reduce usage of newt

This commit is contained in:
miloschwartz
2026-09-08 16:05:17 -04:00
parent ae5f1ed60f
commit 40feb4d220
5 changed files with 18 additions and 16 deletions
+2 -2
View File
@@ -9,7 +9,7 @@ This page covers how the **resource** works: reachability, access, and what you
## How It Works
1. You create a private resource with type **AI Gateway** on a Newt site and attach one or more org-level [providers](/manage/ai/providers/overview).
1. You create a private resource with type **AI Gateway** on a Pangolin Site and attach one or more org-level [providers](/manage/ai/providers/overview).
2. You grant [users, roles, or machines](/manage/resources/private/authentication) access, the same as any other private resource.
3. The user connects with the Pangolin client. The machine running the AI client must be on that tunnel.
4. The agent calls the resource URL. Pangolin attributes the call to the connected user and proxies to the selected provider.
@@ -20,7 +20,7 @@ Clients still need a value in the API key field. Use the literal string `none`.
Private AI Gateway resources attach providers on the resource's **AI Gateway** tab. They do not use a host or CIDR [destination](/manage/resources/private/destinations) as the model backend. Cloud APIs are called from Pangolin. [Custom](/manage/ai/providers/custom) providers can use **Site Targets** when the model server is on a site network.
Private resources, including this type, can only be created on [Newt sites](/manage/sites/understanding-sites#newt-site-recommended).
Private resources, including this type, can only be created on [Pangolin Sites](/manage/sites/understanding-sites#pangolin-site-recommended).
## Authentication and Access Rules
+5 -5
View File
@@ -35,7 +35,7 @@ HTTP/HTTPS, SSH, RDP, and VNC are all **browser-based**. You assign a fully qual
[AI Gateway](/manage/resources/public/ai-gateway) also gets a public FQDN, but coding agents call it as an API. Visiting the URL in a browser is how users retrieve a virtual API key, not how they run the workload.
SSH, RDP, and VNC require a **Newt site**. HTTP/HTTPS, AI Gateway, and TCP/UDP resources can also run on local and basic WireGuard sites.
SSH, RDP, and VNC require a **Pangolin Site**. HTTP/HTTPS, AI Gateway, and TCP/UDP resources can also run on local and basic WireGuard sites.
TCP and UDP are the exception. They do not receive a FQDN. Instead, they bind to a port on the Pangolin server host and act as simple protocol-agnostic pipes to the downstream resource. Because they are not protocol-aware, they do not enforce Pangolin authentication or access rules.
@@ -72,7 +72,7 @@ TCP and UDP are the exception. They do not receive a FQDN. Instead, they bind to
#### Site Compatibility
<CardGroup cols={3}>
<Card title="Newt Site" icon="plug" href="/manage/sites/understanding-sites#newt-site-recommended">
<Card title="Pangolin Site" icon="plug" href="/manage/sites/understanding-sites#pangolin-site-recommended">
All public resource types supported.
Required for SSH, RDP, and VNC.
@@ -117,7 +117,7 @@ Private resources require users to connect with the Pangolin client before any t
</Card>
</CardGroup>
Private resources can only be created on Newt sites.
Private resources can only be created on Pangolin Sites.
**Private resources function like a zero-trust virtual private network (VPN).** Explicit access to resources must be granted for users and roles to be able to access them. For raw TCP/UDP traffic that does not need a public proxy, prefer a private host or CIDR resource over public TCP/UDP resources.
@@ -126,10 +126,10 @@ Private resources support [aliases](/manage/resources/private/alias) for human-r
#### Site Compatibility
<CardGroup cols={3}>
<Card title="Newt Site" icon="plug" href="/manage/sites/understanding-sites#newt-site-recommended">
<Card title="Pangolin Site" icon="plug" href="/manage/sites/understanding-sites#pangolin-site-recommended">
Supported.
Private resources require a Newt site.
Private resources require a Pangolin Site.
</Card>
<Card title="Local Site" icon="server" href="/manage/sites/understanding-sites#local-site">