NVIDIA / NVIDIA/Personal-AI-Router

[Feature]: Allow authenticated opt-in LAN access to local compatibility endpoints

Offen
#28 7 Kommentare 0 Reaktionen 1 zugewiesene Person Auf GitHub ansehen

@sherief-nv arbeitet bereits daran.

Seit 09.9.2026.

Vorherrschende Sprache
Go
Sterne
1.4k
Forks
250
Ø Merge
23 Std. 27 Min.
Gemergte PRs (30 T.)
1

Beschreibung

Feature request

Please provide a supported, explicit opt-in way to expose PAIR's OpenAI-compatible local endpoint to trusted LAN clients.

Current behavior

PAIR 0.91.7 on Windows 11 binds the LM Studio-compatible proxy on port 1234, but rejects a request arriving through an established firewall/NAT path:

{"code":"loopback-only","error":"plaintext requests are accepted only from loopback; cluster peers must use the mTLS ingress"}

Changing the proxy port preserves the port number but does not change this policy.

Use case

A dedicated Windows GPU workstation already serves:

  • automation clients on another workstation;
  • Kubernetes workloads;
  • an existing firewall-restricted tunnel/NAT endpoint;
  • standard OpenAI-compatible SDKs that cannot run PAIR themselves.

Installing and pairing PAIR inside every client, pod, or workload is substantially more operationally complex than exposing one authenticated endpoint.

Security expectations

I understand why unrestricted plaintext LAN exposure is disabled and am not asking for an insecure default. A secure opt-in mode could require some combination of:

  • an explicit bind address such as 0.0.0.0;
  • API-key authentication or client certificates;
  • source CIDR allowlisting;
  • a prominent warning when enabled.
Requested outcome

Provide a documented, supported mechanism for ordinary OpenAI-compatible clients on trusted networks to access a PAIR endpoint without running a PAIR node locally. The existing loopback-only behavior should remain the default.

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.