Documentation Infrastructure
INFRASTRUCTURE / TECHNICAL

Tunnels & access

Independent routes for production AI, deployment SSH, and the portal.

Hostnames

Hostname Purpose
ai.nutsnews.com Existing production AI API
localserver.ramideltoro.com Machine-authenticated deployment SSH
observe.ramideltoro.com Public portal and authenticated owner routes
localserver.wiki.ramideltoro.com Independent GitHub Pages wiki

SSH

The GitHub runner uses cloudflared as an SSH ProxyCommand. A dedicated Access service token authenticates the tunnel connection, and an SSH key authenticates to the host. Host-key verification remains enabled.

Owner routes

The Node backend protects /owner and /api/owner with a secure Google-authenticated owner session. Cloudflare Access must not intercept these portal paths. Public responses use a fixed allowlist and contain no raw operational logs.

ON THIS PAGE

THREE WAYS TO UNDERSTAND

Same system.
Your level of detail.

Switch reading modes above to find the explanation that fits.

Explore Expert →

Keep exploring

The local server

The host, its services, and how it is managed without reinstalling it.

Qwen & production workers

The compatibility contract that keeps NutsNews connected to local AI.