Skip to content

LiteLLMUser ​

Creates a user in LiteLLM for non-SSO environments. Useful for service accounts, bot users, and environments without an Identity Provider.

API Version: litellm.palena.ai/v1alpha1Kind: LiteLLMUserShort Name: lu

Example ​

yaml
apiVersion: litellm.palena.ai/v1alpha1
kind: LiteLLMUser
metadata:
  name: service-bot
spec:
  instanceRef:
    name: my-gateway
  userId: service-bot@example.com
  userEmail: service-bot@example.com
  userRole: internal_user
  maxBudget: 500
  budgetDuration: "30d"
  models:
    - gpt-4o
  teams:
    - teamRef:
        name: engineering
      role: user

Spec Fields ​

FieldTypeRequiredDefaultDescription
instanceRefInstanceRefYes—Reference to the LiteLLMInstance
userIdstringYes—Unique user identifier (typically email)
userEmailstringNo—User email address
userRolestringNointernal_userUser role (see below)
maxBudget*float64No—Maximum budget in USD
budgetDurationstringNo—Budget reset period (e.g., 30d)
models[]stringNo—Models this user can access
teams[]UserTeamMembershipNo—Team memberships
tpmLimit*intNo—Tokens per minute limit
rpmLimit*intNo—Requests per minute limit
metadatamap[string]stringNo—Custom metadata
blocked*boolNo—Disable all requests from this user without deleting it
softBudget*float64No—Alert threshold in USD below maxBudget (does not block)
modelRpmLimitmap[string]intNo—Per-model requests-per-minute caps (model name → RPM)
modelTpmLimitmap[string]intNo—Per-model tokens-per-minute caps (model name → TPM)
objectPermission*ObjectPermissionNo—Grant access to MCP servers, vector stores, agents, access groups

User Roles ​

RoleDescription
proxy_adminFull admin access to all LiteLLM features
proxy_admin_viewerRead-only admin access
internal_userStandard user with scoped access
internal_user_viewerRead-only standard user

teams[] ​

FieldTypeDescription
teamRef*InstanceRefReference to a LiteLLMTeam CR
teamIdstringDirect team ID (for teams not managed by a CRD)
rolestringRole within the team (default: user)
maxBudgetInTeam*float64Max budget within this team

You can use either teamRef (references a LiteLLMTeam CR by name) or teamId (direct LiteLLM team ID). The operator resolves teamRef to the team's status.litellmTeamId.

Status Fields ​

FieldTypeDescription
syncedboolWhether the user is synced to LiteLLM
litellmUserIdstringLiteLLM-assigned user ID
currentSpend*float64Current spend in USD
resolvedTeams[]ResolvedTeamMembershipResolved team memberships
lastSyncTime*TimeLast successful sync time
conditions[]ConditionStandard conditions
bash
kubectl get lu
NAME          USERID                     ROLE            SYNCED   AGE
service-bot   service-bot@example.com    internal_user   true     1d

When to Use LiteLLMUser ​

  • Service accounts for CI/CD pipelines
  • Bot users that need API access
  • Non-SSO environments where you manage users declaratively
  • GitOps user management alongside SSO for specific accounts

When SSO/SCIM handles user provisioning, LiteLLMUser CRDs are typically not needed for human users.

Released under the Apache 2.0 License.