04-28 07:59 · AI政策,并购受阻,监管,外资限制,自主可控
China blocks Meta's acquisition of AI startup Manus
China's state planner on Monday called for Meta to unwind its $2 billion acquisition of Manus, a Singaporean artificial intelligence startup with Chinese roots.
The decision to prohibit foreign investment in Manus was made in accordance with laws and regulations, the National Development and Reform Commission said in a brief statement. It added that it has asked the parties involved to withdraw the acquisition transaction.
CNBC has contacted Meta for comment. Its stock was up slightly in morning trading.
The deal had attracted scrutiny from both China and Washington, as lawmakers in the U.S. have prohibited American investors from backing Chinese AI companies directly. Meanwhile, Beijing has increased efforts to discourage Chinese AI founders from moving business offshore.
The Chinese government's intervention in the transaction drew alarm among tech founders and venture capitalists in the country who were hoping to take advantage of the so-called Singapore-washing model, where companies relocate from China to the city-state to avoid scrutiny from Beijing and Washington.
Manus was founded in China before relocating to Singapore. The company develops general purpose AI agents and launched its first general AI agent in March last year, which can execute complex tasks such as market research, coding and data analysis. The release saw the startup lauded as the next DeepSeek.
Manus said it had passed $100 million in annual recurring revenue, or ARR, in December, eight months on from launching a product, which it claimed made it the fastest startup in the world at the time to hit the milestone from $0.
The company raised $75 million in a round led by U.S. VC Benchmark in April last year.
When Meta announced the deal late last year, the tech giant said it would look to accelerate artificial intelligence innovation for businesses and integrate advanced automation into its consumer and enterprise products, including its Meta AI assistant.
But in January, China's Ministry of Commerce said it would conduct an assessment and investigation into how the acquisition complied with laws and regulations concerning export controls, technology import and export, and overseas investment.
A Meta spokesperson told CNBC that the transaction "complied fully with applicable law," and that it anticipated "an appropriate resolution to the inquiry."
When asked about China's move to block Meta's Manus acquisition, APEC Senior Officials Meeting Chairman Chen Xu told reporters that it is "important that all parties act in a spirit of mutual benefit."
While Chen said he did not know the specifics of the issue, he said that "if such an issue can be handled properly, it can help facilitate more substantive discussions in APEC." That's according to an official English translation.
— CNBC's Anniek Bao and Dylan Butts contributed to this story.
▸ 展开全文
04-28 07:59 · 大模型访问限制,AI成本,模型供应链,API策略,AI应用影响
Claude Pro: Opus model will only be available if extra usage is enabled
This guide shows you three ways to change which Claude model you're using with Claude Code: the quick /model
command for instant changes, the --model
flag for one-time session changes, and environment variables to set your preferred model as the permanent default.
Easiest method: Use /model command
The simplest way to change models is to use the /model command directly within Claude Code. This works immediately without restarting your terminal.
Start Claude Code:
claude
Type
/model
and choose your desired model from the interactive menu.Your model change takes effect immediately.
Supported models
Opus 4.7,
claude-opus-4-7
Sonnet 4.6,
claude-sonnet-4-6
Opus 4.6,
claude-opus-4-6
Opus 4.5,
claude-opus-4-5-20251101
Haiku 4.5,
claude-haiku-4-5-20251001
Sonnet 4.5,
claude-sonnet-4-5-20250929
Change model for current session only
Use the --model
flag when starting Claude Code.
Start a fresh Terminal session.
Enter the following commands (depending on the model you’d like to use for that session):
For Opus 4.7:
claude --model claude-opus-4-7
For Sonnet 4.6:
claude --model claude-sonnet-4-6
For Opus 4.6:
claude --model claude-opus-4-6
For Opus 4.5:
claude --model claude-opus-4-5-20251101
For Haiku 4.5:
claude --model claude-haiku-4-5-20251001
For Sonnet 4.5:
claude --model claude-sonnet-4-5-20250929
Change default model for all future sessions
Step 1) Check your shell type by running: echo $SHELL
/bin/zsh
→ You're using zsh (macOS default)/bin/bash
→ You're using bash (Linux default)
Step 2) Add model setting to your shell config:
For ZSH users (macOS)
Opus 4.7:
echo 'export ANTHROPIC_MODEL="claude-opus-4-7"' >> ~/.zshrc
Sonnet 4.6:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-6"' >> ~/.zshrc
Opus 4.6:
echo 'export ANTHROPIC_MODEL="claude-opus-4-6"' >> ~/.zshrc
Opus 4.5:
echo 'export ANTHROPIC_MODEL="claude-opus-4-5-20251101"' >> ~/.zshrc
Haiku 4.5:
echo 'export ANTHROPIC_MODEL="claude-haiku-4-5-20251001"' >> ~/.zshrc
Sonnet 4.5:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-5-20250929"' >> ~/.zshrc
For BASH users (Linux)
Opus 4.7:
echo 'export ANTHROPIC_MODEL="claude-opus-4-7"' >> ~/.bashrc
Sonnet 4.6:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-6"' >> ~/.bashrc
Opus 4.6:
echo 'export ANTHROPIC_MODEL="claude-opus-4-6"' >> ~/.bashrc
Opus 4.5:
echo 'export ANTHROPIC_MODEL="claude-opus-4-5-20251101"' >> ~/.bashrc
Haiku 4.5:
echo 'export ANTHROPIC_MODEL="claude-haiku-4-5-20251001"' >> ~/.bashrc
Sonnet 4.5:
echo 'export ANTHROPIC_MODEL="claude-sonnet-4-5-20250929"' >> ~/.bashrc
Step 3) Apply the changes:
For ZSH:
source ~/.zshrc
For BASH:
source ~/.bashrc
Step 4) Close Terminal completely, then reopen it.
Step 5) Start Claude Code in a fresh Terminal session: claude
.
Now your chosen model will be the default for all future Claude Code sessions.
▸ 展开全文
04-28 07:59 · 数据泄露,AI安全,供应链风险,语音数据,合规审查
4TB of voice samples just stolen from 40k AI contractors at Mercor
4TB of voice samples were just stolen from 40,000 AI contractors. Here is how to verify if yours is being weaponized.
On April 4, 2026, the extortion group Lapsus$ posted Mercor on its leak site. The dump is reported at roughly four terabytes and bundles a payload that breach analysts have been warning about for two years: voice biometrics paired with the same person's government-issued identity document. According to the leaked sample index, the archive covers more than 40,000 contractors who signed up to label data, record reading passages, and run through verification calls for AI training.
Why this breach is different
Most voice leaks in the last decade fell into one of two buckets. Either a call center got popped and recordings were stolen with no easy way to map them back to identity. Or an ID-document broker leaked driver's licenses and selfies without any audio attached. Mercor merged both columns. The contractor onboarding pipeline asked for a passport or driver's license scan, then a webcam selfie, then a sit-down voice recording reading scripted prompts in a quiet room. That sequence, in one row of one database, is exactly what a synthetic voice cloning service needs as input.
The Wall Street Journal reported in February 2026 that high-quality voice cloning now requires roughly fifteen seconds of clean reference audio for tools available off the shelf. The Mercor recordings are reported to average two to five minutes of studio-clean speech per contractor. That is far past the threshold. Pair it with a verified ID document and the attacker has both the clone and the credential needed to put the clone to work.
What attackers can now do with stolen voice data
The threat models below are not speculative. Each is a documented technique already used in the wild before this breach.
- Bank verification bypass. Several US and UK banks still treat voiceprint matching as one of two factors. A clone of the account holder reading a challenge phrase clears the audio gate, leaving only a knowledge question that often comes from the same leaked dataset.
- Vishing the victim's employer. Calling HR or finance pretending to be the employee to redirect payroll, request a wire, or unlock a workstation. The Krebs on Security archive lists more than two dozen confirmed cases since 2023.
- Deepfake video calls in the Hong Kong Arup template. In 2024 a finance worker at Arup wired roughly 25 million dollars after a multi-person deepfake video call. The voices and faces had been built from public footage. Mercor leaked something better than public footage: studio audio plus a verified ID.
- Insurance claim fraud. Pindrop reported a 475 percent year-over-year increase in synthetic voice attacks against insurance call centers across 2025. Auto, life, and disability claims are the prime targets because they are settled by phone.
- Romance and grandparent scams targeting family members. The FBI Internet Crime Complaint Center logged 2.3 billion dollars in losses for victims aged 60 and over in calendar year 2026. The single fastest-growing category was emergency impersonation calls, where the synthetic voice claims to be a relative in trouble.
How to check if your voice is being misused
If you ever uploaded a voice sample to Mercor, or to any of the other AI training brokers that operated through 2025, treat your voice the way you would treat a leaked password. You cannot rotate it, but you can change what it unlocks. Here is the short list.
- Self-audit your public audio footprint. Search YouTube, podcast directories, and old Zoom recordings for samples of your voice that are publicly indexable. Take down what you can. The less reference audio is in the open, the less robust an attacker's clone.
- Set up a verbal codeword with family and finance contacts. Pick a phrase that has never been spoken on a recording and never typed in chat. Brief the people who handle money on your behalf. If a call ever asks for a transfer, the codeword is mandatory.
- Rotate where voiceprints are still in use. Google Voice Match, Amazon Alexa Voice ID, Apple personal voice, and any banking voiceprint enrollment can be deleted and replaced. Do that now, ideally from a new recording in a different acoustic environment than the leaked sample.
- Tell your bank to disable voiceprint as a verification factor. Ask in writing for multi-factor authentication that combines an app token or hardware key with a knowledge factor. Many banks let you opt out of voice as a primary factor; few of them advertise it.
- Run suspicious recordings through a forensic scanner. If you receive an audio file or voicemail that claims to be from someone you know and asks for money, access, or urgency, run it through a deepfake detector before acting. ORAVYS offers a free check for the first three samples submitted by breach victims (see the offer below).
The forensic checklist that experts use
When a sample lands on a forensic analyst's desk, the following artifacts are the
▸ 展开全文
04-28 07:57 · 开源停止维护,数据库备份,供应链风险,运维工具,PostgreSQL
Pgbackrest is no longer being maintained
TL;DR: pgBackRest is no longer being maintained. If you fork pgBackRest, please select a new name for your project.
After a lot of thought, I have decided to stop working on pgBackRest. I did not come to this decision lightly. pgBackRest has been my passion project for the last thirteen years, and I was fortunate to have corporate sponsorship for much of this time, but there were also many late nights and weekends as I worked to make pgBackRest the project it is today, aided by numerous contributors. Every open-source developer knows exactly what I mean and how much of your life gets devoted to a special project.
Since Crunchy Data was sold, I have been maintaining pgBackRest and looking for a position that would allow me to continue the work, but so far I have not been successful. Likewise, my efforts to secure sponsorship have also fallen far short of what I need to make the project viable.
Like everyone else, I need to make a living, and the range of pgBackRest-related roles is very limited. I can now consider a wider variety of opportunities, but those will not leave me time to work on pgBackRest, which requires a fair amount of time for maintenance, bug fixes, PR reviews, answering issues, etc. That does not even include time to write new features, which is what I really love to do. Rather than do the work poorly and/or sporadically, I think it makes more sense to have a hard stop.
I imagine at some point pgBackRest will be forked, but that will be a new project with new maintainers, and they will need to build trust the same way we did.
Again, many thanks to all the pgBackRest contributors over the years. It was a pleasure working with you!
pgBackRest is a reliable backup and restore solution for PostgreSQL that seamlessly scales up to the largest databases and workloads.
pgBackRest v2.58.0 is the current stable release. Release notes are on the Releases page.
Compression is usually the bottleneck during backup operations so pgBackRest solves this problem with parallel processing and more efficient compression algorithms such as lz4 and zstd.
A custom protocol allows pgBackRest to backup, restore, and archive locally or remotely via TLS/SSH with minimal configuration. An interface to query PostgreSQL is also provided via the protocol layer so that remote access to PostgreSQL is never required, which enhances security.
Multiple repositories allow, for example, a local repository with minimal retention for fast restores and a remote repository with a longer retention for redundancy and access across the enterprise.
Full, differential, and incremental backups are supported. pgBackRest is not susceptible to the time resolution issues of rsync, making differential and incremental backups safe without the requirement to checksum each file. Block-level backups save space by only copying the parts of files that have changed.
Retention polices can be set for full and differential backups to create coverage for any time frame. The WAL archive can be maintained for all backups or strictly for the most recent backups. In the latter case WAL required to make older backups consistent will be maintained in the archive.
Checksums are calculated for every file in the backup and rechecked during a restore or verify. After a backup finishes copying files, it waits until every WAL segment required to make the backup consistent reaches the repository.
Backups in the repository may be stored in the same format as a standard PostgreSQL cluster (including tablespaces). If compression is disabled and hard links are enabled it is possible to snapshot a backup in the repository and bring up a PostgreSQL cluster directly on the snapshot. This is advantageous for terabyte-scale databases that are time consuming to restore in the traditional way.
All operations utilize file and directory level fsync to ensure durability.
If page checksums are enabled pgBackRest will validate the checksums for every file that is copied during a backup. All page checksums are validated during a full backup and checksums in files that have changed are validated during differential and incremental backups.
Validation failures do not stop the backup process, but warnings with details of exactly which pages have failed validation are output to the console and file log.
This feature allows page-level corruption to be detected early, before backups that contain valid copies of the data have expired.
An interrupted backup can be resumed from the point where it was stopped. Files that were already copied are compared with the checksums in the manifest to ensure integrity. Since this operation can take place entirely on the repository host, it reduces load on the PostgreSQL host and saves time since checksum calculation is faster than compressing and retransmitting data.
Compression and checksum calculations are performed in stream while files are being copied to the repository, whether the repository is located locally or remotely.
If the repository is on a
▸ 展开全文
04-28 07:56 · 历史趣闻,非技术内容,无关联
Magic by return of post: How mail order delivered the occult
What allowed occultism to blossom in the United States at the turn of the 20th century? Linotype machines, cheap pulp paper, and newly improved postal networks. Allan Johnson investigates the forgotten history and (still living) world of mail-order magic.
April 22, 2026
In the early twentieth century, after the rationalising forces of the Enlightenment had supposedly recast spiritual life through reason, curious advertisements began to appear in popular periodicals ranging from Popular Mechanics to Weird Tales, offering arcane occult knowledge sent directly to the reader’s door. Typical of their genre, a 1902 notice in the Chicago Tribune introduced the De Laurence Institute of Hypnotism, which promised to “[unfold] the mysterious law of all personal magnetism, occult force, and influence”, while, elsewhere, the Occult Digest announced the services of the Los Angeles–based Brotherhood of Light, who had on offer “correspondence courses in all branches of occult science” by return of post.1 Sending away for the secrets of the ages was, it seemed, disarmingly simple, part and parcel of the colossal mail-order industry that had emerged during the Second Industrial Revolution of the late-nineteenth and early twentieth centuries.
The rise of mail-order magic was, in many ways, both an upshot and a parody of modernity. America’s long nineteenth century had already seen its fair share of religious transformation, with movements like Mormonism, Seventh-day Adventism, Christian Science, and the Shakers, among others, emerging from the spiritual fervour of the Second Great Awakening, each grappling in their own way with the relationship between the individual and society at large. In 1917, German sociologist Max Weber famously argued that “the fate of our times is characterized by rationalization and intellectualization and, above all, by the ‘disenchantment of the world’”.2 To Weber’s mind, the progress of the modern world had eradicated the need for spiritual practice, with the purposes it had once held now being carried by the cold logics of bureaucracy, science, and instrumental reason. From the vantage point of hindsight, however, Weber’s Entzauberung thesis seems less terminal than he had imagined.
In a time increasingly shaped by Taylorist factories and scientific materialism, Weber ultimately misread modernity, and his account of disenchantment confused modernity’s growing spiritual liberalism with large-scale secularisation. That is, Weber believed that the declining adherence to Christianity (which was unmistakable) signalled that the numinous had faded from modern life (which couldn’t have been further from the truth). Modernity and scientific materialism didn’t really get rid of spiritual practice as much as abstract it from an inherited, communal framework. What modernity had in fact created was a radical redistribution of belief, in which the rationalist currents presumed to have extinguished faith in powers and presences beyond oneself became the very means by which one could learn about these otherworldly forces from the privacy of one’s own home.
The new material conditions of postal exchange — linotype machines, cheap pulp paper, and rapidly improving and expanding delivery networks — made the recondite world of the occult ultra-targeted and at a scale never before seen. The consumer now got to choose if they wanted to practice meditation, astrology, tarot, Mesmerism, Kabbalah, Rosicrucianism, something even more arcane, or a unique combination of them all. There was no fixed template for how the instruction unfolded, but most would-be adherents began their affiliation by responding to the offer of a free sample lesson or catalogue from a magazine ad. From there, they could subscribe to courses whose scale, duration, and cost varied greatly. To give just a single example, lessons from Psychiana, one of the largest esoteric correspondence schools of the 1930s by subscriber numbers, cost around $1 each (about $20 in today’s currency) and were purchased in groups of ten or twenty lessons, with one lesson posted weekly. For students of Psychiana, as well as those who sent away to the many other smaller providers, completion of these introductory sequences usually then opened onto further tiers of instruction or advanced courses, with payment typically remitted in cash, sometimes in instalments or in arrears.
One of mail-order magic’s early innovators was Sydney Flower, the shadowy Chicago-based publisher behind The Hypnotic Magazine, The Yogi, and New Thought (the latter co-edited with William Walker Atkinson, best known as the presumed author of 1908’s Kybalion), as well as a startling range of orderable courses, through his Psychic Research Company and Magnetic Publishing Company, with titles such as A Course of Instruction in Magnetic Healing in Five Parts and A Course of Instruction in the Development of Power through Clairvoyance.
Flower emerges with almost no trace of a past, but by the time he arr
▸ 展开全文
04-22 08:02 · AI安全,开源工具,代理监控,生产部署,大模型应用
CrabTrap: An LLM-as-a-judge HTTP proxy to secure agents in production
Brex LLC is a wholly owned subsidiary of Capital One, N.A.
Brex LLC | 650 S 500W Suite 300 | Salt Lake City, UT 84101
The Brex business account consists of Checking, a commercial checking account provided by Column N.A., Member FDIC (an unaffiliated institution), and Treasury and Vault, cash management services provided by Brex Treasury LLC, Member FINRA/SIPC and a Capital One company.
Securities are offered through Brex Treasury LLC. Funds in Treasury are not FDIC-insured. Funds in Vault at program banks are eligible for FDIC insurance. Funds are not FDIC-insured until they arrive at program banks. Conditions apply.
Investing in securities involves risk and loss of money. Yield and return are variable and fluctuate. Past performance is not a guarantee of future results. This is not an offer to, or implied offer, or a solicitation to, buy or sell any securities. Brex Treasury LLC does not provide legal, tax, or investment advice. The latest statement of financial condition for Brex Treasury LLC is available here. You could lose money by investing in the Fund. Although the Fund seeks to preserve the value of your investment at $1.00 per share, it cannot guarantee it will do so. An investment in the Fund is not insured or guaranteed by the FDIC or any other government agency.
The Brex Mastercard® Corporate Credit Card is issued by Emigrant Bank, Fifth Third Bank N.A., or Airwallex (Netherlands) B.V. (all unaffiliated institutions), pursuant to licenses by Mastercard International Inc. Mastercard is a registered trademark, and the circles design is a trademark of Mastercard International Inc. The Brex Commercial Card is issued by Sutton Bank (an unaffiliated institution), pursuant to a license from Visa® U.S.A. Inc. Can be used where Visa® cards are accepted. No ATM access. All loans are subject to approval, including underwriting, credit, and collateral approval, as well as availability restrictions. Nothing herein should be construed as a commitment to lend.
Certain payment services are provided by Brex Payments LLC, a licensed money transmitter (NMLS #2035354) and a Capital One company.
Some Brex products have associated fees. Plans start at $0 per user, per month, and more advanced features are available for $12 per user, per month.
▸ 展开全文
04-22 08:01 · AI代理,技术竞争,人才招聘,初创企业,自动化
Trellis AI (YC W24) Is hiring engineers to build self-improving agents
Trellis builds and deploys computer use agents to get patients access to life-saving medicine.
Our computer-use AI agents process billions of dollars worth of therapies annually with patients in all fifty states. We do this by automating document intake, prior authorizations, and appeals at scale to streamline operations and accelerate care. We classify medical referrals, understand chart notes, and automate contract and reimbursement search to provide patients with accurate coverage determinations and cost responsibility. Think of us as the Stripe of healthcare billing and reimbursements.
Trellis is a spinout from Stanford AI Lab and is backed by leading investors including YC, General Catalyst, Telesoft Partners, and executives at Google and Salesforce.
🧍🏻♂️Why work with us
- Real impact at massive scale: We serve patients in all fifty states and are scaling to hundreds of healthcare locations. You'll directly see the number of patients who received treatment because of the agents you built.
- Work with industry experts: Apply your AI alongside healthcare operations leaders who have overseen 50+ healthcare locations, gaining deep domain expertise while building cutting-edge technology.
- Be at the forefront of AI in healthcare: Build production-grade agentic systems that make critical healthcare decisions, backed by robust evaluation frameworks.
- Direct customer engagement: Work closely with F500 customers and the founding team. You'll wear multiple hats from technical architecture to customer success.
- Extreme ownership: Own key parts of Trellis's technical infrastructure and have opportunities to launch new initiatives that process billions in healthcare transactions.
- World-class team: Join team members who have won international physics olympiads, published economics research, were founding engineers at unicorn startups, and taught AI classes to hundreds of Stanford graduate students.
- Incredible growth and traction: We've grown revenue 10x in the past few months alone and have XX% market share in the specialty healthcare markets we serve.
What you'll build
- Agentic frameworks for healthcare decision-making: Design and implement AI systems that autonomously navigate complex reimbursement logic and prior authorization workflows.
- 24/7 AI co-workers: Build and deploy long-running agent workers that triage and process healthcare data around the clock, functioning as reliable digital teammates for care teams.
- Production-grade AI systems: Develop your agents within our comprehensive evaluation suite, ensuring production-ready performance from day one.
Requirements
- Experience architecting, developing, and testing full-stack code end-to-end
- Expertise in programming languages such as Python, Go and ML/NLP libraries such as PyTorch, TensorFlow, Transformers
- Being proactive and a fast-learner with bias for action
- Experience working with relational and non-relational databases, especially Postgres
- Experience with data and ML infrastructure
- Open source contributions and projects are a big plus
- Experience with cloud platforms (e.g., AWS, Azure, GCP) and containerization technologies (e.g., Docker, Kubernetes) is a plus
Trellis helps healthcare providers treat more patients, faster—while eliminating pre-service paperwork.
We automate document intake, prior authorizations, and appeals at scale to streamline operations and accelerate care.
Our AI agent is trained on millions of clinical data points and converts messy, unstructured documents into clean, structured data directly in your EHR.
With Trellis, leading healthcare providers and pharmaceutical companies were able to:
-
Reduce time to treatment by over 90%
-
Improve prior authorization approval and reimbursement rates
-
Leverage structured data to enhance drug program performance and clinical decision-making
Administrative costs account for over 20% of U.S. healthcare spending—delaying care, draining revenue, and driving staff burnout while having less visibility into patient care than ever before. We built Trellis to tackle this head on.
▸ 展开全文
04-22 08:00 · 开源,AI基础设施,技术竞争,开发者工具,模型路由
Show HN: GoModel – an open-source AI gateway in Go
A high-performance AI gateway written in Go, providing a unified OpenAI-compatible API for OpenAI, Anthropic, Gemini, xAI, Groq, OpenRouter, Z.ai, Azure OpenAI, Oracle, Ollama, and more.
Step 1: Start GoModel
docker run --rm -p 8080:8080 \
-e LOGGING_ENABLED=true \
-e LOGGING_LOG_BODIES=true \
-e LOG_FORMAT=text \
-e LOGGING_LOG_HEADERS=true \
-e OPENAI_API_KEY="your-openai-key" \
enterpilot/gomodel
Pass only the provider credentials or base URL you need (at least one required):
docker run --rm -p 8080:8080 \
-e OPENAI_API_KEY="your-openai-key" \
-e ANTHROPIC_API_KEY="your-anthropic-key" \
-e GEMINI_API_KEY="your-gemini-key" \
-e GROQ_API_KEY="your-groq-key" \
-e OPENROUTER_API_KEY="your-openrouter-key" \
-e ZAI_API_KEY="your-zai-key" \
-e XAI_API_KEY="your-xai-key" \
-e AZURE_API_KEY="your-azure-key" \
-e AZURE_BASE_URL="https://your-resource.openai.azure.com/openai/deployments/your-deployment" \
-e AZURE_API_VERSION="2024-10-21" \
-e ORACLE_API_KEY="your-oracle-key" \
-e ORACLE_BASE_URL="https://inference.generativeai.us-chicago-1.oci.oraclecloud.com/20231130/actions/v1" \
-e ORACLE_MODELS="openai.gpt-oss-120b,xai.grok-3" \
-e OLLAMA_BASE_URL="http://host.docker.internal:11434/v1" \
enterpilot/gomodel
-e
on the command line - they can leak via shell history and process lists. For production, use docker run --env-file .env
to load API keys from a file instead.
Step 2: Make your first API call
curl http://localhost:8080/v1/chat/completions \
-H "Content-Type: application/json" \
-d '{
"model": "gpt-5-chat-latest",
"messages": [{"role": "user", "content": "Hello!"}]
}'
That's it! GoModel automatically detects which providers are available based on the credentials you supply.
Example model identifiers are illustrative and subject to change; consult provider catalogs for current models. Feature columns reflect gateway API support, not every individual model capability exposed by an upstream provider.
✅ Supported ❌ Unsupported
For Z.ai's GLM Coding Plan, set ZAI_BASE_URL=https://api.z.ai/api/coding/paas/v4
.
For Oracle, set ORACLE_MODELS=openai.gpt-oss-120b,xai.grok-3
when the
upstream /models
endpoint is unavailable.
Prerequisites: Go 1.26.2+
-
Create a
.env
file:cp .env.template .env
-
Add your API keys to
.env
(at least one required). -
Start the server:
make run
Infrastructure only (Redis, PostgreSQL, MongoDB, Adminer - no image build):
docker compose up -d
# or: make infra
Full stack (adds GoModel + Prometheus; builds the app image):
cp .env.template .env
# Add your API keys to .env
docker compose --profile app up -d
# or: make image
docker build -t gomodel .
docker run --rm -p 8080:8080 --env-file .env gomodel
GoModel is configured through environment variables and an optional config.yaml
. Environment variables override YAML values. See .env.template
and config/config.example.yaml
for the available options.
Key settings:
Quick Start - Authentication: By default GOMODEL_MASTER_KEY
is unset. Without this key, API endpoints are unprotected and anyone can call them. This is insecure for production. Strongly recommend setting a strong secret before exposing the service. Add GOMODEL_MASTER_KEY
to your .env
or environment for production deployments.
GoModel has a two-layer response cache that reduces LLM API costs and latency for repeated or semantically similar requests.
Hashes the full request body (path + Workflow
+ body) and returns a stored response on byte-identical requests. Sub-millisecond lookup. Activate by environment variables: RESPONSE_CACHE_SIMPLE_ENABLED
and REDIS_URL
.
Responses served from this layer carry X-Cache: HIT (exact)
.
Embeds the last user message via your configured provider’s OpenAI-compatible /v1/embeddings
API (cache.response.semantic.embedder.provider
must name a key in the top-level providers
map) and performs a KNN vector search. Semantically equivalent queries - e.g. "What's the capital of France?" vs "Which city is France's capital?" - can return the same cached response without an upstream LLM call.
Expected hit rates: ~60–70% in high-repetition workloads vs. ~18% for exact-match alone.
Responses served from this layer carry X-Cache: HIT (semantic)
.
Supported vector backends: qdrant
, pgvector
, pinecone
, weaviate
(set cache.response.semantic.vector_store.type
and the matching nested block).
Both cache layers run after guardrail/workflow patching so they always see the final prompt. Use Cache-Control: no-cache
or Cache-Control: no-store
to bypass caching per-request.
See DEVELOPMENT.md for testing, linting, and pre-commit setup.
- Intelligent routing
- Broader provider support: Oracle model configuration via environment variables, plus Cohere, Command A, Operational, and DeepSeek V3
- Budget management with limits per
user_path
and/or API key - Editable model pricing for accurate cost tracking and budgeting
- Full support for the OpenAI
/responses
and/conversations
lifecycle - Prompt cache visibility showing how much of each prompt was cached by the provider
- Guardrails h
▸ 展开全文
04-20 08:00 · 航天,技术故障,硬件,行业动态,火箭回收
Blue Origin's rocket reuse achievement marred by upper stage failure
The third flight of Blue Origin’s heavy-lift New Glenn launcher began Sunday with the company’s first successful reflight of an orbital-class booster, but ended with a setback for Jeff Bezos’ flagship rocket, a key element in NASA’s Artemis lunar program.
The 321-foot-tall (98-meter) New Glenn launch vehicle ignited its seven methane-fueled BE-4 engines at 7:25 am EDT (11:25 UTC) Sunday, beginning a slow climb from its launch pad at Cape Canaveral Space Force Station, Florida.
The main engines, each producing more than a half-million pounds of thrust, accelerated the rocket past the speed of sound in about a minute-and-a-half. Three minutes into the flight, the booster switched off its engines and fell away from New Glenn’s upper stage, powered by two BE-3U engines burning liquid hydrogen and liquid oxygen.
New Glenn’s first stage continued a downrange parabolic arc, briefly soaring into space before guiding itself toward Blue Origin’s landing platform in the Atlantic Ocean nearly 400 miles southeast of Cape Canaveral. Reigniting its engines for two braking burns, the booster settled onto the ship for a smoky but on-target touchdown less than 10 minutes after liftoff.
The landing marked the end of the second flight for this booster, named Never Tell Me The Odds, after debuting with a good launch and recovery on Blue Origin’s previous New Glenn mission in November. Blue Origin, founded and owned by Amazon’s Jeff Bezos, has landed and reused its smaller New Shepard suborbital booster numerous times, but New Glenn surpasses New Shepard in difficulty and scale. It flies higher, travels faster, and is three times the height of the New Shepard.
Technicians installed new engines on the booster for Sunday’s flight, but the Blue Origin intends to reuse the engines from the November launch on future New Glenn missions, according to Dave Limp, the company’s CEO.
New Glenn allows Blue Origin to reach into a broader market for launches to low-Earth orbit and beyond. SpaceX has shown it can recycle a Falcon 9 booster for reflight in just nine days, and launch Falcon 9s five or more times in one week using a fleet of reusable boosters and three active launch pads. Blue Origin officials expect reusing New Glenn boosters will unlock a vastly faster launch rate for themselves.
▸ 展开全文
04-20 07:58 · 政府IT,数据公开,公共服务,欧洲市场,邮箱服务
2,100 Swiss municipalities showing which provider handles their official email
A map of all ~2,100 Swiss municipalities showing which provider handles their official email — grouped by jurisdiction — based on public DNS records and other public network signals.
Digital sovereignty: US-based providers are subject to the US CLOUD Act, which allows US authorities to request stored data, regardless of where it is physically hosted. This map makes the current provider landscape visible.
Each municipality's official domain is checked via 11 signals from DNS records, SMTP banners, ASN lookups, and a public Microsoft API endpoint, then classified by provider type with confidence scoring.
Disclaimer: DNS records indicate mail routing and authorized senders, not necessarily where data is stored.
▸ 展开全文