mirror of
https://github.com/coder/coder.git
synced 2026-09-22 05:05:20 +08:00
## Summary AI Governance is now included with Premium licenses instead of being sold as a separate per-user add-on. This updates `docs/` to describe the new packaging, removes "Add-On" from AI Governance references, and refreshes the editions architecture diagram. ## Changes - **`docs/ai-coder/ai-governance.md`**: title is now "AI Governance"; rewrote the licensing statements (previously "a separate, per-user license... not included with a Premium subscription and must be purchased separately") to state it is included with Premium. The usage-pool section now attributes the shared Agent Workspace Build pool to Premium deployments. - **Repeated admonition (28 files under `ai-coder/agent-firewall/` and `ai-coder/ai-gateway/`)**: replaced "requires the AI Governance Add-On / as of Coder v2.32, deployments without the add-on..." with "is part of AI Governance, which is included with a Premium license." The v2.32 add-on gate no longer applies; the gate is now Premium vs. Community. - **`docs/ai-coder/index.md`, `security.md`, `tasks.md`, `usage-data-reporting.md`, `admin/licensing/index.md`, `install/releases/esr-2.29-2.34-upgrade.md`, `ai-gateway/ai-gateway-proxy/setup.md`, `ai-gateway/clients/claude-code.md`**: reworded add-on references to Premium inclusion. - **`docs/manifest.json`**: nav title "AI Governance Add-On" → "AI Governance", updated two descriptions, and swapped the 25 `"state": ["ai governance add-on"]` badges to `["premium"]` so the sidebar badge reads "Premium" instead of "AI Governance Add-On". - **`docs/images/single-region-architecture.png`**: refreshed the diagram in the **Community and Premium editions** tab on [Architecture](https://coder.com/docs/admin/infrastructure/architecture). Also deleted the unreferenced `single-region-architecture.svg` copy. ## Follow-ups outside this PR - The `"ai governance add-on"` doc-state badge is defined in `coder/coder.com` (`src/utils/docs/state.ts`). After this merges, no manifest entry uses that key, so it becomes dead config and can be removed there. - `enterprise/coderd/license/license.go:564-572` still warns admins that "The AI Governance add-on is required to use AI Gateway." That backend string will contradict these docs once shipped. ## Verification - `pnpm run lint-docs`: 0 errors across 504 files - `make lint/emdash`: clean - Vale on the changed Markdown files: 0 errors; remaining warnings are pre-existing gerund headings on untouched lines - `docs/manifest.json` validated as JSON - Confirmed the deleted SVG had no references anywhere in the repo --- PR generated with Coder Agents on behalf of @mattvollmer.
37 lines
1.4 KiB
Markdown
37 lines
1.4 KiB
Markdown
> [!NOTE]
|
|
> Features mentioned on this page, such as AI Gateway and Agent Firewall,
|
|
> are part of [AI Governance](./ai-governance.md), which is included with a
|
|
> Premium license.
|
|
|
|
As the AI landscape is evolving, we are working to ensure Coder remains a secure
|
|
platform for running AI agents just as it is for other cloud development
|
|
environments.
|
|
|
|
## Use Trusted Models
|
|
|
|
Most agents can be configured to either use a local LLM (e.g. llama3), an agent
|
|
proxy (e.g. OpenRouter), or a Cloud-Provided LLM (e.g. AWS Bedrock). Research
|
|
which models you are comfortable with and configure your Coder templates to use
|
|
those.
|
|
|
|
## Set up Firewalls and Proxies
|
|
|
|
Many enterprises run Coder workspaces behind a firewall or a proxy to prevent
|
|
threats or bad actors. These same protections can be used to ensure AI agents do
|
|
not access or upload sensitive information.
|
|
|
|
## Separate API keys and scopes for agents
|
|
|
|
Many agents require API keys to access external services. It is recommended to
|
|
create a separate API key for your agent with the minimum permissions required.
|
|
This will likely involve editing your template for Agents to set different
|
|
scopes or tokens from the standard one.
|
|
|
|
Additional guidance and tooling is coming in future releases of Coder.
|
|
|
|
## Set Up Agent Firewall
|
|
|
|
Agent Firewall is a process-level firewall that lets you restrict and
|
|
audit what AI agents can access within Coder workspaces. To learn more about
|
|
this feature, see [Agent Firewall](./agent-firewall/index.md).
|