Block a user
upstream: let an API key read its own allocation and top up, without handing services the account password
upstream: let an API key read its own allocation and top up, without handing services the account password
Merged to main as 18683d90 (branch feat/upstream-key-auth-allocation,
CI run 1142 green — Format, Clippy, Test, CUDA type-check, Web).
Acceptance, all covered by `web_pg::api_key_reads_allo…
grenade
created branch feat/upstream-key-auth-allocation in helexa/helexa
2026-08-17 11:55:28 +00:00
upstream: let an API key read its own allocation and top up, without handing services the account password
slash-less route URLs 301 to port 14443 and hang until the browser times out
frankie (pg standby) needs db-perms.sh re-run when reachable
frankie (pg standby) needs db-perms.sh re-run when reachable
Ran and verified. Both pg hosts are reachable again, and the standby now has the app-owned file with the two mappings that matter:
frankie: moments.conf:cert_cn nikola.kosherinata.internal …
build-web races the api/worker deploys, so the crawler snapshot may not match the api
build-web races the api/worker deploys, so the crawler snapshot may not match the api
helexa.ai serves unmetered inference to anyone with no credential — and anonymous web chat depends on it
Operator decisions (2026-08-17)
- Free access to the large model stays. Anonymous keeps reaching
Qwen/Qwen3.8-27B; the earlier suggestion to demote free users to the small tier is…
helexa.ai serves unmetered inference to anyone with no credential — and anonymous web chat depends on it
anonymous callers are exempt from fair-share, so any unauthenticated client can starve authenticated ones
return the candle fork upstream — or stop calling it temporary; 3 of its 4 commits were never offered
return the cudarc fork upstream — 3 commits, 82 lines, and a PR that was never actually filed
research: quant strategy, and whether NVFP4 on the Blackwell cards buys real throughput