Public task
OpenAI provisioning for n1x
Add composable OpenAI runtime and Terraform provisioning capabilities to n1x.
Part of InfraBench ↗
- Model configurations
- 1
- Evaluation attempts
- 3
- Public examples
- 3
Current task results
Evaluation comparison
Published evaluation results for this task version. Each bar shows a model configuration’s average score.
| Model | Average score | Score range | Attempts |
|---|---|---|---|
| Muse Spark 1.3 Contributoropencode · opencode · 1.18.11 | 93.3%± 3.3 pp SE | 90.0% – 100.0% | 33 scored |
Averages and ranges use scored attempts on this exact version. Attempts without a score are counted separately. SE measures uncertainty across attempt scores.
The task
What the agent receives# Add first-class OpenAI API Platform support to n1x
Introduce an `openai` capability which, when composed with `infra`, declares the
official `openai/openai` Terraform provider at `~> 0.7.0`, creates an OpenAI
project named from `local.app_id`, creates a `${local.app_id}-runtime` service
account with the API project-member role, and exposes the project and service
account IDs as Terraform outputs. Terraform must not mint runtime API keys; it
authenticates with `OPENAI_ADMIN_KEY`.
Introduce a `web-openai` capability that requires `web` and `openai`, adds
`openai` `^7.0.0` to the generated web app, and makes the server-only
`OPENAI_API_KEY` part of the normal generated web environment workflow. When
`infra` is selected, pass the runtime key through the existing
`TF_VAR_web_secret_env_values` map. Never expose either credential through a
`NEXT_PUBLIC_*` variable.
Keep the capabilities composable:
- `web-openai` must work without `infra`.
- `openai` with `infra` must not introduce the web SDK or runtime key.
- Existing projects that select neither capability must not gain OpenAI output.
- Repeated apply operations must be idempotent.
- Removing the capabilities must clean up their managed Terraform, environment,
and guidance insertions according to n1x's existing lifecycle rules.
Document the operator workflow and credential boundary. After provisioning, an
operator creates a scoped runtime key through the OpenAI Admin API and supplies
it through `TF_VAR_web_secret_env_values`; the admin key is only for Terraform
and must never be used for model requests.
Update repository documentation, generated guidance, lint coverage, and smoke
coverage while preserving all existing behavior. Repository documentation
(`README.md` and `AGENTS.md` guidance templates) may be updated freely; every
other engine or capability source outside the disclosed `openai`, `web-openai`,
`web`, and `infra` seams must remain byte-for-byte unchanged.