Uh oh!
There was an error while loading. Please reload this page.
feat(admin): add admin.enabled switch to run without the admin listener - #791
Conversation
A standalone gateway could only run admin-less in managed mode, which needs the full mTLS/control-plane bootstrap. admin.enabled = false (default true) lets etcd/file mode skip binding the admin listener too — the shape the gateway takes once the Admin API is removed. The proxy, the metrics/status listener, and /status/models are unaffected; the metrics listener still reads models through the same store handle, and Config::validate drops the admin_keys/admin.addr requirement when there is no surface to authenticate. This is the enabler for retiring the Admin API: it makes the admin-listener-off configuration runnable and testable during the coexistence window, before any admin code is deleted. The e2e harness gains an admin: false spawn mode that seeds resources straight to etcd (never the Admin API) and gates readiness on the proxy /livez plus the metrics listener; a new admin-disabled e2e proves an etcd-seeded request path works with the admin listener off.
Warning Review limit reached
Next review available in:37 minutes Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available. How can I continue?After more reviews become available, a review can be triggered using the To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews. How do review limits work?CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability. For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window. Please refer docs for additional details. Review details⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (4)
📝 WalkthroughWalkthroughChangesAdmin listener control
Estimated code review effort: 3 (Moderate) | ~20 minutes Sequence Diagram(s)sequenceDiagram
participant E2ETest
participant AppHarness
participant aisix
participant etcd
participant Upstream
E2ETest->>AppHarness: spawn with admin false
AppHarness->>aisix: generate disabled admin configuration
E2ETest->>etcd: seed gateway configuration
aisix->>Upstream: proxy chat completion
E2ETest->>aisix: query metrics and admin health
Suggested reviewers: 🚥 Pre-merge checks | ✅ 5 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
moonming
commented
Jul 21, 2026
@coderabbitai full review |
✅ Action performedFull review finished. Your plan includes PR reviews subject to rate limits. More reviews will be available in 59 minutes. |
Address the cold-audit findings on the admin.enabled switch: - MEDIUM: file-mode admin-off routes through a distinct store branch (FileManagedStore) that had no coverage — every new test was etcd-only. Add a file-mode config unit test and a file-source admin-off e2e leg (declarative resources.yaml, one proxy request, /status/config reports the file-loaded model, admin port refused). - LOW: skip the redundant admin etcd client at boot when admin is off (is_managed() || !admin.enabled) — /status/models then reads the snapshot, as in managed mode, and boot no longer fails on a connection it immediately drops. - LOW: assert the admin port is specifically ECONNREFUSED, not any throw. - LOW: assert exact resource_counts (models/provider_keys/api_keys == 1) under the unique etcd prefix, not >= 1. - LOW: document that admin-off + prometheus-off reduces readiness to the proxy /livez.
moonming
commented
Jul 21, 2026
Independent cold audit (diverse-lens: correctness / security+breaking / e2e-coverage, 3 agents → synthesis). All findings addressed in MEDIUM — file-mode admin-off had zero coverage. File mode binds the admin surface through a distinct store branch ( LOW (batched into the same commit):
The correctness and security lenses independently confirmed |
…n-off Close the last coverage corner the audit noted: the file-mode FileManagedStore /status/models read was only exercised admin-on. The file admin-off leg now reads the runtime health view on the metrics listener and asserts the file-loaded model row — the read surface that must stay live once the admin listener is gone.
moonming
commented
Jul 21, 2026
@coderabbitai review |
✅ Action performedReview finished.
|
What
Add an
admin.enabledstartup-config switch (defaulttrue) that lets a standalone gateway run without binding the admin listener, and wire the e2e harness to spawn in that mode. This is the foundation for retiring the Admin API: it makes the admin-listener-off configuration a runnable, tested reality during the coexistence window, before any admin code is deleted.Why
The gateway already runs admin-less in managed mode (config comes from the control plane over etcd). But in standalone etcd/file mode the admin listener was always bound — there was no way to preview the post-removal world, and the e2e harness had no way to prove the request path works without it.
admin.enabled = falsecloses that gap:SeedClient, never the Admin API).admin.enabledis a process-level startup-config toggle (likeproxy.addr), not a per-resource setting, so it carries no control-plane/schema work.Changes
AdminConfig.enabled: bool(crates/aisix-core/src/config.rs), defaults totrue. Whenfalse,Config::validateno longer requiresadmin_keys/admin.addr(there is no surface to authenticate), mirroring the existing managed-mode relaxation.crates/aisix-server/src/main.rs): the admin listener is spawned only when its store is present andadmin.enabled./status/config,/status/ready,/status/models,/metrics(metrics listener) and the proxy/livezare unaffected — the metrics/status listener is bound independently and still reads models through the same store handle, so/status/modelskeeps working with the admin listener off.tests/e2e/src/harness/app.ts):AppOverrides.admin?: boolean(defaulttrue). Withadmin: false, the generated config carriesadmin.enabled = falseand readiness gates on the proxy/livez+ the metrics listener instead of/admin/v1/health.admin-disabled-e2e.test.ts): spawnsadmin: false, seeds a provider key + model + caller key only through etcd, and asserts (1) a proxy chat request succeeds, (2)/status/configreports the applied config on the metrics listener, (3) the admin port is not bound (connection refused).enableddefaults totrue;enabled: falserelaxes theadmin_keysrequirement.Verification
cargo fmt,cargo clippy -p aisix-core -p aisix-server -p aisix-admin --all-targets -D warnings,cargo test -p aisix-core --lib(config, +2 new) and-p aisix-admin --lib(114) green.admin-disabled-e2egreen (3/3). Regression:allowed-modelsandseed-vs-admin-characterization(exercises both the admin and etcd-seed paths) green — withadmindefaulting totrue, the admin-on config + readiness are byte-identical to before, so existing tests are unaffected. Full e2e suite green locally.Scope / follow-ups (this is P0-1 step 1 of the Admin API removal — AISIX-Cloud#1007 Phase 4)
This PR delivers the switch. It does not yet flip the suite: several tests still seed through
AdminClient, and a few deliberately exercise the Admin API (characterization, file-mode 409 rejection, key rotation, auth baseline). Follow-ups:AdminClient→SeedClient) and relocate the harness's default readiness probe off/admin/v1/health.admin.enabledin the configuration-files reference (api7/docs).Summary by CodeRabbit
New Features
Bug Fixes
Tests