mirror of
https://github.com/coder/coder.git
synced 2026-09-24 15:04:27 +08:00
chore: Style fixes and nits across the AI Governance docs (#25793)
- Add the "AI Governance Add-On" label across all pages - Use a generic `coder.example.com` URL across examples - Fix a few typos - Remove mentions of command access as a feature of AI Gov Fixes DOCS-262 <!-- If you have used AI to produce some or all of this PR, please ensure you have read our [AI Contribution guidelines](https://coder.com/docs/about/contributing/AI_CONTRIBUTING) before submitting. --> --------- Co-authored-by: Danny Kopping <danny@coder.com>
This commit is contained in:
co-authored by
Danny Kopping
parent
ca337915cc
commit
61a9c4a61d
@@ -48,8 +48,8 @@ In your Terraform module, enable Agent Firewall with minimal configuration:
|
||||
|
||||
```tf
|
||||
module "claude-code" {
|
||||
source = "dev.registry.coder.com/coder/claude-code/coder"
|
||||
version = "4.7.0"
|
||||
source = "registry.coder.com/coder/claude-code/coder"
|
||||
version = "5.2.0"
|
||||
enable_boundary = true
|
||||
}
|
||||
```
|
||||
@@ -59,7 +59,7 @@ Claude Code module, use the following minimal configuration:
|
||||
|
||||
```yaml
|
||||
allowlist:
|
||||
- "domain=dev.coder.com" # Required - use your Coder deployment domain
|
||||
- "domain=coder.example.com" # Required - use your Coder deployment domain
|
||||
- "domain=api.anthropic.com" # Required - API endpoint for Claude
|
||||
- "domain=statsig.anthropic.com" # Required - Feature flags and analytics
|
||||
- "domain=claude.ai" # Recommended - WebFetch/WebSearch features
|
||||
@@ -225,5 +225,5 @@ such as Grafana Loki.
|
||||
Example of an allowed request (assuming stderr):
|
||||
|
||||
```console
|
||||
2026-01-16 00:11:40.564 [info] coderd.agentrpc: boundary_request owner=joe workspace_name=some-task-c88d agent_name=dev decision=allow workspace_id=f2bd4e9f-7e27-49fc-961e-be4d1c2aa987 http_method=GET http_url=https://dev.coder.com event_time=2026-01-16T00:11:39.388607657Z matched_rule=domain=dev.coder.com request_id=9f30d667-1fc9-47ba-b9e5-8eac46e0abef trace=478b2b45577307c4fd1bcfc64fad6ffb span=9ece4bc70c311edb
|
||||
2026-01-16 00:11:40.564 [info] coderd.agentrpc: boundary_request owner=joe workspace_name=some-task-c88d agent_name=dev decision=allow workspace_id=f2bd4e9f-7e27-49fc-961e-be4d1c2aa987 http_method=GET http_url=https://coder.example.com event_time=2026-01-16T00:11:39.388607657Z matched_rule=domain=coder.example.com request_id=9f30d667-1fc9-47ba-b9e5-8eac46e0abef trace=478b2b45577307c4fd1bcfc64fad6ffb span=9ece4bc70c311edb
|
||||
```
|
||||
|
||||
@@ -51,12 +51,10 @@ being used across the organization. AI Gateway provides audit trails of prompts,
|
||||
token usage, and tool invocations, giving administrators insight into AI
|
||||
adoption patterns and potential issues.
|
||||
|
||||
### Restricting agent network and command access
|
||||
### Restricting agent network access
|
||||
|
||||
AI agents can make arbitrary network requests, potentially accessing
|
||||
unauthorized services or exfiltrating data. They can also execute destructive
|
||||
commands within a workspace. Agent Firewall enforces process-level policies
|
||||
that restrict which domains agents can reach and what actions they can perform,
|
||||
AI agents can make arbitrary network requests, potentially accessing unauthorized services or exfiltrating data.
|
||||
Agent Firewall enforces process-level policies that restrict which domains agents can reach and what actions they can perform,
|
||||
preventing unintended data exposure and destructive operations like `rm -rf`.
|
||||
|
||||
### Centralizing API key management
|
||||
|
||||
@@ -5,7 +5,7 @@ The [AI Governance Add-On](./ai-governance.md) requires reporting usage data to
|
||||
- number of agent workspace builds consumed
|
||||
- number of AI Governance seats consumed
|
||||
|
||||
No user-identifiable information or additional metrics are sent to Tallyman. This information is also shared with [Metronome](https://metronome.com), a Stripe product and Coder partner for usage-based and reporting.
|
||||
No user-identifiable information or additional metrics are sent to Tallyman. This information is also shared with [Metronome](https://metronome.com), a Stripe product and Coder partner for usage-based billing and reporting.
|
||||
|
||||
To send usage data, your Coder deployment must be able to make outbound HTTPS requests to `https://tallyman-prod.coder.com`. Usage data is sent approximately every 17 minutes and can be monitored via `coderd` logs.
|
||||
|
||||
@@ -17,7 +17,7 @@ Example of a successful request (requires debug logging enabled [`CODER_LOG_FILT
|
||||
|
||||
Example of a request payload:
|
||||
|
||||
```sh
|
||||
```txt
|
||||
POST /api/v1/events/ingest HTTP/1.1
|
||||
Host: tallyman-prod.coder.com
|
||||
Content-Type: application/json
|
||||
|
||||
Reference in New Issue
Block a user