mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-25 00:51:28 +02:00
The catalog is the only source of models an operator can pick from, and it cannot know two things that matter. It goes stale — its entries carry comments recording which models a vendor retired on which date — and it cannot see an account: which OpenAI models an org is entitled to, which Bedrock inference profiles a given account and region hold, which Vertex models a project has enabled. Add a client that asks the vendor directly, with the endpoint, auth header and response shape all declared by the catalog rather than supplied by the caller. The four shapes come from probing the live APIs (see the discovery e2e); each vendor invented its own envelope and none can be guessed from the request. Bedrock is the case that shaped the design. Its listing lives on the control plane while inference must go to the runtime host, so Discovery carries its own host. The ids it returns are region-prefixed and are taken verbatim, because that prefix is what AWS requires and it cannot be derived from the configured region — an eu-central-1 account holds global.* profiles alongside its eu.* ones. The vendor is authoritative for the id; the catalog stays authoritative for pricing. A discovered model the shipped table cannot price is reported as such, so it cannot be registered at a silent zero rate. Management has not made outbound calls on an operator's behalf before, and it holds a credential for every provider, so the host is checked before dialing: every resolved address must be public, which covers the cloud metadata address and NetBird's own overlay range, and redirects are not followed since they would move the request to a host the check never saw.