LLM Gateway
sickn33/agentic-awesome-skills
Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.
Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills llm-gateway --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/infrastructure/networking/llm-gateway .claude/skills/llm-gateway && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "llm-gateway" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gateway into .claude/skills/llm-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "llm-gateway", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gatewayType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills llm-gateway --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/infrastructure/networking/llm-gateway .agents/skills/llm-gateway && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "llm-gateway" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gateway into .agents/skills/llm-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "llm-gateway", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills llm-gateway --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/infrastructure/networking/llm-gateway .cursor/skills/llm-gateway && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "llm-gateway" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gateway into .cursor/skills/llm-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "llm-gateway", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/BagelHole/DevOps-Security-Agent-Skills.git --path infrastructure/networking/llm-gateway--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills llm-gateway --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/infrastructure/networking/llm-gateway .gemini/skills/llm-gateway && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "llm-gateway" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gateway into .gemini/skills/llm-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "llm-gateway", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills llm-gatewayInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/infrastructure/networking/llm-gateway .github/skills/llm-gateway && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "llm-gateway" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gateway into .github/skills/llm-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "llm-gateway", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install BagelHole/DevOps-Security-Agent-Skills llm-gateway --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/infrastructure/networking/llm-gateway .opencode/skills/llm-gateway && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "llm-gateway" agent skill from https://github.com/BagelHole/DevOps-Security-Agent-Skills/tree/main/infrastructure/networking/llm-gateway into .opencode/skills/llm-gateway/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "llm-gateway", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
llm-gatewayDeploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.
LLM Gateway is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking. Covers LiteLLM Proxy, OpenRouter-compatible setup, and custom Nginx/Traefik patterns.
Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering, covering Model routing and gateways, Cloud networking and Rate limiting. It works with NGINX, OpenRouter, Docker and vLLM. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.
Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curldockerFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl and docker, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OPENAI_API_KEYLITELLM_MASTER_KEYANTHROPIC_API_KEYLANGFUSE_PUBLIC_KEYLANGFUSE_SECRET_KEYPOSTGRES_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
LLM Gateway loads about 2k tokens when it runs. Until then it costs about 61 tokens; SKILL.md has 283 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 283 words, ~1,986 tokens.
.claude/skills/llm-gateway/SKILL.md (or your agent's skills folder).A unified API gateway that routes LLM requests across providers and self-hosted models — with rate limiting, cost tracking, caching, and failover.
Use this skill when:
LiteLLM is the de facto open-source LLM gateway with OpenAI-compatible API.
# Run with Docker
docker run -d \
--name litellm-proxy \
-p 4000:4000 \
-e OPENAI_API_KEY=$OPENAI_API_KEY \
-e ANTHROPIC_API_KEY=$ANTHROPIC_API_KEY \
-v $(pwd)/litellm-config.yaml:/app/config.yaml \
ghcr.io/berriai/litellm:main-latest \
--config /app/config.yaml \
--detailed_debug# litellm-config.yaml
model_list:
# OpenAI models
- model_name: gpt-4o
litellm_params:
model: openai/gpt-4o
api_key: os.environ/OPENAI_API_KEY
rpm: 10000
tpm: 2000000
- model_name: gpt-4o-mini
litellm_params:
model: openai/gpt-4o-mini
api_key: os.environ/OPENAI_API_KEY
# Anthropic
- model_name: claude-sonnet-4-6
litellm_params:
model: anthropic/claude-sonnet-4-6
api_key: os.environ/ANTHROPIC_API_KEY
# Self-hosted vLLM instances (load balanced)
- model_name: llama-3.1-8b
litellm_params:
model: openai/meta-llama/Llama-3.1-8B-Instruct
api_base: http://vllm-1:8000/v1
api_key: fake # vLLM key
- model_name: llama-3.1-8b
litellm_params:
model: openai/meta-llama/Llama-3.1-8B-Instruct
api_base: http://vllm-2:8000/v1 # second replica — auto load balanced
api_key: fake
# Fallback: cheap model if primary fails
- model_name: gpt-4o
litellm_params:
model: openai/gpt-4o-mini # fallback to cheaper model
api_key: os.environ/OPENAI_API_KEY
router_settings:
routing_strategy: least-busy # or: latency-based, simple-shuffle
num_retries: 3
retry_after: 5
allowed_fails: 2
cooldown_time: 60
# Fallback configuration
fallbacks:
- gpt-4o: [claude-sonnet-4-6]
- claude-sonnet-4-6: [gpt-4o]
litellm_settings:
# Semantic caching
cache: true
cache_params:
type: redis
host: redis
port: 6379
similarity_threshold: 0.90 # cache if >90% semantic similarity
# Logging
success_callback: ["langfuse"]
failure_callback: ["langfuse"]
langfuse_public_key: os.environ/LANGFUSE_PUBLIC_KEY
langfuse_secret_key: os.environ/LANGFUSE_SECRET_KEY
general_settings:
master_key: os.environ/LITELLM_MASTER_KEY
database_url: postgresql://litellm:password@postgres:5432/litellm
store_model_in_db: trueservices:
litellm:
image: ghcr.io/berriai/litellm:main-latest
command: ["--config", "/app/config.yaml", "--port", "4000"]
volumes:
- ./litellm-config.yaml:/app/config.yaml
ports:
- "4000:4000"
environment:
- OPENAI_API_KEY=${OPENAI_API_KEY}
- ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY}
- LITELLM_MASTER_KEY=${LITELLM_MASTER_KEY}
- DATABASE_URL=postgresql://litellm:password@postgres:5432/litellm
depends_on:
postgres:
condition: service_healthy
redis:
condition: service_started
restart: unless-stopped
postgres:
image: postgres:16-alpine
environment:
POSTGRES_DB: litellm
POSTGRES_USER: litellm
POSTGRES_PASSWORD: password
volumes:
- postgres-data:/var/lib/postgresql/data
healthcheck:
test: ["CMD-SHELL", "pg_isready -U litellm"]
interval: 5s
retries: 5
restart: unless-stopped
redis:
image: redis:7-alpine
command: redis-server --maxmemory 2gb --maxmemory-policy allkeys-lru
volumes:
- redis-data:/data
restart: unless-stopped
volumes:
postgres-data:
redis-data:# Create a virtual API key for a team (via LiteLLM API)
curl -X POST http://localhost:4000/key/generate \
-H "Authorization: Bearer $LITELLM_MASTER_KEY" \
-H "Content-Type: application/json" \
-d '{
"team_id": "team-backend",
"key_alias": "backend-team-key",
"models": ["gpt-4o-mini", "llama-3.1-8b"],
"max_budget": 100, # USD limit
"budget_duration": "monthly",
"rpm_limit": 100, # requests per minute
"tpm_limit": 500000 # tokens per minute
}'
# View spend
curl http://localhost:4000/spend/keys \
-H "Authorization: Bearer $LITELLM_MASTER_KEY"# nginx.conf — round-robin across vLLM replicas
upstream vllm_backends {
least_conn;
server vllm-1:8000 max_fails=3 fail_timeout=30s;
server vllm-2:8000 max_fails=3 fail_timeout=30s;
server vllm-3:8000 max_fails=3 fail_timeout=30s;
keepalive 32;
}
server {
listen 80;
server_name llm-api.internal;
# Rate limiting
limit_req_zone $http_authorization zone=per_key:10m rate=100r/m;
limit_req zone=per_key burst=20 nodelay;
location /v1/ {
proxy_pass http://vllm_backends;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_read_timeout 300s; # long timeout for streaming
proxy_buffering off; # required for SSE streaming
proxy_cache_bypass 1;
}
}# Check LiteLLM health
curl http://localhost:4000/health
# Model-level health
curl http://localhost:4000/health/liveliness
# Spend by model
curl http://localhost:4000/spend/models \
-H "Authorization: Bearer $LITELLM_MASTER_KEY"
# Active virtual keys
curl http://localhost:4000/key/list \
-H "Authorization: Bearer $LITELLM_MASTER_KEY"| Issue | Cause | Fix |
|---|---|---|
ConnectionRefusedError to backend | Backend not reachable | Check api_base URL; verify backend is healthy |
| Rate limit errors (429) | Budget/RPM exceeded | Increase limits or rotate to fallback model |
| Slow streaming responses | proxy_buffering enabled | Set proxy_buffering off in Nginx |
| Cache miss rate high | Threshold too strict | Lower similarity_threshold to 0.85 |
| Postgres connection errors | DB not ready | Add depends_on with condition: service_healthy |
cache: true with Redis for repeated or similar queries; can cut costs 30–50%.num_retries: 3 with fallbacks to handle provider outages gracefully.least-busy routing strategy for self-hosted models to avoid GPU saturation.© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in infrastructure/networking/llm-gateway of BagelHole/DevOps-Security-Agent-Skills.
Open the folder on GitHubat commit 0365f57
LLM Gateway next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| LLM Gateway this skillBagelHole/DevOps-Security-Agent-Skills | 1.2k | — | ~2k | Automated safety check: Pass | MIT | |
| LLM Gatewaysickn33/agentic-awesome-skills | 47k | 1 repos | ~2.1k | Automated safety check: Pass | MIT | |
| Openrouter Load Balancingjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Using Ccproxy Inspectorstarbaser/ccproxy | 350 | — | ~2.7k | Automated safety check: Pass | Custom licence | |
| Openrouter Rate Limitsjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~2.4k | Automated safety check: Pass | MIT | |
| Proxy Mode ReferenceMadAppGang/claude-code | 285 | — | ~1.3k | Automated safety check: Pass | MIT |
sickn33/agentic-awesome-skills
Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.
jeremylongshore/tons-of-skills-marketplace
Distribute OpenRouter requests across multiple keys and models for high throughput.
starbaser/ccproxy
Operates the ccproxy inspector MITM system for intercepting, inspecting, and transforming LLM API traffic.
jeremylongshore/tons-of-skills-marketplace
Understand and handle OpenRouter rate limits. An agent skill from jeremylongshore/tons-of-skills-marketplace.
MadAppGang/claude-code
Reference guide for using external AI models via claudish CLI.
decolua/9router
Generates vector embeddings through the 9Router /v1/embeddings endpoint, using models from providers such as OpenAI, Gemini, Mistral and Voyage for RAG and semantic search.
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
BagelHole/DevOps-Security-Agent-Skills
Set up metrics collection and visualization with Prometheus and Grafana.
BagelHole/DevOps-Security-Agent-Skills
Scan systems and dependencies for CVEs and security vulnerabilities.
Works with
Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking. LLM Gateway is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Deploy an API gateway for LLM traffic with load balancing, rate limiting, key management, semantic caching, fallback routing, and cost tracking.
LLM Gateway fits situations like: tasks that involve Model routing and gateways; tasks that involve Cloud networking; tasks that involve Rate limiting.
Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a claude-code`. Or copy the skill folder (infrastructure/networking/llm-gateway in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/llm-gateway in your project. Claude Code loads it when a task matches its description.
Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a codex`. Or copy the skill folder (infrastructure/networking/llm-gateway in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/llm-gateway in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill llm-gateway -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/llm-gateway, .gemini/skills/llm-gateway, .github/skills/llm-gateway and .opencode/skills/llm-gateway in your project.
Going by SKILL.md and its folder, LLM Gateway needs the command-line tools its instructions call (curl and docker) and credentials named OPENAI_API_KEY, LITELLM_MASTER_KEY, ANTHROPIC_API_KEY and LANGFUSE_PUBLIC_KEY. Our summary lists: Docker; A credential in OPENAI_API_KEY; A credential in ANTHROPIC_API_KEY.
SKILL.md contains no URLs. Its commands use curl and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
LLM Gateway is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with LLM Gateway: LLM Gateway (sickn33/agentic-awesome-skills, 47k stars), Openrouter Load Balancing (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Using Ccproxy Inspector (starbaser/ccproxy, 350 stars) and Openrouter Rate Limits (jeremylongshore/tons-of-skills-marketplace, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,152 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.
Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.