Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion src/components/pages/CorePage.astro
Original file line number Diff line number Diff line change
Expand Up @@ -143,7 +143,7 @@ const fileLink = "break-all text-[var(--color-brand-1)] transition-colors hover:
<p class="nx-body">{c.does.items[2].body}</p>
</article>
<article class="nx-tile nx-span-2 nx-in">
<div class="viz swap" aria-hidden="true"><span class="from">sk-ant-api03-7Hq…</span><span class="to">[CREDENTIAL_1]</span></div>
<div class="viz swap" aria-hidden="true"><span class="from">sk-ant-api03-7Hq…</span><span class="to">{"<<TW_SECRET_1>>"}</span></div>
<h3 class="nx-h3">{c.does.items[3].title}</h3>
<p class="nx-body">{c.does.items[3].body}</p>
</article>
Expand Down
4 changes: 2 additions & 2 deletions src/content/docs-core/en/crate-layers.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ No crate depends on a group below its own.
| Group | Crate | Role |
| --- | --- | --- |
| Shared with ThinkWatch Enterprise | `tw-dialect` | Conversion of requests, responses and streams between Anthropic Messages, OpenAI Chat Completions, OpenAI Responses and Gemini; usage parsing |
| | `tw-guard` | Outbound redaction and restoration, inspection of the tool calls an upstream returns, hidden characters, content filtering and the output length limit |
| | `tw-guard` | Outbound redaction and restoration, inspection of the tool calls an upstream returns, and the content filter, with the settings, built-in rules, validation, rule listings and trials of all three |
| | `tw-breaker` | The circuit-breaker state machine |
| | `tw-bedrock` | Amazon Bedrock on the wire: SigV4 signing, event-stream framing, addresses and the model catalog |
| Domain logic | `tw-types` | Messages for people: a stable code, its arguments and the English sentence |
Expand All @@ -34,7 +34,7 @@ No crate depends on a group below its own.

## Shared with ThinkWatch Enterprise

ThinkWatch Enterprise depends on the first group and nothing else: format conversion and usage parsing (`tw-dialect`), the guards (`tw-guard`), the circuit breaker (`tw-breaker`) and Amazon Bedrock's wire protocol (`tw-bedrock`). These four depend only on each other, which a test in `tw-dialect` enforces, and CI builds ThinkWatch Enterprise against every change to them. A component that only one product uses lives in that product's repository rather than in Core.
ThinkWatch Enterprise depends on the first group and nothing else: format conversion and usage parsing (`tw-dialect`), the guards and their rules (`tw-guard`), the circuit breaker (`tw-breaker`) and Amazon Bedrock's wire protocol (`tw-bedrock`). These four depend only on each other, which a test in `tw-dialect` enforces, and CI builds ThinkWatch Enterprise against every change to them. A component that only one product uses lives in that product's repository rather than in Core.

## Used by ThinkWatch Lite

Expand Down
5 changes: 3 additions & 2 deletions src/content/docs-core/en/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,9 @@ Clients such as Claude Code and Codex send their requests to the gateway, and Co
- **Rule-based routing.** Rules match on the model, the gateway key, the input size, the presence of tools or images and other properties of a request, and send it to an upstream or a group, rewrite its parameters or refuse it. When the client and the upstream use different API formats, the request is converted between Anthropic Messages, OpenAI Chat Completions, OpenAI Responses and Gemini.
- **Failover before the first byte.** Until the first byte reaches the client, a failing upstream is replaced by the next one without the client noticing. After that point, the failure is reported. A circuit breaker keeps requests away from an upstream that keeps failing.
- **Cost accounting.** Token usage and cache hits are priced from a public price table, which the control plane refreshes daily, or from a price sheet in the configuration. Each request records its cost and where the price came from. Estimated amounts are marked as such, and usage that cannot be priced is labelled *unknown* rather than given an invented figure.
- **Outbound redaction.** Credentials in a request are replaced with placeholders before the request leaves, and restored when the model echoes them back.
- **Tool-call inspection.** Tool calls returned by an upstream are checked against a rule set, and a dangerous call can be cut off mid-stream. With checks for hidden characters, content rules and an output limit, these form five guards, each set to `off`, `observe` or `enforce`.
- **Outbound redaction.** Credentials and personal information anywhere in a request are replaced with placeholders before the request leaves, and restored when the model echoes them back.
- **Tool-call inspection.** Tool calls returned by an upstream are checked against a rule set, and a dangerous call can be cut off mid-stream.
- **Content filter.** The user messages and tool results a client sends are checked by keyword, regular expression or code point, and each rule refuses the request, deletes what it matched or only records it; the built-in rules also catch hidden characters that can carry instructions. Each of the three guards is set to `off`, `observe` or `enforce`, and all start in `observe`.
- **An encrypted control plane.** The desktop app and `twcore` commands reach core over a local socket (a loopback port on Windows) and, when it is enabled, a remote control port. Every control connection starts with a Noise handshake keyed by `listen.control.key`; there are no certificates.

## Further reading
Expand Down
4 changes: 2 additions & 2 deletions src/content/docs-core/zh-CN/crate-layers.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ tw-gateway · tw-control ← 数据
| 分组 | crate | 作用 |
| --- | --- | --- |
| 与 ThinkWatch 企业版共用 | `tw-dialect` | 请求、响应与流在 Anthropic Messages、OpenAI Chat Completions、OpenAI Responses 与 Gemini 之间的转换;用量解析 |
| | `tw-guard` | 出站脱敏与还原、上游返回的工具调用审查、隐藏字符、内容过滤与输出长度限制 |
| | `tw-guard` | 出站脱敏与还原、上游返回的工具调用审查与内容过滤,以及这三项防护的设置、内置规则、校验、规则列表与测试 |
| | `tw-breaker` | 熔断器状态机 |
| | `tw-bedrock` | Amazon Bedrock 的线上协议:SigV4 签名、事件流拆帧、接口地址与模型目录 |
| 领域逻辑 | `tw-types` | 面向用户的消息:稳定的消息码、参数与英文句子 |
Expand All @@ -34,7 +34,7 @@ tw-gateway · tw-control ← 数据

## 与 ThinkWatch 企业版共用

ThinkWatch 企业版只依赖第一组:格式转换与用量解析(`tw-dialect`)、各项防护(`tw-guard`)、熔断器(`tw-breaker`)与 Amazon Bedrock 的线上协议(`tw-bedrock`)。这四个 crate 只依赖彼此,`tw-dialect` 中的一项测试保证这一点;每次改动它们,CI 都会用 ThinkWatch 企业版编译一遍。只有一个产品使用的组件放在该产品自己的仓库中,不留在 Core。
ThinkWatch 企业版只依赖第一组:格式转换与用量解析(`tw-dialect`)、各项防护及其规则(`tw-guard`)、熔断器(`tw-breaker`)与 Amazon Bedrock 的线上协议(`tw-bedrock`)。这四个 crate 只依赖彼此,`tw-dialect` 中的一项测试保证这一点;每次改动它们,CI 都会用 ThinkWatch 企业版编译一遍。只有一个产品使用的组件放在该产品自己的仓库中,不留在 Core。

## ThinkWatch Lite 使用的部分

Expand Down
5 changes: 3 additions & 2 deletions src/content/docs-core/zh-CN/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,8 +15,9 @@ Claude Code、Codex 等客户端把请求发往网关后,Core 提供以下功
- **按规则路由。** 规则按模型、网关密钥、输入规模、是否携带工具或图片等请求属性匹配,将请求发往某个上游或策略组、改写其参数,或拒绝请求。客户端与上游的接口格式不同时,请求在 Anthropic Messages、OpenAI Chat Completions、OpenAI Responses 与 Gemini 之间转换。
- **首字节前的故障转移。** 首字节到达客户端之前,出错的上游由下一个上游替换,客户端无从察觉;此后发生的故障如实报告。熔断器使持续出错的上游暂不接收请求。
- **费用核算。** token 用量与缓存命中按公开价目表计价(控制面每天刷新一次),或按配置中的价目表计价;每个请求都记录费用及价格来源。估算的金额另行标注,无法计价的用量标记为「未知」,不会填入虚构的数值。
- **出站脱敏。** 请求发出之前,其中的凭据替换为占位符;模型回显时再恢复原值。
- **工具调用审查。** 上游返回的工具调用按规则集审查,高危调用可在流式传输中途截断。它与隐藏字符检查、内容规则和输出长度限制合为五项防护,每项可设为 `off`、`observe` 或 `enforce`。
- **出站脱敏。** 请求发出之前,其中任何位置的凭据和个人信息替换为占位符;模型回显时再恢复原值。
- **工具调用审查。** 上游返回的工具调用按规则集审查,高危调用可在流式传输中途截断。
- **内容过滤。** 客户端发送的用户消息和工具结果按关键词、正则表达式或码位检查,每条规则可拒绝请求、删除命中的内容或仅记录;内置规则也能查出可夹带指令的隐藏字符。三项防护各可设为 `off`、`observe` 或 `enforce`,出厂均为 `observe`。
- **加密的控制面。** 桌面应用与 `twcore` 命令通过本地 socket(Windows 上为回环端口)连接 core,开启后也可经远程控制端口连接。每条控制连接都先以 `listen.control.key` 完成 Noise 握手,不使用证书。

## 后续阅读
Expand Down
Loading
Loading