式 `^[a-zA-Z0-9._-]+$`。 | -| auth.query| 否 | Object | 身份验证查询参数。键必须匹配模式 `^[a-zA-Z0-9._-]+$`。 | -| auth.gcp | 否 | Object | Google Cloud Platform (GCP) 身份验证配置。 | -| auth.gcp.service_account_json | 否 | String | GCP 服务账号 JSON 文件的内容。也可以通过设置“GCP_SERVICE_ACCOUNT”环境变量来配置。 | -| auth.gcp.max_ttl | 否 | Integer | 缓存 GCP 访问令牌的最大 TTL(秒)。最小值:1。 | -| auth.gcp.expire_early_secs| 否 | Integer | 在访问令牌实际过期时间之前使其过期的秒数,以避免边缘情况。最小值:0。默认值:60。 | -| options | 否 | Object | 模型的键/值设置 | -| options.model | 否 | String | 要执行的模型。示例:openai 的 "gpt-3.5-turbo",deekseek 的 "deepseek-chat",或 openai-compatible 或 aimlapi 服务的 "qwen-turbo" | -| override.endpoint | 否 | String | 使用 OpenAI 兼容服务时覆盖默认端点(例如,自托管模型或第三方 LLM 服务)。当提供商为 'openai-compatible' 时,endpoint 字段是必需的。 | -| timeout | 否 | Integer | 对 LLM 服务请求的总超时时间(毫秒),包括连接、发送和读取超时。范围:1 - 6。默认值:3| -| keepalive | 否 | Boolean | 为对 LLM 服务的请求启用 keepalive。默认值:true | -| keepalive_timeout | 否 | Integer | 对 LLM 服务请求的 keepalive 超时时间(毫秒)。最小值:1000。默认值:6 | -| keepalive_pool| 否 | Integer | 对 LLM 服务请求的 keepalive 池大小。最小值:1。默认值:30 | -| ssl_verify| 否 | Boolean | 对 LLM 服务请求的 SSL 验证。默认值:true | - -## 工作原理 - - +| **字段** | **必选项** | **类型** | **描述** | +| --- | --- | --- | --- | +| `prompt` | True | string | 发送到 LLM 服务用于重写客户端请求的提示词。 | +| `provider` | True | string | LLM 服务提供商。可选值:`openai`、`deepseek`、`azure-openai`、`aimlapi`、`gemini`、`vertex-ai`、`anthropic`、`openrouter`、`openai-compatible`。设置为 `aimlapi` 时,插件使用 OpenAI 兼容驱动并将请求代理到 `https://api.aimlapi.com/v1/chat/completions`。设置为 `openai-compatible` 时,插件将请求代理到 `override` 中配置的自定义端点。设置为 `azure-openai` 时,插件同样将请求代理到 `override` 中配置的自定义端点,并会额外移除用户请求中的 `model` 参数。 | +| `auth` | True | object | 身份验证配置。 | +| `auth.header` | False | object | 身份验证请求头。键必须匹配模式 `^[a-zA-Z0-9._-]+$`。`header` 和 `query` 至少需要配置其中一个。 | +| `auth.query` | False | object | 身份验证查询参数。键必须匹配模式 `^[a-zA-Z0-9._-]+$`。`header` 和 `query` 至少需要配置其中一个。 | +| `options` | False | object | 模型配置。除了 `model` 之外,还可以配置其他参数,这些参数会在请求体中转发给上游 LLM 服务。例如,使用 OpenAI 时,可以配置 `temperature`、`top_p` 和 `stream` 等参数。更多可用选项请参阅 LLM 提供商的 API 文档。 | +| `options.model` | False | string | LLM 模型名称,例如 `gpt-4` 或 `gpt-3.5`。更多可用模型请参阅 LLM 提供商的 API 文档。 | +| `override` | False | object | 覆盖设置。 | +| `override.endpoint` | False | string | LLM 提供商端点。当 `provider` 为 `openai-compatible` 时必填。 | +| `timeout` | False | integer | 请求 LLM 服务的超时时间(毫秒)。范围:1 - 6。默认值:`3`。 | +| `keepalive` | False | boolean | 是否在请求 LLM 服务时保持连接。默认值:`true`。 | +| `keepalive_timeout` | False | integer | 请求 LLM 服务的 keepalive 超时时间(毫秒)。最小值:`1000`。默认值:`6`。 | Review Comment: 文档声明 `keepalive_timeout` 默认值为 `6`,但 `ai
