The two seed scripts are fully superseded by the new admin endpoint `POST /api/admin/config/router` — same encryption, same configKV writes, same `configkv:invalidate` publish, plus auth + audit + body limits. Keeping both code paths created a drift risk on the AAD label and the merge semantics. Doc + test fallout: - `e2e-llm-router.ts` now points readers to the admin endpoint for the prerequisite seed step. - `docs/ai-context/verifications/llm-router.md` and `streaming-tts.md` get curl-based seed instructions; the 2026-05-15 llm-router evidence stays intact with a note that the script it used has since been removed. - The U9 follow-up entry in `llm-router.md` flips from "not shipped" to "partially shipped" — ETag + HMAC publish are still deferred, so the `config_write` / `config_invalid_hmac` Grafana panels stay parked. - Self-edit on the admin route + `app.ts` docstrings to drop the earlier "scripts stay as break-glass" wording.
@proj-airi/server
HTTP and WebSocket backend for AIRI. This app owns auth, billing, chat synchronization, gateway forwarding, and server-side observability export.
What It Does
- Serves the Hono-based API and WebSocket endpoints.
- Uses Postgres as the source of truth for users, billing, and durable state.
- Uses Redis for cache, KV, Pub/Sub, and Streams.
- Forwards GenAI requests to the configured upstream gateway and records billing from usage.
- Exports traces, metrics, and logs through OpenTelemetry.
How To Use It
Install dependencies from the repo root and run scoped commands:
pnpm -F @proj-airi/server typecheck
pnpm -F @proj-airi/server exec vitest run
pnpm -F @proj-airi/server build
For local observability infrastructure, use:
docker compose -f apps/server/docker-compose.otel.yml up -d
ADDITIONAL_TRUSTED_ORIGINS (LAN / Capacitor dev)
When the mobile dev server uses a non-localhost origin (for example https://10.x.x.x:5273 from cap copy ios / capacitor.config.json), set ADDITIONAL_TRUSTED_ORIGINS in apps/server/.env.local to a comma-separated list of exact origins (parsed and normalized at startup). Example:
ADDITIONAL_TRUSTED_ORIGINS=https://10.0.0.129:5273,https://198.18.0.1:5273
Restart the API server after changing this variable.