firewall-ai-gateway-debug

작성자: vercel

방화벽 및 Vercel AI Gateway 디버깅: 네트워크 정책 허용 목록, OIDC 토큰 갱신, AI Gateway 변환 규칙, 방화벽…

npx skills add https://github.com/vercel-labs/vercel-openclaw --skill firewall-ai-gateway-debug

Firewall AI Gateway Debug

Use this skill for model-call failures, egress blocks, network policy drift, or AI Gateway token refresh problems.

Evidence First

Collect:

  • GET /api/admin/preflight or launch verification preflight evidence.
  • GET /api/admin/logs filtered for firewall., token., gateway., watchdog..
  • GET /api/admin/sandbox-diag.
  • Current firewall mode and learned/allowed domains from admin surfaces.
  • Sanitized model-call or gateway error body. Do not print Authorization tokens.

Critical Splits

  • AI Gateway credential unavailable vs expired vs circuit-breaker-open.
  • Static API key bypass vs OIDC token path.
  • Firewall learning/allowlist issue vs model provider/API issue.
  • OPENAI_BASE_URL inside sandbox is present, while Authorization is injected by network policy transform.
  • Policy object shape changes when an AI Gateway token exists.

Invariants

  • AI Gateway token never enters sandbox files or env.
  • ai-gateway.vercel.sh stays allowed even in enforcing mode.
  • Token refresh applies sandbox.update({ networkPolicy }); it should not rewrite config files or restart the gateway.
  • Public/admin display URLs must not expose deployment-protection bypass secrets.

Fix Boundaries

  • Primary: src/server/firewall/{domains,policy,state}.ts.
  • Token path: src/server/sandbox/lifecycle.ts, src/server/deploy-preflight.ts.
  • Public URLs: src/server/public-url.ts.
  • Tests: firewall policy tests, token refresh tests, launch-verify/preflight tests.
  • Docs: docs/environment-variables.md, docs/deployment-protection.md, lat.md/sandbox-lifecycle.md.

Verification

node scripts/verify.mjs --steps=test,typecheck
lat check

For live incidents, prove a model call succeeds after the policy/token change and that no token value appears in logs, UI, or sandbox config.

vercel의 다른 스킬

benchmark-sandbox
vercel
Vercel Sandbox에서 vercel-plugin eval 시나리오를 로컬 WezTerm 패널 대신 실행합니다. Claude Code와 플러그인이 사전 설치된 임시 마이크로VM을 프로비저닝합니다.
official
emil-design-eng
vercel
이 스킬은 Emil Kowalski의 UI 폴리시, 컴포넌트 디자인, 애니메이션 결정, 그리고 소프트웨어를 훌륭하게 만드는 보이지 않는 세부 사항에 대한 철학을 인코딩합니다.
official
vercel-react-best-practices
vercel
Vercel Engineering의 React 및 Next.js 성능 최적화 가이드라인입니다. 이 스킬은 React/Next.js 코드를 작성, 검토 또는 리팩토링할 때 사용해야 합니다.
official
vercel-react-best-practices
vercel
Vercel Engineering의 React 및 Next.js 성능 최적화 가이드라인입니다. 이 스킬은 React/Next.js 코드를 작성, 검토 또는 리팩토링할 때 사용해야 합니다.
official
write-guide
vercel
점진적인 예제를 통해 실제 사용 사례를 가르치는 기술 가이드를 제작합니다. 개념은 독자가 필요로 할 때만 소개됩니다.
official
release
vercel
Vercel-plugin 릴리스 — 게이트 실행, 버전 업, 아티팩트 생성, 커밋 및 푸시. "릴리스", "배포", "버전 업 및 푸시", "릴리스 생성" 요청 시 사용.
official
deepsec
vercel
dev3000에서 체크아웃한 Vercel 프로젝트에 대해 DeepSec을 실행합니다. 원클릭 DeepSec 설정, 프로젝트 컨텍스트 부트스트래핑, 제한된 1차 처리 등에 사용합니다.
official
backport-pr
vercel
병합된 Next.js 풀 리퀘스트를 canary에서 next-16-2와 같은 이전 릴리스 브랜치로 백포트합니다. 사용자가 백포트, 체리픽 또는 열기를 요청할 때 사용합니다…
official