Skip to content

Gateway

  • A gateway is the one front door to every model server: authentication, limits, routing, caching, and metering live there, so the engines stay simple and keyless.
  • Everything it adds must leave streaming intact: bytes are forwarded and flushed as they arrive, and failures after the first byte become SSE error events.
  • The gateway continues the caller’s trace with its own span, so one request is one trace from client to engine.

Work the chapters in order with ol start <ID>, ol check <ID>. The tracer chapter (gw.00) is in Pass 1; the server skeleton, streaming observer, routing, and the rest follow in Pass 7, each upgrading the same go/gateway/ packages behind the same OpenAI-compatible surface.


An LLM gateway is a reverse proxy whose payload is a stream. Every feature it gains (keys, rate limits, caching, routing, usage accounting) is a step in a middleware chain in front of one operation: copy the engine’s response to the client, chunk by chunk, without delaying the first token. The tracer gateway is that operation plus a key check and trace propagation; later modules insert the rest of the chain around it.

Key ideas:

  • Two HTTP exchanges per request: client to gateway, gateway to engine. Hop-by-hop headers stay on their hop; the gateway’s own key never travels further.
  • Middleware order is a contract (gw.01): requestid -> otel -> recover -> authn -> policy -> ratelimit -> cache -> route -> proxy -> meter.
  • Before the first byte the gateway can still choose a status (401, 429, 503); after it, only an SSE error event.
TrackConnection
Streaming & SSEthe wire format the gateway forwards
Authorization & Access ControlAPI keys and scopes (gw.02, gw.03)
Distributed Data & Cachingthe response cache (gw.06)
Model Routing & Cascadesrouting and cascades (gw.05)
Observabilitythe gateway.proxy span and gateway metrics (obs.*)
#ModuleChapterKindPass
1gw.00Tracer gateway: static API-key check, SSE pass-through without buffering, traceparent and X-Request-Id propagationbuild1
2gw.01Server skeleton, composition root, go/config, graceful shutdownbuild7
3gw.04SSE streaming proxy (upgrades gw.00)build7
4gw.05Worker registry, routing, cascades, failover, disaggregated orchestrationbuild7
5gw.07Usage ledger, metering, admin APIbuild7
6gw.08Usage policy enforcementbuild10