🍱 feat: Reload Custom Model Lists Across Replicas - #16470
Closed
lia-by-librechat[bot] wants to merge 1 commit into
Closed
lia-by-librechat[bot] wants to merge 1 commit into
lia-by-librechat[bot] wants to merge 1 commit into
Conversation
Contributor
Author
|
Please review exact head |
5 tasks done
Contributor
Author
|
Superseded by #16471, the same narrow model-list reload carried onto current dev without canary-only commits. Closing this canary PR so there is one merge target; the branch remains intact. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Changing the default model list for an existing custom endpoint in
librechat.yamlcurrently requires restarting every API replica. This PR validates a local or HTTP(S)CONFIG_PATHon an explicit admin reload, installs only existing custom endpoints'models.defaultchanges, and reports every other YAML edit as requiring a restart. A new endpoint, changed credentials, memory policy, MCP settings, tool filters, and startup configuration never take effect through this reload.The control appears in General settings only for a user with platform-scoped
MANAGE_CONFIGSandACCESS_ADMIN. It checks access when settings opens, not during every authenticated startup-config request. The POST independently enforces both grants. A model picker already open in another browser observes the applied replica generation and refreshes its models only after a serving replica proves it has that version.Supersedes the closed broad-scope PR #16385. Builds on the last-good reload behavior already merged in #16383. Targets canary for an explicit operator rollout.
How it works
A slower admin reload cannot overwrite a newer Redis generation. A replica whose source has not caught up retains its last good model list and retries at a configurable rate; publication is not a claim that all replicas have applied it. Only the process-local
APP_CONFIGcache stores the accepted base. Redis is optional: without it, the operation and report are explicitly local-only. The initial Redis read is bounded; a server can start during a Redis outage and continue serving its last good config.Rollout:
configReload.clusterReadydefaults tofalse. After all replicas run this version, enable it in the source configuration and restart them before invoking reload. The new Redis key is versioned and isolated from the previous broad reload protocol. Do not perform clustered reloads during a mixed-version rollout.configReload.clientPollIntervalMsandconfigReload.mismatchRetryMsdefault to 3000 ms and 5000 ms respectively; remote fetches retain the previous 10-second timeout unless configured.Type of change
Testing
tsc --noEmitinpackages/data-provider,packages/api, andclient; builds ofpackages/data-provider,packages/data-schemas,packages/api, andpackages/client; stagednpm run static-checks(all affected gates passed).Risk / compatibility
Only default model lists for existing, uniquely named custom endpoints can change live. Other edits remain at each replica's startup value, including values used by the expired-file sweep, GitHub skill synchronization, MCP recovery, and global static tool catalog. Source-validation errors leave the last good base intact. Redis publication uses a single-key Lua compare-and-publish, and a published generation never exposes YAML or configuration secrets. MongoDB config override priority remains unchanged. An unavailable Redis store permits a local-only reload and reports propagation failure without blocking normal cached requests.
Checklist