pub struct RoutingPolicy {
pub allowlist: Option<BTreeSet<ProviderKey>>,
pub denylist: BTreeSet<ProviderKey>,
pub max_cost_per_million: Option<MicroCents>,
pub allowed_regions: Option<BTreeSet<String>>,
pub sensitivity: DataSensitivity,
pub sensitivity_allowlist: BTreeMap<DataSensitivity, BTreeSet<ProviderKey>>,
pub preference: Vec<ModelRef>,
pub skip_degraded: bool,
pub required_tag: Option<String>,
}Expand description
Tenant and deployment constraints on routing (spec §20.6, §25.5).
Every filter is opt-in except the sensitivity rule, which fails closed for
Confidential and
Restricted: sending regulated data to a
provider nobody declared is exactly the mistake this field exists to
prevent.
Fields§
§allowlist: Option<BTreeSet<ProviderKey>>When set, only these providers may be used.
denylist: BTreeSet<ProviderKey>Providers that may never be used, whatever the allowlist says.
max_cost_per_million: Option<MicroCents>Ceiling on the profile’s higher per-million price. A profile with an unknown price does not pass a ceiling.
allowed_regions: Option<BTreeSet<String>>When set, only profiles declaring one of these regions may be used. A profile with no declared region does not pass a residency requirement.
sensitivity: DataSensitivityHow sensitive the payload of this call is.
sensitivity_allowlist: BTreeMap<DataSensitivity, BTreeSet<ProviderKey>>Which providers may see data at each sensitivity level.
An absent entry means “no restriction” for
Public and
Internal, and “nothing is allowed” for
Confidential and
Restricted.
preference: Vec<ModelRef>Profiles to try first, in this order. Anything not listed keeps the pool’s declaration order, after the listed ones.
skip_degraded: boolWhether degraded profiles are dropped when a healthy one remains.
Defaults to true through RoutingPolicy::new.
required_tag: Option<String>When set, only profiles carrying this tag may be used. No profile carrying it is an error, never a quiet fallback to an untagged one.
Implementations§
Source§impl RoutingPolicy
impl RoutingPolicy
Sourcepub fn new() -> Self
pub fn new() -> Self
A policy with no restriction beyond capability fit, treating the payload
as Internal and skipping degraded
profiles when a healthy one remains.
Sourcepub fn with_required_tag(self, tag: impl Into<String>) -> Self
pub fn with_required_tag(self, tag: impl Into<String>) -> Self
Admits only profiles carrying tag.
Sourcepub fn with_allowlist<I: IntoIterator<Item = ProviderKey>>(
self,
providers: I,
) -> Self
pub fn with_allowlist<I: IntoIterator<Item = ProviderKey>>( self, providers: I, ) -> Self
Restricts routing to these providers.
Sourcepub fn with_denylist<I: IntoIterator<Item = ProviderKey>>(
self,
providers: I,
) -> Self
pub fn with_denylist<I: IntoIterator<Item = ProviderKey>>( self, providers: I, ) -> Self
Forbids these providers.
Sourcepub fn with_max_cost(self, ceiling: MicroCents) -> Self
pub fn with_max_cost(self, ceiling: MicroCents) -> Self
Sets the cost ceiling.
Sourcepub fn with_regions<I: IntoIterator<Item = String>>(self, regions: I) -> Self
pub fn with_regions<I: IntoIterator<Item = String>>(self, regions: I) -> Self
Restricts routing to these regions.
Sourcepub fn with_sensitivity(self, sensitivity: DataSensitivity) -> Self
pub fn with_sensitivity(self, sensitivity: DataSensitivity) -> Self
Declares the payload’s sensitivity.
Sourcepub fn allowing<I: IntoIterator<Item = ProviderKey>>(
self,
level: DataSensitivity,
providers: I,
) -> Self
pub fn allowing<I: IntoIterator<Item = ProviderKey>>( self, level: DataSensitivity, providers: I, ) -> Self
Declares which providers may see data at level.
Sourcepub fn preferring<I: IntoIterator<Item = ModelRef>>(self, order: I) -> Self
pub fn preferring<I: IntoIterator<Item = ModelRef>>(self, order: I) -> Self
Sets the preference order.
Trait Implementations§
Source§impl Clone for RoutingPolicy
impl Clone for RoutingPolicy
Source§impl Debug for RoutingPolicy
impl Debug for RoutingPolicy
Source§impl Default for RoutingPolicy
impl Default for RoutingPolicy
Source§fn default() -> Self
fn default() -> Self
Same as RoutingPolicy::new.