Agent skill

Config Architecture

by majiayu000 in majiayu000/litellm-rs

LiteLLM-RS Configuration Architecture. An agent skill from majiayu000/litellm-rs.

MITAuto-check passedAI & LLM Engineering

Install Config Architecture

skills CLI
$ npx skills add majiayu000/litellm-rs --skill config-architecture -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install majiayu000/litellm-rs config-architecture --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/majiayu000/litellm-rs.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/config-architecture .claude/skills/config-architecture && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
config-architecture
GitHub stars
118
Token cost
~3.2k tokens
SKILL.md length
593 words
Files
4
Skills in repo
9
Repo updated
First seen
Licence
MIT

At a glance

LiteLLM-RS Configuration Architecture. An agent skill from majiayu000/litellm-rs.

  • Changing config models
  • SKILL.md covers Overview, YAML Configuration Structure, Type-Safe Configuration Models and Environment Variable…, plus 2 more sections
  • Reaches api.openai.com; needs OPENAI_API_KEY and LITELLM_JWT_SECRET
  • Debugging env variable substitution failures

What it does

Config Architecture is an agent skill from majiayu000/litellm-rs. LiteLLM-RS Configuration Architecture. Covers YAML loading with ${VAR} environment substitution, strict serde config models, startup validation via the Validate trait, and the LITELLM env-only fallback. Use when changing config models or serde defaults, debugging env variable substitution failures, updating validation rules, altering config loading behavior, or troubleshooting gateway.yaml.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files (for example `reference/best-practices.md`, `reference/provider-config-errors.md` and `reference/validation.md`).

It sits in AI & LLM Engineering, covering Model routing and gateways. It works with Rust and OpenAI. The repository describes itself as: Self-hosted Rust LLM gateway with OpenAI-compatible APIs, load balancing, failover, and a reusable Rust kernel. The licence is MIT.

When your agent uses it

  • Changing config models
  • Debugging env variable substitution failures
  • Updating validation rules
  • Altering config loading behavior

Example prompts

  • “/config-architecture”

Requirements

  • A credential in OPENAI_API_KEY
  • A credential in LITELLM_JWT_SECRET

What it can do on your machine

Read from SKILL.md and the folder at commit ed3f4d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are rust and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY
    • LITELLM_JWT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Config Architecture loads about 3.2k tokens when it runs. Until then it costs about 104 tokens; SKILL.md has 593 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~104
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from majiayu000/litellm-rs at commit ed3f4d9, republished under its MIT licence (© majiayu000). 593 words, ~3,152 tokens.

Download SKILL.mdSave it as .claude/skills/config-architecture/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
config-architecture
description
LiteLLM-RS Configuration Architecture. Covers YAML loading with ${VAR} environment substitution, strict serde config models, startup validation via the Validate trait, and the LITELLM_* env-only fallback. Use when changing config models or serde defaults, debugging env variable substitution failures, updating validation rules, altering config loading behavior, or troubleshooting gateway.yaml.

Configuration Architecture Guide

Overview

LiteLLM-RS loads a single YAML file into type-safe Rust models (GatewayConfig in src/config/models/gateway.rs and its children), substitutes ${VAR} / $VAR tokens from the process environment during load, fills missing fields from serde defaults, then validates the whole tree once at startup.

There is no hot reload. Configuration is read once at startup; src/utils/config/optimized.rs states this explicitly ("Hot reload is not supported"). Restart the process to pick up changes. AppState.config (src/server/state.rs) is atomically swappable by explicit code paths, but nothing watches the file.

Load Order
┌─────────────────────────────────────────────────────────────────┐
│  1. YAML file                                                   │
│     --config PATH (default: "config/gateway.yaml", src/main.rs) │
└─────────────────────────────────────────────────────────────────┘
                              ↓
┌─────────────────────────────────────────────────────────────────┐
│  2. Environment substitution (substitute_env_vars)              │
│     ${VAR} = required (hard error if unset)                     │
│     $VAR   = best-effort (left literal if unset)                │
└─────────────────────────────────────────────────────────────────┘
                              ↓
┌─────────────────────────────────────────────────────────────────┐
│  3. serde parse + defaults                                      │
│     #[serde(default ...)] fills omitted fields;                 │
│     deny_unknown_fields rejects keys on structs that opt in     │
└─────────────────────────────────────────────────────────────────┘
                              ↓
┌─────────────────────────────────────────────────────────────────┐
│  4. Validation (Validate trait)                                 │
│     runs inside Config::from_file / Config::from_env            │
│     failure aborts startup                                      │
└─────────────────────────────────────────────────────────────────┘

After loading, explicit --host / --port CLI values overwrite server.host / server.port, then the config is re-validated (load_config_with_overrides in src/main.rs).

Fallback rule: when the gateway starts without an explicit --config and the default file fails to load, run_server_with_default_config_overrides retries with Config::from_env(), which builds the config from LITELLM_* environment variables only (src/config/models/gateway.rs::GatewayConfig::from_env). An explicit --config path that fails is a hard error — no env fallback (load_explicit_config in src/server/builder.rs).

There is no search-path chain: no /etc/litellm/..., no gateway.yaml in cwd. The only default is the single constant DEFAULT_CONFIG_PATH = "config/gateway.yaml" relative to the process working directory (src/main.rs).


YAML Configuration Structure

The canonical example is config/gateway.yaml.example; unit tests assert it parses against the current schema. Top-level sections of GatewayConfig:

yaml
schema_version: "1.0"        # only "1.0" is accepted by validation

server:                      # host/port/workers/timeout/max_body_size/tls/cors/features/...
providers:                   # LIST of provider entries, not a map
  - name: "openai-primary"
    provider_type: "openai"
    api_key: "${OPENAI_API_KEY}"
    base_url: "https://api.openai.com/v1"
    models: ["gpt-4o"]
    priority: 0              # lower wins under priority_based routing

model_aliases:               # public alias -> canonical model or another alias
  production-chat: "gpt-4o"

router:                      # strategy, circuit_breaker, load_balancer
storage:                     # database, redis, vector_db
auth:                        # enable_jwt, enable_api_key, jwt_secret, rbac, allow_anonymous
monitoring:                  # metrics, tracing, health, callbacks
cache:                       # deterministic response cache
rate_limit:                  # token bucket strategy, redis_failure_mode
guardrails:                  # content safety; prompt-injection protection on by default
ip_access:                   # allowlist/blocklist; empty/default rules allow all
enterprise:                  # sso, audit_logging
pricing:                     # source, unpriced_model_policy

Unknown top-level fields are rejected at parse time (#[serde(deny_unknown_fields)] on GatewayConfig), as are unknown keys in the nested YAML models that carry the same attribute. This is not a universal serde guarantee: providers[].settings is intentionally open-ended, and some provider/callback backend payload structs do not deny unknown fields. There are no top-level logging, routing, or observability sections — logging lives under monitoring.logging, routing under router.


Type-Safe Configuration Models

Root Configuration

src/config/models/gateway.rs:

rust
#[derive(Debug, Clone, Serialize, Deserialize)]
#[serde(deny_unknown_fields)]
pub struct GatewayConfig {
    pub schema_version: String,                    // default "1.0"
    pub server: ServerConfig,
    pub providers: Vec<ProviderConfig>,            // Vec, not a map
    pub model_aliases: HashMap<String, String>,    // default empty
    pub router: GatewayRouterConfig,
    pub storage: StorageConfig,
    pub auth: AuthConfig,
    pub monitoring: MonitoringConfig,
    pub cache: CacheConfig,                        // default
    pub rate_limit: RateLimitConfig,               // default
    pub guardrails: GuardrailConfig,               // default = enabled
    pub ip_access: IpAccessConfig,                 // default
    pub enterprise: EnterpriseConfig,              // default
    pub pricing: GatewayPricingConfig,             // default
}
Server Configuration

src/config/models/server.rs:

rust
#[serde(deny_unknown_fields)]
pub struct ServerConfig {
    pub host: String,                      // default "0.0.0.0"
    pub port: u16,                         // default 8000
    pub workers: Option<usize>,            // None -> CPU count at runtime
    pub max_connections: Option<usize>,
    pub timeout: u64,                      // seconds, default 30
    pub max_body_size: usize,              // bytes, default 10 MiB
    pub dev_mode: bool,                    // default false
    pub tls: Option<TlsConfig>,
    pub cors: CorsConfig,
    pub features: Vec<String>,
    pub trusted_proxies: Vec<String>,      // X-Forwarded-For trust list
    pub stream_idle_timeout: u64,          // SSE idle timeout, default 300s; 0 disables
}

Shared defaults live in src/config/models/mod.rs: default_port() returns 8000, default_timeout() returns 30, default_max_body_size() returns 10 * 1024 * 1024. There is no keep_alive, request_timeout, or string-form max_request_size field.

Provider Configuration

src/config/models/provider.rs — one entry per deployment, stored as Vec<ProviderConfig>:

rust
#[serde(deny_unknown_fields)]
pub struct ProviderConfig {
    pub name: String,                      // must be unique across entries
    pub provider_type: String,             // e.g. "openai", "anthropic"
    pub api_key: String,                   // required unless registry skips key checks
    pub base_url: Option<String>,
    pub endpoint_access: ProviderEndpointAccess, // default PublicOnly; "private_network" opt-in
    pub api_version: Option<String>,
    pub organization: Option<String>,
    pub project: Option<String>,
    pub weight: f32,                       // default 1.0, valid range (0, 100]
    pub priority: u32,                     // default 0; lower wins in priority_based
    pub rpm: u32,                          // default 1000
    pub tpm: u32,                          // default 100_000
    pub max_concurrent_requests: u32,      // default 10
    pub timeout: u64,                      // seconds, default 30, max 300
    pub max_retries: u32,                  // default 3
    pub retry: RetryConfig,                // base_delay/max_delay/backoff_multiplier/jitter
    pub health_check: ProviderHealthCheckConfig,
    pub settings: HashMap<String, serde_json::Value>, // provider-specific keys
    pub models: Vec<String>,
    pub tags: Vec<String>,
    pub enabled: bool,                     // default true
}

This is the YAML-facing model. The separate ProviderConfig trait that provider implementations satisfy lives in src/core/traits/provider/config.rs — see reference/provider-config-errors.md.


Show full SKILL.md (268 more words)Show less

Environment Variable Substitution

substitute_env_vars in src/config/mod.rs processes the raw file text before parsing:

  • ${VAR_NAME} — substituted with the env value. If unset, loading fails: all missing braced variables are collected, deduplicated, sorted, and reported in one error (Missing environment variables referenced by config: A, B). Placeholders can never silently reach runtime as literal strings.
  • $VAR_NAME — shell-style bare form, also substituted. If unset, the token is left literal so ordinary dollar-containing values pass through untouched.
  • ${VAR:-default} is not supported and is silently dangerous: neither recognized pattern matches a token containing :-, so the whole string stays literal in the parsed value — no substitution and no error.
  • Substitution is line-based and quote/comment aware: text after an unquoted # (a YAML comment) is never substituted, and values pulled from the environment are not re-expanded.
  • Errors surface as GatewayError::Config (the runtime loader does not use ConfigError; see reference/provider-config-errors.md).
yaml
# Works
api_key: "${OPENAI_API_KEY}"        # fails startup if OPENAI_API_KEY is unset
url: "$REDIS_URL"                   # left literal if REDIS_URL is unset

# Does NOT work - no fallback syntax; url becomes the literal
# string "${REDIS_URL:-redis://localhost:6379}"
url: "${REDIS_URL:-redis://localhost:6379}"

Separately, when the implicit-default serve path falls back to env-only configuration, GatewayConfig::from_env reads dedicated LITELLM_* variables (LITELLM_HOST, LITELLM_PORT, LITELLM_DATABASE_URL, LITELLM_JWT_SECRET, LITELLM_PROVIDERS, ... — see the constants atop src/config/models/gateway.rs). This is independent of ${VAR} substitution inside YAML.


Configuration Loading

Actual chain, Config::from_file in src/config/mod.rs:

rust
pub async fn from_file<P: AsRef<Path>>(path: P) -> Result<Self> {
    let content = tokio::fs::read_to_string(path).await
        .map_err(|e| GatewayError::Config(format!("Failed to read config file: {}", e)))?;
    let content = substitute_env_vars(&content)?;          // hard error on missing ${VAR}
    let gateway: GatewayConfig = serde_yml::from_str(&content)
        .map_err(|e| GatewayError::Config(format!("Failed to parse config: {}", e)))?;
    let config = Self { gateway };
    config.validate()?;                                    // Validate trait, single entry point
    Ok(config)
}

Entry points:

PathBehavior
gateway --config FILE ...loads exactly that file; failure is fatal
gateway serve (no --config)tries config/gateway.yaml; on any load error retries via Config::from_env()
gateway validate-configloads + validates only, prints result

Secret redaction happens only on export: to_json / to_yaml replace known secrets (provider API keys, jwt_secret, HMAC secret, S3/vector/SSO credentials) with [REDACTED] before serializing.

References

© majiayu000, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in .claude/skills/config-architecture of majiayu000/litellm-rs.

  • SKILL.md
  • reference/best-practices.md
  • reference/provider-config-errors.md
  • reference/validation.md

Open the folder on GitHubat commit ed3f4d9

Compare with similar skills

Config Architecture next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Config Architecture compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Config Architecture this skillmajiayu000/litellm-rs118—~3.2kAutomated safety check: PassMIT
Evaluating Bitrouter Routesbitrouter/bitrouter235—~1.2kAutomated safety check: PassApache-2.0
Run Bitrouter Benchmarkbitrouter/bitrouter235—~2.2kAutomated safety check: PassApache-2.0
Run Shuntpleaseai/shunt203—~2.6kAutomated safety check: PassApache-2.0
Provider Integrationhex/claude-council857—~635Automated safety check: PassMIT
9Router AI Gateway Setupdecolua/9router31k—~744Automated safety check: PassMIT

Similar skills

  • Evaluating Bitrouter Routes

    bitrouter/bitrouter

    A skill your agent uses when evaluating BitRouter route decisions or Eval Exchange subjects with task-native verifiers, human reviewers, private enterprise evaluators, agentic judges, or genuinely…

    235 GitHub stars~1.2k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Run Bitrouter Benchmark

    bitrouter/bitrouter

    A skill your agent uses when a user wants to run, compare, resume, audit, share, or submit a Harbor benchmark through BitRouter, including choosing a Harbor dataset and agent, confirming routed…

    235 GitHub stars~2.2k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Run Shunt

    pleaseai/shunt

    Build, launch, and drive shunt — the Claude Code LLM gateway (a Rust/axum Anthropic-Messages proxy).

    203 GitHub stars~2.6k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Provider Integration

    hex/claude-council

    Adds new AI providers to claude-council, configures provider API settings, troubleshoots provider connections, and documents the provider script interface.

    857 GitHub stars~635 tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Sets up access to the 9Router AI gateway, an OpenAI-compatible REST endpoint for chat, images, speech, embeddings, web search and web fetch, and indexes its capability skills.

    31k GitHub stars~744 tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Sends chat and code-generation requests through a 9Router gateway using OpenAI or Anthropic message formats, with streaming and auto-fallback combos.

    31k GitHub stars~635 tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed

More from majiayu000/litellm-rs

All 9 skills in this repo
  • Auth Architecture

    majiayu000/litellm-rs

    LiteLLM-RS Authentication Architecture. An agent skill from majiayu000/litellm-rs.

    118 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • Caching Architecture

    majiayu000/litellm-rs

    LiteLLM-RS response caching architecture. An agent skill from majiayu000/litellm-rs.

    118 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Error Handling

    majiayu000/litellm-rs

    LiteLLM-RS Error Handling Architecture. An agent skill from majiayu000/litellm-rs.

    118 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Observability Architecture

    majiayu000/litellm-rs

    LiteLLM-RS Observability Architecture. An agent skill from majiayu000/litellm-rs.

    118 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • Provider Architecture

    majiayu000/litellm-rs

    LiteLLM-RS provider system in two tiers - data-driven OpenAI-compatible catalog entries auto-routed through OpenAILikeProvider, plus code-based provider modules implementing the LLMProvider trait…

    118 GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Routing Architecture

    majiayu000/litellm-rs

    LiteLLM-RS Routing Architecture. An agent skill from majiayu000/litellm-rs.

    118 GitHub stars~1.9k tokensUpdated today
    Auto-check passed

Works with

Questions about Config Architecture

What does Config Architecture do?

LiteLLM-RS Configuration Architecture. An agent skill from majiayu000/litellm-rs. Config Architecture is an agent skill from majiayu000/litellm-rs. LiteLLM-RS Configuration Architecture.

When should I use Config Architecture?

Config Architecture fits situations like: changing config models; debugging env variable substitution failures; updating validation rules; altering config loading behavior.

How do I install Config Architecture in Claude Code?

Run `npx skills add majiayu000/litellm-rs --skill config-architecture -a claude-code`. Or copy the skill folder (.claude/skills/config-architecture in majiayu000/litellm-rs) into .claude/skills/config-architecture in your project. Claude Code loads it when a task matches its description.

How do I install Config Architecture in Codex?

Run `npx skills add majiayu000/litellm-rs --skill config-architecture -a codex`. Or copy the skill folder (.claude/skills/config-architecture in majiayu000/litellm-rs) into .agents/skills/config-architecture in your project. Codex loads it when a task matches its description.

Can I use Config Architecture in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add majiayu000/litellm-rs --skill config-architecture -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/config-architecture, .gemini/skills/config-architecture, .github/skills/config-architecture and .opencode/skills/config-architecture in your project.

What does Config Architecture need to run?

Going by SKILL.md and its folder, Config Architecture needs credentials named OPENAI_API_KEY and LITELLM_JWT_SECRET. Our summary lists: A credential in OPENAI_API_KEY; A credential in LITELLM_JWT_SECRET.

Does Config Architecture access the network?

SKILL.md names 1 domain. In commands or code: api.openai.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Config Architecture safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Config Architecture use?

Config Architecture is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Config Architecture use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Config Architecture?

Skills that share tags, products or a category with Config Architecture: Evaluating Bitrouter Routes (bitrouter/bitrouter, 235 stars), Run Bitrouter Benchmark (bitrouter/bitrouter, 235 stars), Run Shunt (pleaseai/shunt, 203 stars) and Provider Integration (hex/claude-council, 857 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Config Architecture?

majiayu000 (a GitHub user) maintains it in majiayu000/litellm-rs, which has 118 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 11, 2026.

Source: majiayu000/litellm-rs on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.