☰
BFE mod_ai_token_auth 基础配置指南:为大模型 api-key 鉴权模块配置规则文件、Redis 连接与日志开关
2026/10/10 2:24:40 网站建设 项目流程
  • 后端
  • 网络/通信
  • 云原生

【免费下载链接】bfe

A modern layer 7 load balancer from baidu

项目地址:https://gitcode.com/gh_mirrors/bf/bfe
点击查看免费下载

mod_ai_token_auth.conf是 BFE(Baidu Front End)mod_ai_token_auth 模块的基础配置文件,负责指定 api-key 规则配置文件(token_rule.data)的路径、Redis 连接信息以及 debug 日志开关。mod_ai_token_auth 是 BFE 中面向大模型服务的 api-key(token)鉴权模块:一个 api-key 代表一个对某些大模型服务拥有一定访问权限和配额的令牌,模块根据规则对请求Authorization头中携带的 api-key 进行校验,并配合 Redis 完成配额扣减。

读完本文你将掌握:mod_ai_token_auth.conf每个配置项的类型、默认值与合法性约束;如何基于仓库中的真实示例编写一份可运行的配置文件;以及各配置项在源码中是如何被加载、校验并影响模块行为的。

配置文件位置与加载方式

在仓库中,模块的默认示例配置文件位于 conf/mod_ai_token_auth/mod_ai_token_auth.conf,规则文件默认路径为mod_ai_token_auth/token_rule.data(对应仓库中的 conf/mod_ai_token_auth/token_rule.data)。

模块启动时通过Init()加载配置(见 mod_ai_token_auth.go):

confPath := bfe_module.ModConfPath(cr, m.name) if m.conf, err = ConfLoad(confPath, cr); err != nil { return fmt.Errorf("%s: conf load err %v", m.name, err) } openDebug = m.conf.Log.OpenDebug

ConfLoad使用gopkg.in/gcfg.v1读取 ini 格式的配置文件(见 conf_mod_ai_token_auth.go)。需要注意的是:gcfg 对 ini 的节名(section)和键名(key)匹配不区分大小写,因此示例中[Basic]、[Redis]、[Log]与源码中的Basic、Redis、Log结构体一一对应,键名大小写均可接受。

配置项总览

下表完整列出 mod_ai_token_auth.conf.md 中定义的全部配置项:

配置项类型参数含义必填补充描述合法性条件
Basic.ProductRulePathStringapi-key 声明和规则配置的文件路径N默认值为mod_ai_token_auth/token_rule.data类型为 FilePath;文件须存在且可读
Redis.BnsStringRedis 服务的 bns 名YRedis 用于存储 api-key 的配额使用量须为有效的 Redis 服务地址
Redis.ConnectTimeoutInteger连接超时时间(毫秒)Y-必须大于 0
Redis.ReadTimeoutInteger读取超时时间(毫秒)Y-必须大于 0
Redis.WriteTimeoutInteger写入超时时间(毫秒)Y-必须大于 0
Redis.MaxIdleInteger最大空闲连接数Y-必须大于等于 0
Redis.MaxActiveInteger最大活跃连接数Y0 表示不限必须大于等于 0
Redis.PasswordStringRedis 密码N未配置时不启用认证-
Log.OpenDebugBoolean是否开启 debug 日志N默认值为False-

对应到源码中的配置结构体(conf_mod_ai_token_auth.go),可以更清晰地看到分组关系:

type ConfModAITokenAuth struct { Basic struct { ProductRulePath string } // redis conf Redis struct { Bns string // bns name for redis proxy ConnectTimeout int // connect timeout (ms) ReadTimeout int // read timeout (ms) WriteTimeout int // write timeout(ms) MaxIdle int // max idle connections in pool Password string // redis password,ignore if not set MaxActive int // max active connections in pool, 0 means no limit } Log struct { OpenDebug bool } }

Basic 分组

  • ProductRulePath:指定 api-key 规则文件路径,即 token_rule.data.md 所描述的规则文件。它是可选项:当配置为空时,模块会打印告警并使用默认值mod_ai_token_auth/token_rule.data(见 conf_mod_ai_token_auth.go):
if cfg.Basic.ProductRulePath == "" { log.Logger.Warn("ModAITokenAuth.ProductRulePath not set, use default value") cfg.Basic.ProductRulePath = "mod_ai_token_auth/token_rule.data" } cfg.Basic.ProductRulePath = bfe_util.ConfPathProc(cfg.Basic.ProductRulePath, confRoot)

加载后还会通过bfe_util.ConfPathProc基于confRoot将相对路径解析为绝对路径。该规则文件支持热加载:模块将 reload handler 注册为loadProductRuleConf(mod_ai_token_auth.go),运维可通过 BFE 的 reload 接口在不重启进程的情况下更新规则。

Redis 分组

Redis 用于存储 api-key 的配额余额(见 token.go 中的HasBalance与Deduct实现)。除Redis.Password外均为必填项:

  • Bns:Redis 服务的 bns 名,bns(Baidu Naming Service)是百度内部的命名服务。配置加载时通过redis_client.CheckRedisConf校验其合法性(conf_mod_ai_token_auth.go),该函数会解析 bns 配置字符串,解析失败即报错(client.go)。
  • ConnectTimeout / ReadTimeout / WriteTimeout:连接、读、写超时时间(毫秒)。源码校验要求三者都严格大于 0:
// check connectTimeOut if cfg.Redis.ConnectTimeout <= 0 { return fmt.Errorf("Redis.ConnectTimeout must > 0") } // check Read/Write Timeout if cfg.Redis.ReadTimeout <= 0 || cfg.Redis.WriteTimeout <= 0 { return fmt.Errorf("Redis.ReadTimeout/WriteTimeout must > 0") }
  • MaxIdle / MaxActive:连接池的最大空闲连接数与最大活跃连接数;MaxActive设为 0 表示不限制连接数。
  • Password:可选。未配置时不启用 Redis 认证。

这些参数最终被组装进redis_client.Options,用于创建 Redis 客户端(mod_ai_token_auth.go):

r := m.conf.Redis options := &redis_client.Options{ ServiceConf: r.Bns, MaxIdle: r.MaxIdle, MaxActive: r.MaxActive, Wait: false, ConnTimeoutMs: r.ConnectTimeout, ReadTimeoutMs: r.ReadTimeout, WriteTimeoutMs: r.WriteTimeout, Password: r.Password, } client := redis_client.NewRedisClient(options) m.redisClient = client

Log 分组

  • OpenDebug:布尔开关,默认False。开启后,模块在匹配规则、产品未找到等路径上输出 debug 日志(见 mod_ai_token_auth.go 中openDebug的判断),并在模块初始化时通过openDebug = m.conf.Log.OpenDebug赋值到包级变量。生产环境建议保持关闭,避免日志量过大。

完整配置示例

以下是文档中给出的完整示例(mod_ai_token_auth.conf.md),可直接复制后按环境调整:

[Basic] ProductRulePath = mod_ai_token_auth/token_rule.data [Redis] # bns addr bns = BLB.ALB-redis # timeout in ms connectTimeout = 20 readTimeout = 20 writeTimeout = 20 # max idle connections maxIdle = 20 # max active connections maxActive = 100 # redis password (optional) password = [Log] OpenDebug = false

仓库中的实际示例配置文件 conf/mod_ai_token_auth/mod_ai_token_auth.conf 与之结构一致,仅将 bns 换成了BFE.poc-redis-wx,并省略了maxActive与password(省略时取 Go 零值,即MaxActive=0表示不限连接数、Password为空表示不启用认证)。注意示例中节名与键名大小写混用([basic]/[log]、ProductRulePath),这恰好验证了 gcfg 大小写不敏感的解析行为。

配置校验与加载流程小结

综合源码(conf_mod_ai_token_auth.go)与文档(mod_ai_token_auth.conf.md),配置文件从落盘到生效的完整流程为:

  1. 读取:ConfLoad通过gcfg.ReadFileInto将 ini 内容解析进ConfModAITokenAuth结构体;
  2. 补默认值:ProductRulePath为空时回退到mod_ai_token_auth/token_rule.data,并调用ConfPathProc解析为绝对路径;
  3. 校验:Check依次校验Redis.Bns可解析、ConnectTimeout、ReadTimeout、WriteTimeout均大于 0;任何一项不满足都会返回错误并导致模块初始化失败;
  4. 生效:Init将OpenDebug写入包级变量、依据 Redis 参数创建客户端,并调用loadProductRuleConf加载规则文件,随后注册HandleFoundProduct等过滤器(mod_ai_token_auth.go)。

模块在HandleFoundProduct回调点执行鉴权,规则匹配成功后依次进行 token 有效性(enabled / expired_time)、配额余额、源 IP 子网等检查(详见 token_rule_table.go),模型 allow/block 检查则在 AI 转发阶段(HandleAfterAITargetModel)对最终解析出的目标模型进行复核(model_check.go)。配额扣除发生在HandleRequestFinish回调,通过 Lua 脚本对 Redis key 执行原子扣减(token.go),因此本文中 Redis 相关配置项(bns、超时、连接池、密码)直接决定了鉴权与计费链路的可用性与性能。

关联文档与进一步阅读

  • 模块功能与工作原理总览:mod_ai_token_auth 模块说明(含请求携带 api-key 的方式Authorization: Bearer <api-key>与鉴权流程图解、监控指标 REQ_TOTAL / REQ_AUTH / REQ_AUTH_FAIL)
  • 规则文件(api-key 声明、配额计划、鉴权规则)详解:token_rule.data 规则配置
  • FilePath 等通用配置类型约定:配置公共约定
  • 路由条件表达式语法(Config中Cond字段的编写规范):Condition 语法
  • 模块注册与整体配置入口:bfe.conf 基础配置
  • 后端
  • 网络/通信
  • 云原生

【免费下载链接】bfe

A modern layer 7 load balancer from baidu

项目地址:https://gitcode.com/gh_mirrors/bf/bfe
点击查看免费下载
上一篇:Formily表单验证:3分钟搞定复杂表单验证的完整指南
下一篇:如何永久保存微信聊天记录:WeChatMsg完整教程指南

创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考

需要专业的网站建设服务?

联系我们获取免费的网站建设咨询和方案报价,让我们帮助您实现业务目标

立即咨询