Skip to content

fix(templates): map LITELLM_API_KEY to OPENAI_API_KEY in Temporal workers - #514

Open
michaelxu2288 wants to merge 2 commits into
scaleapi:mainfrom
michaelxu2288:fix/templates-temporal-openai-key
Open

michaelxu2288 wants to merge 2 commits into
scaleapi:mainfrom
michaelxu2288:fix/templates-temporal-openai-key

Conversation

@michaelxu2288

@michaelxu2288 michaelxu2288 commented Sep 10, 2026 •

Copy link
Copy Markdown

Problem

temporal-openai-agents and temporal-pydantic-ai ship an .env.example that only sets LITELLM_API_KEY. In the OpenAI Agents template, project/acp.py copies it into OPENAI_API_KEY; the Pydantic AI template never does. In both, the model call runs in the Temporal worker, a separate process started by agentex agents run, which never gets the mapping. Following either template's own instructions fails in the worker with openai.OpenAIError: Missing credentials after the activity's retries, while the ACP process looks healthy and the task just never answers. (temporal-langgraph is fine: graph.py, which the worker imports, already maps the key.)

Repro: agentex init (Temporal + OpenAI Agents SDK, or Temporal + Pydantic AI), .env with only LITELLM_API_KEY=<openai key>, run against ./dev.sh, send a message: no reply; worker log shows Missing credentials.

Fix

Apply the same three-line mapping (no-op when OPENAI_API_KEY is already set) in both project/run_worker.py templates, and add a parametrized test asserting the worker entrypoints carry it.

Verification

Scaffolded agents against a local backend with only LITELLM_API_KEY set:

  • Temporal + OpenAI Agents: before, no reply and Missing credentials x7 retries; after, reply in 4.7 s (gpt-5-nano), zero worker tracebacks.
  • Temporal + Pydantic AI: before, same failure; after (together with the CLI .env fix), reply in 4.7 s, zero worker errors.

Depends on / pairs with #515 ("fix(cli): load the agent's .env into locally run ACP and worker processes"): without it, .env reaches the worker only through litellm's import-time load_dotenv(), which is too late for frameworks that build their client at import. The mapping is placed at the top of run_worker.py, before project imports, for that reason.
tests/lib/cli/test_init_templates.py: 28 passed. ruff clean.

RetriggerConfidence Score: 4/5

The PR is not ready to merge because a generated requirements image can fail to build when its private mirror lacks a public dependency.

What we checked:

  • Worker reads the key too late: Both changed entrypoints load .env and map the key before their project imports.

Summary

The PR adds early API-key setup to two Temporal worker templates and makes ACP wait for task creation before replying. It also updates the SDK’s production URL and changes release, security-scanning, and repository CI workflows.

  • Keeps Temporal workers from starting model calls without the configured key.
  • Makes task creation finish before callers send events.
  • Updates the production endpoint and expands CI and release automation.
Diagram
%%{init: {'theme': 'neutral'}}%%
flowchart LR
  S[Injected index secret] --> D[Requirements Dockerfile]
  D --> M[Private mirror as default]
  M -->|Package present| B[Image builds]
  M -->|Public package missing| F[Image build fails]
Loading

Reviews (3) · Last reviewed commit: "fix(templates): load the project .env in..."

@stainless-app
stainless-app Bot force-pushed the next branch 2 times, most recently from bc51c52 to 761833e Compare September 18, 2026 21:47
…kers

The temporal-openai-agents and temporal-pydantic-ai templates' .env.example
only set LITELLM_API_KEY. The OpenAI Agents template's acp.py copies it into
OPENAI_API_KEY, the Pydantic AI template never does, and in both the model
call runs in the Temporal worker, a separate process started by
agentex agents run, which never got the mapping. Following either template's
own instructions fails in the worker with openai.OpenAIError: Missing
credentials after the activity's retries, while the ACP process looks
healthy. (temporal-langgraph is fine: graph.py, imported by the worker,
already does the mapping.)

Apply the same three-line mapping in both run_worker.py templates and add a
parametrized test asserting the worker entrypoints carry it.

Reproduced and verified on scaffolded agents against a local backend with
only LITELLM_API_KEY set: before, no reply and Missing credentials in the
worker log; after, the turn completes (gpt-5-nano).

Claude-Session: https://claude.ai/code/session_01HCVKnA7LeJZ44nxZz1uzF3
…apping the key

The worker is a separate process and agents run does not load the project
.env into it today, so the LITELLM_API_KEY -> OPENAI_API_KEY mapping ran
against an empty environment. Call load_dotenv() first (as acp.py already
does), so the template works on its own; scaleapi#515 makes the CLI load .env for
both processes as well.

Claude-Session: https://claude.ai/code/session_01HCVKnA7LeJZ44nxZz1uzF3
@michaelxu2288
michaelxu2288 force-pushed the fix/templates-temporal-openai-key branch from b5f5e05 to cd23d16 Compare October 1, 2026 09:40
@michaelxu2288
michaelxu2288 changed the base branch from next to main October 1, 2026 09:40

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant