Skip to content

Commit 85a3448

Browse files
committed
docs(aicore): document proxy mode and destination mode routing in user-guide
1 parent a269e02 commit 85a3448

1 file changed

Lines changed: 54 additions & 0 deletions

File tree

‎src/sap_cloud_sdk/aicore/user-guide.md‎

Lines changed: 54 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -47,6 +47,60 @@ set_aicore_config(instance_name="aicore-production")
4747

4848
---
4949

50+
## Routing Modes
51+
52+
`set_aicore_config()` detects which routing mode to activate based on environment variables.
53+
**Agent code is identical in all three modes** — the deployer controls routing by choosing which
54+
env vars to inject.
55+
56+
### Direct mode (default)
57+
58+
No extra env vars required. Credentials are loaded from the mounted K8s secret volume
59+
(`/etc/secrets/appfnd/aicore/<instance>/`) or from `AICORE_*` environment variables.
60+
This is the standard mode for agents deployed on BTP managed runtime.
61+
62+
```python
63+
set_aicore_config() # reads mounted secret or AICORE_* env vars
64+
```
65+
66+
### Proxy mode (`AICORE_PROXY_URL`)
67+
68+
Set `AICORE_PROXY_URL` to route all LiteLLM calls through a LiteLLM-compatible proxy.
69+
No AI Core credentials are written to the process environment — the proxy handles
70+
authentication. Optionally set `AICORE_PROXY_API_KEY` for proxy-level auth.
71+
72+
```bash
73+
# Injected by the deployer (e.g. K8s ConfigMap / Helm values)
74+
AICORE_PROXY_URL=https://your-litellm-proxy.example.com
75+
AICORE_PROXY_API_KEY=sk-... # optional
76+
```
77+
78+
```python
79+
set_aicore_config() # detects AICORE_PROXY_URL, sets litellm.api_base
80+
# AICORE_CLIENT_SECRET is NOT written to env in this mode
81+
```
82+
83+
Model strings (`sap/<model>`) are passed verbatim — no rewriting.
84+
85+
### Destination mode (`AICORE_DESTINATION_NAME`)
86+
87+
Set `AICORE_DESTINATION_NAME` to load AI Core credentials at startup from a BTP Destination
88+
Service destination. The deployer only needs to inject Destination Service binding credentials;
89+
the AI Core `client_secret` never needs to be in the K8s Secret directly.
90+
91+
```bash
92+
AICORE_DESTINATION_NAME=aicore-destination # name of the BTP destination
93+
```
94+
95+
```python
96+
set_aicore_config() # calls Destination Service, writes AICORE_* env vars
97+
```
98+
99+
The destination must use **OAuth2ClientCredentials** authentication with `clientId`,
100+
`clientSecret`, and `tokenServiceURL` as destination configuration properties.
101+
102+
---
103+
50104
## Credential Rotation
51105

52106
BTP rotates AI Core service binding credentials automatically. The SDK

0 commit comments

Comments
 (0)