Files
Fede Kamelhar 5c0c9e446e feat(providers): add OCI Generative AI example provider profile (#3904)
Add an example oci-genai inference profile for Oracle Cloud Infrastructure
Generative AI through its OpenAI-compatible endpoint. The profile injects a
compartment-scoped Generative AI API key as a bearer token only at the
regional OCI inference hosts and only under /openai/v1 with GET, POST, and
DELETE, so the sandbox never holds the key and the key cannot reach any other
OCI surface.

The header comments carry the OCI-side setup (create the IAM policy before
the key, least-privilege statement, key creation and rotation), the
operations verified through the sandbox proxy with a real key (chat
completions with streaming, tool calling, vision input, embeddings, and the
Responses API), the OCI error messages operators will meet, and the realm
and signed-transport caveats.

Scoped to the profile YAML per #3906; the only code change is the entry in
the profile listing test, which enumerates providers/*.yaml.

Signed-off-by: Federico Kamelhar <federico.kamelhar@oracle.com>
2026-09-29 22:36:06 +00:00
..

Example provider profiles

These files are reviewable examples. OpenShell does not compile them into any binary and no gateway loads them on its own: a gateway's profile catalog contains exactly what an operator imported.

Import one at platform scope:

openshell provider profile lint   -f providers/github.yaml
openshell provider profile import -f providers/github.yaml --global

Or import the whole directory:

openshell provider profile import --from providers --global

Drop --global to import into the current workspace instead.

Read the header before importing

Every file opens with a comment block naming its expected client binaries, the image layout those paths assume, the credential scope, the endpoint access it grants, and a smoke test. Read it. A profile's binaries list is the control that decides which processes may reach its endpoints, and several of these examples name paths from a particular reference image layout (/sandbox/.venv, /app/.venv, /sandbox/.cursor-server, /usr/lib/node_modules/...). Imported unchanged into a different image, such a profile matches nothing: the catalog still advertises it, but the credential is never injected and the traffic is denied.

Copy the file, edit binaries and endpoints to match your image and your workload, and import your copy.

Adapting one

  • Give your copy a distinct id if it diverges from the example, so the two cannot be confused in the catalog.
  • Keep binaries as narrow as the workload allows. Widening it to match every image trades away the binary-scoped least privilege that makes credential injection safe.
  • Keep endpoints limited to the hosts the credential should reach. A credential is only sent to the endpoints its profile declares.
  • Run openshell provider profile lint before importing.

See Provider profiles for the full schema.