What the basic UI configures#

The AI Platform connection form creates public-egress connections with an internal data classification. It exposes provider, protocol, endpoint, credential and descriptive location metadata. This form is not a complete editor for every advanced routing or classification field in the backend.

See the illustrated AI platform setup guide for the provider, model and workspace-policy controls used to make models available.

Private routing prerequisites#

The chart includes a separate AI gateway role and settings for routing private inference through Cluster Agents. That layout requires its own internal TLS identities, gateway addressing and appropriate agent permission profile. A private-inference agent profile is distinct from inventory or terminal access.

  1. Have the operator select a supported private-inference deployment layout for your release.
  2. Configure the dedicated gateway identities and endpoints through the installation configuration.
  3. Register the corresponding connection/binding and policy using the supported administrative API/configuration for that layout.
  4. Test the endpoint through the intended route and verify the model conformance result.
  5. Confirm policy requires the intended private route before using sensitive data.

Do not infer privacy from labels#

A residency label alone does not physically relocate a provider or enforce your network boundary. Verify the actual endpoint, egress class, routing binding and policy. If a required integration is unavailable, correct it rather than falling back silently to a public endpoint.