LLMProxy v0.3.0 adds provider operations, shared credential coordination and verifiable container releases.
What changed
- Provider-key dashboard and API: add encrypted keys, enable or disable keys, and inspect fingerprints, usage, failures and cooldowns. One provider account supports up to 64 keys.
- Shared key pools: Redis coordinates rotation and cooldowns across replicas. Managed-key changes propagate automatically; active requests retain their captured credentials.
- Optional live checks: validate credentials and model discovery, or run a small generation probe against a configured model.
- Operational alerts: durable budget, error-rate, response-header latency and exhausted-pool alerts, with acknowledgment, recovery, deduplication and optional webhook delivery.
- GitHub protections: required CI checks and resolved conversations on main, administrator enforcement, secret scanning and push protection, private vulnerability reporting and dependency security updates.
- Verified releases: vulnerability scans for both architectures, Sigstore signatures and scan attestations in both registries, SPDX SBOMs, build provenance and checksums. The README, OpenAPI, deployment examples and operations guides cover the new behavior.
Upgrade from v0.2.0
- Drain existing replicas and back up the database and configuration. Apply the additive
ProviderOperationsmigration once for SQLite or PostgreSQL before restarting replicas when automatic migration is disabled. - Existing configured single keys and key arrays remain compatible. To add keys through the dashboard, set
LLMPROXY_PROVIDER_KEY_ENCRYPTION_KEYto one base64-encoded 32-byte key, identical on every replica. Back it up separately; changing it requires re-encrypting stored credentials. - Review alert thresholds. Live provider checks and webhook delivery are opt-in. Confirm readiness, existing traffic, provider-key status and alerts after deployment.
Complete upgrade notes · Provider operations and configuration
Images and verification
docker pull mohammedtv/llmproxy:0.3.0- Docker Hub:
mohammedtv/llmproxy:0.3.0(public). - GHCR:
ghcr.io/mo7ammedd/llmproxy:v0.3.0(authentication with package read access required). - Platforms:
linux/amd64andlinux/arm64. - Verified index digest in both registries:
sha256:aad94fb63c556702115cfa6d624b487f443d3c18d9c39215f9c0b9e09c924473. - Source commit:
1fa11c5. - Successful release CI.
The release passed 347 .NET tests with PostgreSQL and Redis enabled, the recovery drill, native AMD64/ARM64 container and SDK checks, vulnerability gates and signature/attestation verification. Automated provider traffic uses mocks; live account access and model availability depend on your credentials and configuration.
The vulnerability gate rejects HIGH or CRITICAL findings with published fixes. Full reports also include lower-severity and unfixed findings. Download the attached evidence files together and run sha256sum -c SHA256SUMS. Use Cosign verification to verify origin with this workflow identity:
https://github.com/Mo7ammedd/LLMProxy/.github/workflows/ci.yml@refs/tags/v0.3.0