@@ -47,6 +47,60 @@ set_aicore_config(instance_name="aicore-production")
4747
4848---
4949
50+ ## Routing Modes
51+
52+ ` set_aicore_config() ` detects which routing mode to activate based on environment variables.
53+ ** Agent code is identical in all three modes** — the deployer controls routing by choosing which
54+ env vars to inject.
55+
56+ ### Direct mode (default)
57+
58+ No extra env vars required. Credentials are loaded from the mounted K8s secret volume
59+ (` /etc/secrets/appfnd/aicore/<instance>/ ` ) or from ` AICORE_* ` environment variables.
60+ This is the standard mode for agents deployed on BTP managed runtime.
61+
62+ ``` python
63+ set_aicore_config() # reads mounted secret or AICORE_* env vars
64+ ```
65+
66+ ### Proxy mode (` AICORE_PROXY_URL ` )
67+
68+ Set ` AICORE_PROXY_URL ` to route all LiteLLM calls through a LiteLLM-compatible proxy.
69+ No AI Core credentials are written to the process environment — the proxy handles
70+ authentication. Optionally set ` AICORE_PROXY_API_KEY ` for proxy-level auth.
71+
72+ ``` bash
73+ # Injected by the deployer (e.g. K8s ConfigMap / Helm values)
74+ AICORE_PROXY_URL=https://your-litellm-proxy.example.com
75+ AICORE_PROXY_API_KEY=sk-... # optional
76+ ```
77+
78+ ``` python
79+ set_aicore_config() # detects AICORE_PROXY_URL, sets litellm.api_base
80+ # AICORE_CLIENT_SECRET is NOT written to env in this mode
81+ ```
82+
83+ Model strings (` sap/<model> ` ) are passed verbatim — no rewriting.
84+
85+ ### Destination mode (` AICORE_DESTINATION_NAME ` )
86+
87+ Set ` AICORE_DESTINATION_NAME ` to load AI Core credentials at startup from a BTP Destination
88+ Service destination. The deployer only needs to inject Destination Service binding credentials;
89+ the AI Core ` client_secret ` never needs to be in the K8s Secret directly.
90+
91+ ``` bash
92+ AICORE_DESTINATION_NAME=aicore-destination # name of the BTP destination
93+ ```
94+
95+ ``` python
96+ set_aicore_config() # calls Destination Service, writes AICORE_* env vars
97+ ```
98+
99+ The destination must use ** OAuth2ClientCredentials** authentication with ` clientId ` ,
100+ ` clientSecret ` , and ` tokenServiceURL ` as destination configuration properties.
101+
102+ ---
103+
50104## Credential Rotation
51105
52106BTP rotates AI Core service binding credentials automatically. The SDK
0 commit comments