Skip to main content

coder ai-gateway start

On this page

Run a standalone AI Gateway server

Usage

coder ai-gateway start [flags]

Description

Runs a standalone replica of the AI Gateway. Standalone replicas serve LLM client traffic on a dedicated HTTP listener and connect to coderd using the Coder deployment URL and an AI Gateway key. Set --url or CODER_URL to the Coder deployment address, and set --key (CODER_AI_GATEWAY_KEY) or --key-file (CODER_AI_GATEWAY_KEY_FILE). A user login or session token is not required.

Options

--key

Typestring
Environment$CODER_AI_GATEWAY_KEY

The AI Gateway key used to authenticate to coderd.

--key-file

Typestring
Environment$CODER_AI_GATEWAY_KEY_FILE

Path to a file containing the AI Gateway key used to authenticate to coderd.

--http-address

Typestring
Environment$CODER_AI_GATEWAY_HTTP_ADDRESS
Default127.0.0.1:4001

The bind address to serve incoming AI Gateway client traffic.

--tls-cert-file

Typestring
Environment$CODER_AI_GATEWAY_TLS_CERT_FILE

Path to a PEM-encoded TLS certificate. Enables TLS termination when set together with --tls-key-file.

--tls-key-file

Typestring
Environment$CODER_AI_GATEWAY_TLS_KEY_FILE

Path to a PEM-encoded TLS private key. Enables TLS termination when set together with --tls-cert-file.

--prometheus-enable

Typebool
Environment$CODER_PROMETHEUS_ENABLE
YAMLintrospection.prometheus.enable

Serve prometheus metrics on the address defined by prometheus address.

--prometheus-address

Typehost:port
Environment$CODER_PROMETHEUS_ADDRESS
YAMLintrospection.prometheus.address
Default127.0.0.1:2112

The bind address to serve prometheus metrics.

--trace

Typebool
Environment$CODER_TRACE_ENABLE
YAMLintrospection.tracing.enable

Whether application tracing data is collected. It exports to a backend configured by environment variables. See: https://github.com/open-telemetry/opentelemetry-specification/blob/main/specification/protocol/exporter.md.

--trace-honeycomb-api-key

Typestring
Environment$CODER_TRACE_HONEYCOMB_API_KEY

Enables trace exporting to Honeycomb.io using the provided API Key.

--trace-logs

Typebool
Environment$CODER_TRACE_LOGS
YAMLintrospection.tracing.captureLogs

Enables capturing of logs as events in traces. This is useful for debugging, but may result in a very large amount of events being sent to the tracing backend which may incur significant costs.

-l, --log-filter

Typestring-array
Environment$CODER_LOG_FILTER
YAMLintrospection.logging.filter

Filter debug logs by matching against a given regex. Use .* to match all debug logs.

--log-human

Typestring
Environment$CODER_LOGGING_HUMAN
YAMLintrospection.logging.humanPath
Default/dev/stderr

Output human-readable logs to a given file.

--log-json

Typestring
Environment$CODER_LOGGING_JSON
YAMLintrospection.logging.jsonPath

Output JSON logs to a given file.

--log-stackdriver

Typestring
Environment$CODER_LOGGING_STACKDRIVER
YAMLintrospection.logging.stackdriverPath

Output Stackdriver compatible logs to a given file.

--experiments

Typestring-array
Environment$CODER_EXPERIMENTS
YAMLexperiments

Enable one or more experiments. These are not ready for production. Separate multiple experiments with commas, or enter '*' to opt-in to all available experiments.

-c, --config

Typeyaml-config-path
Environment$CODER_CONFIG_PATH

Specify a YAML file to load configuration from.

--ai-gateway-max-concurrency

Typeint
Environment$CODER_AI_GATEWAY_MAX_CONCURRENCY
YAMLai_gateway.max_concurrency
Default0

Maximum number of concurrent AI Gateway requests per replica. Set to 0 to disable (unlimited).

--ai-gateway-rate-limit

Typeint
Environment$CODER_AI_GATEWAY_RATE_LIMIT
YAMLai_gateway.rate_limit
Default0

Maximum number of AI Gateway requests per second per replica. Set to 0 to disable (unlimited).

--ai-gateway-structured-logging

Typebool
Environment$CODER_AI_GATEWAY_STRUCTURED_LOGGING
YAMLai_gateway.structured_logging
Defaultfalse

Emit structured logs for AI Gateway interception records. Use this for exporting these records to external SIEM or observability systems.

--ai-gateway-structured-logging-source

Typecoderd|gateway|both
Environment$CODER_AI_GATEWAY_STRUCTURED_LOGGING_SOURCE
YAMLai_gateway.structured_logging_source
Defaultcoderd

Which process emits AI Gateway interception records when structured logging is enabled: coderd, the gateway, or both. The gateway emits records that are never persisted, such as those dropped by --ai-gateway-disable-content-recording, but cannot report thread_parent_id or thread_root_id. Use both to verify a move from one to the other; records reaching coderd are then reported twice. A standalone gateway must be configured to emit its own records, and its logs shipped rather than coderd's.

--ai-gateway-disable-content-recording

Typebool
Environment$CODER_AI_GATEWAY_DISABLE_CONTENT_RECORDING
YAMLai_gateway.disable_content_recording
Defaultfalse

Stop recording the content of intercepted conversations. No user prompt, tool call or model reasoning record is stored, including tool names and the arguments they were called with. Interceptions and token usage are still recorded, so cost controls, budget enforcement and spend reporting are unaffected. Sessions show no conversation detail, prompt and tool call telemetry report zero, and interceptions are no longer grouped into threads for clients that do not send their own session ID. Combine with --ai-gateway-structured-logging-source=gateway to keep exporting these records to a SIEM instead.

--ai-gateway-send-actor-headers

Typebool
Environment$CODER_AI_GATEWAY_SEND_ACTOR_HEADERS
YAMLai_gateway.send_actor_headers
Defaultfalse

Add configured headers identifying the authenticated user to intercepted upstream requests. Use this when a proxy between AI Gateway and an upstream AI provider needs user identity. When enabled, removes client-supplied headers at configured actor-header destinations before adding authenticated values. Client headers starting with X-AI-Bridge-Actor are always removed.

--ai-gateway-actor-header-id

Typestring
Environment$CODER_AI_GATEWAY_ACTOR_HEADER_ID
YAMLai_gateway.actor_header_id
DefaultX-AI-Bridge-Actor-ID

Header name for the authenticated user's ID. Empty disables this header. Requires AI Gateway actor headers to be enabled.

--ai-gateway-actor-header-username

Typestring
Environment$CODER_AI_GATEWAY_ACTOR_HEADER_USERNAME
YAMLai_gateway.actor_header_username
DefaultX-AI-Bridge-Actor-Metadata-Username

Header name for the authenticated user's username. Empty disables this header. Requires AI Gateway actor headers to be enabled.

--ai-gateway-actor-header-email

Typestring
Environment$CODER_AI_GATEWAY_ACTOR_HEADER_EMAIL
YAMLai_gateway.actor_header_email

Header name for the authenticated user's email address. Empty disables this header. Requires AI Gateway actor headers to be enabled. Applies to every configured provider; email is personal information.

--ai-gateway-dump-dir

Typestring
Environment$CODER_AI_GATEWAY_DUMP_DIR
YAMLai_gateway.api_dump_dir

Base directory for dumping AI Gateway request/response pairs to disk for debugging. When set, each provider writes under a subdirectory named after the provider. Sensitive headers are redacted. Leave empty to disable.

--ai-gateway-allow-byok

Typebool
Environment$CODER_AI_GATEWAY_ALLOW_BYOK
YAMLai_gateway.allow_byok
Defaulttrue

Allow users to provide their own LLM API keys or subscriptions. When disabled, only centralized key authentication is permitted.

--ai-gateway-circuit-breaker-enabled

Typebool
Environment$CODER_AI_GATEWAY_CIRCUIT_BREAKER_ENABLED
YAMLai_gateway.circuit_breaker_enabled
Defaultfalse

Enable the circuit breaker to protect against cascading failures from upstream AI provider overload (503, 529).