/** * Deployment policy for embedding models and their endpoint. * * The ai-gateway provider catalog is the authority for which models a * deployment provides. A Cloud deployment must not offer arbitrary embedding * models — not even through a BYOK credential — and a Cloud user cannot supply an * endpoint: the catalog names the provider and the endpoint, the user only brings * an API key. A Local deployment may use any model and any endpoint the user * configures. This module is the single decision point so the registration, * configuration and runtime paths cannot drift apart. */ export declare const EMBEDDING_MODEL_NOT_ALLOWED = "embedding_model_not_allowed"; export declare const EMBEDDING_ENDPOINT_NOT_PROVIDED = "embedding_endpoint_not_provided"; /** Port over the ai-gateway provider catalog. */ export interface EmbeddingModelCatalog { /** True only for models this catalog provides as embedding models. */ isManagedEmbeddingModel(provider: string, modelId: string): boolean; /** Endpoint this deployment provides for that provider, if it provides one. */ managedEmbeddingBaseUrl(provider: string): string | undefined; } export interface EmbeddingModelPolicyInput { deployment: string; catalog?: EmbeddingModelCatalog; } export interface EmbeddingModelRequest { provider: string; model: string; } /** Endpoint inputs a Pod may carry. A Cloud deployment ignores the Pod values. */ export interface EmbeddingEndpointRequest { provider: string; baseUrl?: string; proxyUrl?: string; } export interface EmbeddingEndpoint { baseUrl?: string; proxyUrl?: string; /** Whether the endpoint came from the deployment catalog or from the Pod. */ source: 'catalog' | 'pod'; } export declare class EmbeddingPolicyError extends Error { readonly code: string; protected constructor(code: string, message: string); } export declare class EmbeddingModelNotAllowedError extends EmbeddingPolicyError { constructor(provider: string, model: string); } export declare class EmbeddingEndpointNotProvidedError extends EmbeddingPolicyError { constructor(provider: string); } export declare class EmbeddingModelPolicy { private readonly catalog?; private constructor(); /** Local deployments (and runtimes without a catalog) keep arbitrary BYOK models. */ static allowAll(): EmbeddingModelPolicy; static fromCatalog(catalog: EmbeddingModelCatalog): EmbeddingModelPolicy; isEnforced(): boolean; isAllowed(input: EmbeddingModelRequest): boolean; assertAllowed(input: EmbeddingModelRequest): void; /** * Resolve the endpoint an embedding call may use. * * Local (and catalog-less runtimes) keep whatever the Pod carries. A Cloud * deployment replaces the Pod endpoint with the one its catalog provides and * drops any Pod proxy, so a BYOK key can never redirect Cloud egress. */ resolveEndpoint(input: EmbeddingEndpointRequest): EmbeddingEndpoint; } export declare function createEmbeddingModelPolicy(input: EmbeddingModelPolicyInput): EmbeddingModelPolicy; /** True for every deployment rejection, so callers never retry a policy decision. */ export declare function isEmbeddingPolicyRejection(error: unknown): boolean; export declare function isEmbeddingModelNotAllowedError(error: unknown): boolean; /** * Parse an AI Config model assignment (`settings/providers/.ttl#` * or its absolute form) into the provider/model pair the policy checks. A ref * that does not name both cannot be proven to be provided, so it resolves to * `undefined` and an enforcing policy rejects it. */ export declare function parseEmbeddingModelRef(ref: string): EmbeddingModelRequest | undefined;