Add the routing decision controller and enforcement - #8942
Conversation
Co-authored-by: lpcox <15877973+lpcox@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Critical route matching and moderate configuration failure handling issues remain unresolved.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (2)
What changed in this PR
Adds standalone routing decision and request-enforcement modules, with server wiring deferred.
Changes:
- Implements bounded model classification, ranking, and selection.
- Enforces selected model, effort, and endpoint.
- Adds controller and enforcement tests.
| File | Review |
|---|---|
containers/api-proxy/routing-enforcement.test.js |
Covers request, response, drain, and upgrade enforcement. |
containers/api-proxy/routing-enforcement.js |
Must parse pathnames so query-bearing discovery and inference requests work correctly. |
containers/api-proxy/routing-controller.test.js |
Covers routing decisions and degradation paths. |
containers/api-proxy/routing-controller.js |
Must handle missing configuration safely; effort-aware overlap diagnostics also need correction. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
|
🔌 Smoke Services — All services reachable! ✅
|
|
✨ The prophecy is fulfilled... Smoke Codex has completed its mystical journey. The stars align. 🌟 Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed. Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
|
✅ Smoke Gemini completed. All facets verified. 💎 Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "play.googleapis.com"See Network Configuration for more information.
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✅ Security Guard completed successfully! Security review of PR #8942: No security concerns found. Both new files (routing-controller.js and routing-enforcement.js) implement proper input validation, immutability enforcement, request screening, and timeout controls. No weakened firewall rules, capability additions, or information leakage detected.
|
|
✅ Build Test Suite completed successfully! Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
✅ Smoke Claude passed Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅ Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
Smoke Test: Cloud Hypervisor + Copilot
All checks passed ✅ Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "example.com"
- "github.com"See Network Configuration for more information.
|
🔐 Smoke Test: Copilot BYOK (Direct) Mode
Running in direct BYOK mode ( Overall: ✅ PASS cc
|
|
Smoke Test: Copilot Engine —
Recent merged PRs:
Overall: PASS ✅
|
|
EGRESS_RESULT allow=pass deny=pass ✅ Allowed domain (github.com) reachable — allowed=200 Overall status: PASS
Warning Firewall blocked 2 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "api.github.com"
- "example.com"See Network Configuration for more information.
|
|
Services Connectivity Smoke Test
Overall: PASS
|
Chroot Version Comparison Results
Overall: FAILED — Node.js version mismatch between host and chroot environments. Since not all tests passed, the
|
Smoke Test: Claude Engine Validation
Overall result: PASS Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.anthropic.com"See Network Configuration for more information.
|
|
Merged PRs: #8933 Fix ARC/DinD agent safe-output staging paths; #8929 Enforce AWF domain policy on Claude hosted web search and fetch Warning Firewall blocked 13 domainsThe following domains were blocked by the firewall during workflow execution:
[!TIP] tools:
github:
mode: gh-proxySee GitHub Tools for more information on To allow these domains, add them to the network:
allowed:
- defaults
- "ab.chatgpt.com"
- "accounts.google.com"
- "android.clients.google.com"
- "api.github.com"
- "clients2.google.com"
- "collector.github.com"
- "contentautofill.googleapis.com"
- "github.com"
- "github.githubassets.com"
- "msfeed25.pkgs.visualstudio.com"
- "update.googleapis.com"
- "www.google.com"
- "www.gstatic.com"See Network Configuration for more information.
|
🏗️ Build Test Suite Results
Overall: 8/8 ecosystems passed — PASS Notes:
Warning Firewall blocked 8 domainsThe following domains were blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "api.nuget.org"
- "bun.sh"
- "dc.services.visualstudio.com"
- "deno.land"
- "dl.deno.land"
- "github.com"
- "releaseassets.githubusercontent.com"
- "repo.maven.apache.org"See Network Configuration for more information.
|
Smoke Test: API Proxy OpenTelemetry Tracing — Results
Summary: All checks pass; module, tests, env forwarding, and integration hook are wired correctly. No spans were exported in this run since no OTLP endpoint was active — expected behavior, not a failure. Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "o205451.ingest.us.sentry.io"See Network Configuration for more information.
|
Smoke Test: Gemini Engine Validation Results
Overall status: FAIL Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "play.googleapis.com"See Network Configuration for more information.
|


The candidate pool, router client, and classifier landed separately, but nothing combined them into one decision and nothing made that decision binding — a routed run would log a chosen model while the agent stayed free to call any other. This adds the two leaf modules that close that gap. The running proxy does not call them yet, so behavior is unchanged until the server wiring issue.
containers/api-proxy/routing-controller.js— the decision204) and capabilities → build the pool → classify → rank → validate → return exactly one immutable selection or one sanitized failure.{ conversation, models: pool.choices }. Route body carriesobjective, the same frozen conversation,toRouteCandidates(pool), andclassificationonly when one validated.invalid_classifier_output) instead of retrying, and a terminal provider failure stops the run rather than advancing the ranked list.routing_configuration_errorafter one planner attempt, since the planner does not retryENOTFOUND.containers/api-proxy/routing-enforcement.js— the guaranteeGETmodel discovery is exempt. The enforced endpoint follows the presence of the selected effort:/responseswith one,/chat/completionswithout.drain()waits out admitted responses while rejecting new ones.Tests
20 cases across
routing-controller.test.jsandrouting-enforcement.test.js, covering the planning payload shapes, the attempt and capacity accounting, each degradation reason, terminal-failure handling, the endpoint/effort pairing, header overrides, byte-preserving failure observation, drain, and upgrade rejection.