namespace GB5Shared.ExternalAI { /// /// Per-module configuration for a link to the external Enterprise AI engine /// (AI-Enterprise-v1.0, a separate Python/FastAPI service — see /// FrameworkBLL.GOP.Worker.AI.AIExtractOptions for the original, GOP-specific version this /// generalizes). Each consuming module (EAIAdmin, KMS, ...) binds its own instance from its /// own config section (e.g. "EAIAdmin:AIExtract", "KMS:AIExtract") and passes it into /// per call — deliberately not resolved via generic /// IOptions<AIEngineOptions> DI, since multiple modules binding the same options TYPE to /// different sections inside one process (PlatformHost) would collide on the last registration /// won. See EAIAdmin/KmsAISyncClient for how each module resolves its own instance from /// IConfiguration directly. /// public class AIEngineOptions { public string EngineBaseUrl { get; set; } = "http://217.217.249.121:8006"; /// Vault path for the shared secret AI-Enterprise-v1.0 verifies tokens against. /// Owned by a separate, externally-operated system, not something GB5 issues or verifies — /// each module gets its own path so it can rotate independently even if the underlying /// secret value happens to be the same one the engine's operator provisioned. public string SigningKeyVaultPath { get; set; } = string.Empty; public string Issuer { get; set; } = string.Empty; public string Audience { get; set; } = "AI-Enterprise-v1.0"; /// Short-lived — minted fresh per call, never cached or reused. public int AccessTokenMinutes { get; set; } = 5; public int TimeoutSeconds { get; set; } = 120; } }