refactor(ssl): support per-service SSL verification overrides #19375
+394
−118
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.

Relevant issues
Addresses issue where a global
litellm.ssl_verifysetting (e.g., for AIM Guardrail) would incorrectly apply to Bedrock calls, causingSSLCertVerificationError. This PR enables per-service SSL configuration overrides.Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
tests/litellm/directory: Added tests/test_litellm/test_ssl_verify_unit.py covering priority logic for Bedrock, AIM, and HTTP clients.make test-unitType
🐛 Bug Fix
🧹 Refactoring
📖 Documentation
✅ Test
Changes
Problem:
Solution:
Passed Parameter>ENV: SSL_VERIFY>litellm.ssl_verify>ENV: SSL_CERT_FILE.security_settings.mdfor "Per-Service SSL Verification".aim_security.mdwith configuration examples.Test Cases Added
Identified in tests/test_litellm/test_ssl_verify_unit.py:
test_base_aws_llm_get_ssl_verify_priority: Verifies that passed params override global settings in Bedrock.test_aim_guardrail_ssl_verify_propagation: Confirms AIM guardrail passes the custom path to the HTTP client.test_http_handler_get_ssl_verify_logic: Validates the core logic for bools, strings, and env variable fallbacks.test_bedrock_llm_init_passes_ssl_verify: Ensures the Bedrock LLM class correctly passes the setting to the AWS handlers.