docs: refresh pairing locality refs

This commit is contained in:
Peter Steinberger
2026-04-04 16:12:56 +01:00
parent 983909f826
commit 89535f9313
5 changed files with 27 additions and 13 deletions

View File

@@ -893,10 +893,12 @@ paths, set `OPENCLAW_ALLOW_INSECURE_PRIVATE_WS=1` on the client process as break
Local device pairing:
- Device pairing is autoapproved for **local** connects (loopback or the
gateway hosts own tailnet address) to keep samehost clients smooth.
- Other tailnet peers are **not** treated as local; they still need pairing
approval.
- Device pairing is auto-approved for direct local loopback connects to keep
same-host clients smooth.
- OpenClaw also has a narrow backend/container-local self-connect path for
trusted shared-secret helper flows.
- Tailnet and LAN connects, including same-host tailnet binds, are treated as
remote for pairing and still need approval.
Auth modes: