Documentation
¶
Overview ¶
Package ai mounts the Hanzo AI subsystem (LLM control plane, RAG, model hub, MCP management) into the unified cloud binary per HIP-0106.
App builds the zip.App and routers.Register binds every route onto it natively; there is no net/http router underneath and nothing is adapted onto zip. The adaptation runs the other way, once, at Handler: a host that wants an http.Handler gets the whole App exposed as one. The only net/http left inside is the /v1/voice trio, and routers/router.go says why.
All ~309 X-Org-Id call-sites inside controllers/* continue to read gateway-minted identity headers (X-Org-Id, X-User-Id, X-User-Email) per HIP-0026 — the adapter does not strip headers; zip middleware in the cloud binary already mints them from the JWT before forwarding.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func App ¶ added in v1.833.14
func App(secrets object.SecretStore) (*zip.App, error)
Mount registers AI's HTTP surface per HIP-0106 AND initializes the AI runtime so those routes actually serve.
Routes under /v1/ai/* are forwarded to the registered handler (the the router ControllerRegister built by routers/router.go). The MountSpec contract (cloud.MountAll) gives each subsystem exactly one hook — Mount — and it owns BOTH route wiring and runtime initialization. So Mount calls Bootstrap(), the single shared boot sequence (DB, model config, balance/tier/rate-limit, filters, billing queue) that ends by publishing the handler via SetHandler. Without that call the adapter's getHandler() stays nil and every /v1/ai/* request 503s with "ai runtime not initialized" — the exact defect this fixes.
The same Bootstrap() runs in the standalone cmd/aid entrypoint, so the runtime is defined ONCE and behaves identically embedded or standalone. Bootstrap is sync.Once-guarded, so calling it here is safe even if the process also calls it elsewhere. SECRETS ARRIVE AS AN INTERFACE, NOT AS THE HOST'S Deps. ai is a SUBSYSTEM: it is mounted by a host, and a subsystem that imports its host cannot be mounted by a second one — which is exactly what happened. hanzoai/cloud has two editions, and because this package took cloud.Deps, the private edition's cloud.Deps and the OSS edition's were different types with the same name and neither could mount ai.
object.SetSecretStore already took ai's OWN interface (object.SecretStore: GetSecret/PutSecret), so cloud.Deps was carried across the boundary to reach one field and then discarded. Taking the interface directly costs the host one argument and removes the whole dependency: ai now imports zip and nothing of its host's.
func BillingQueue ¶ added in v1.785.4
func BillingQueue() *util.BillingQueue
BillingQueue returns the Commerce billing usage queue created by Bootstrap, or nil if none was configured / Bootstrap did not reach it.
func Bootstrap ¶ added in v1.785.4
func Bootstrap() error
Bootstrap performs the AI runtime initialization shared by BOTH entrypoints — the standalone server (cmd/aid) and the embedded unified cloud binary (Mount, per HIP-0106). It is the SINGLE source of the runtime boot sequence: DB + adapter + tables, model/pricing config, the HTTP client, GeoIP/parser, the background maintenance tasks, the Commerce-backed balance gate + tier cache + per-key rate limiter, the full BeforeRouter/AfterExec filter chain, the session config, and the billing usage queue. After wiring those it publishes the fully-configured native router via SetHandler so the unified binary's /v1/ai/* adapter stops returning 503 "ai runtime not initialized".
What Bootstrap deliberately does NOT do (those are standalone-only concerns that the embedded binary owns differently, and several would break or collide when co-resident in the unified process):
- It binds NO listeners. The native ZAP inference node (port 9999), the inter-service ZAP transport (CLOUD_ZAP_PORT, default 9320) and the standalone HTTP listener (:httpport) stay in cmd/aid. The unified binary serves routers.App through zip on its own :8080 and runs its own ZAP at :9653; starting the legacy nodes here would collide.
- It calls NO util.StopOldInstance — that races on the legacy standalone port and is meaningless when the embedded binary never listens there.
- It installs NO signal handler and never calls os.Exit. cloud.Serve owns graceful shutdown for the unified binary; cmd/aid keeps its own drain goroutine, wired to the handles returned here.
Bootstrap is guarded by sync.Once: it is safe to call more than once, so Mount can call it at mount time and the standalone can call it explicitly without double-initializing global runtime state. The cached result (including the error) is returned on every call.
It returns an error rather than panicking: several init steps (notably the DB open) panic deep inside on a missing/unreachable backend, which would take down the whole multi-subsystem cloud binary. Bootstrap recovers those into a precise error so Mount can surface "mount ai: bootstrap: ..." and the operator sees exactly what failed.
The rate limiter and billing queue created here are exposed via RateLimiter() and BillingQueue() for the standalone's graceful-drain wiring. Either may be nil (e.g. the billing queue is nil when no Commerce endpoint is configured).
func Document ¶ added in v1.833.90
Document is the OpenAPI projection of the app this process built, or nil before there is one.
It reads the SAME live app Handler serves, for the same reason Handler resolves its router per request: the routes are a projection of the built app, so a document taken from anything else can describe a surface this process is not serving. A host that mounts this module (hanzoai/cloud publishes it into the fleet document) has no app of its own to pass, and should not need one to ask what we serve.
func Handler ¶ added in v1.833.89
Handler is the HTTP surface as an http.Handler, for the ZAP transports that carry an HTTP request over the binary protocol (controllers.InitZapHandlers and InitForwardBridge). It is the same app the socket serves, so a bridged request meets every filter a socketed one does.
The router is resolved PER REQUEST, never captured. App.Fiber() hands out the current generation's router and a generation is a projection — the next build materialises a fresh one, and a captured pointer would keep serving the old table. zip panics on the mirror-image mistake for the same reason.
func RateLimiter ¶ added in v1.785.4
func RateLimiter() *routers.RateLimiter
RateLimiter returns the per-key rate limiter created by Bootstrap, or nil if Bootstrap has not run (or failed before creating it).
Types ¶
This section is empty.
Directories
¶
| Path | Synopsis |
|---|---|
|
Package address names the caller's address on the wire between a host in front and this module.
|
Package address names the caller's address on the wire between a host in front and this module. |
|
builtin_tool/web
Package webtools gives every Responses-API agent the three capabilities the platform already serves and no agent could reach: web search, page fetch, and deep research.
|
Package webtools gives every Responses-API agent the three capabilities the platform already serves and no agent could reach: web search, page fetch, and deep research. |
|
cmd
|
|
|
aid
command
|
|
|
check_ddl
command
|
|
|
pg2sqlite
command
Command pg2sqlite migrates cloud-api's dbx-managed Postgres database to a SQLite file.
|
Command pg2sqlite migrates cloud-api's dbx-managed Postgres database to a SQLite file. |
|
routerdoc
command
Command routerdoc lifts each hand-written route's sentence out of the Go doc comment on the handler it names, into routers/wired_gen.go.
|
Command routerdoc lifts each hand-written route's sentence out of the Go doc comment on the handler it names, into routers/wired_gen.go. |
|
Package funding is the cash circuit-breaker.
|
Package funding is the cash circuit-breaker. |
|
Hedging: ask several providers at once and keep the first answer.
|
Hedging: ask several providers at once and keep the first answer. |
|
internal
|
|
|
authtest
Package authtest mints a credential a test can present.
|
Package authtest mints a credential a test can present. |
|
gemini
Package gemini is the ONE client for Google's Gemini API, covering exactly the four calls this module makes: countTokens, generateContent, batchEmbedContents and models.list.
|
Package gemini is the ONE client for Google's Gemini API, covering exactly the four calls this module makes: countTokens, generateContent, batchEmbedContents and models.list. |
|
iam
Package iam is ai's INTERNAL IAM client: the small, clean OIDC+REST surface ai needs to talk to Hanzo IAM (hanzo.id), decoupled from the retired SDK module github.com/hanzoai/iam-v1.
|
Package iam is ai's INTERNAL IAM client: the small, clean OIDC+REST surface ai needs to talk to Hanzo IAM (hanzo.id), decoupled from the retired SDK module github.com/hanzoai/iam-v1. |
|
Package log is the leveled logging surface for the ai runtime.
|
Package log is the leveled logging surface for the ai runtime. |
|
Package router turns a chat request into a concrete model id.
|
Package router turns a chat request into a concrete model id. |
|
Package upstream is the one place that knows where a provider lives and how a call proves it may reach one.
|
Package upstream is the one place that knows where a provider lives and how a call proves it may reach one. |