Files
LocalAI/docs/static/images/diagrams/mitm-intercept.html
LocalAI [bot] 7e59a5c7c5 docs: architecture & feature diagrams (blueprint style) (#10137)
* docs: add 'how LocalAI works' architecture diagram

Add a blueprint-style architecture diagram: clients -> small core (API,
router, WebUI, agents) -> gRPC -> backend processes pulled on demand as
OCI images. Place it on the overview page and replace the stale external
architecture image on the reference page.

Assisted-by: Claude:claude-opus-4-8 [Claude Code]
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>

* docs: add blueprint diagrams across feature, distributed & getting-started docs

Add 24 architecture/flow/comparison diagrams (PNG + HTML source) under
docs/static/images/diagrams/, wired into their docs pages, from an
impact-vs-effort audit of the docs. Broaden the API surface on the
overview architecture diagram (OpenAI, Anthropic, ElevenLabs, Ollama,
and LocalAI's own API) and move the gRPC boundary label clear of the arrows.

Pages: distributed mode (architecture, scheduling, ds4 layer-split),
distributed inferencing, MLX, realtime, quantization, MCP, agents,
mitm & cloud proxy, middleware, reverse-proxy TLS, VRAM, voice & face
recognition, reranker, function calling, fine-tuning (recipe + jobs),
diarization, audio transform, quickstart, model resolution.

Assisted-by: Claude:claude-opus-4-8 [Claude Code]
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>

* docs: add composable-core diagram to README hero

Commit the composable-core card (small core + on-demand backend tiles)
alongside the other diagrams and reference it from the README hero via a
repo-relative path, so it renders on GitHub.

Assisted-by: Claude:claude-opus-4-8 [Claude Code]
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>

* docs: fix composable-core connectors/badge and federated-vs-worker layout

- composable-core: thicken the plug-in connectors so they read clearly, and
  widen the SEPARATE IMAGE badge so its text no longer overflows the box.
- federated-vs-worker: shorten the WHOLE/SPLIT REQUEST pills to fit, and
  replace the tangled node-to-node activation arrows with a clean fan-out
  (request split across all sharded nodes), mirroring the federated panel.

Assisted-by: Claude:claude-opus-4-8 [Claude Code]
Signed-off-by: Ettore Di Giacinto <mudler@localai.io>

---------

Signed-off-by: Ettore Di Giacinto <mudler@localai.io>
Co-authored-by: Ettore Di Giacinto <mudler@localai.io>
2026-06-02 18:43:22 +02:00

186 lines
9.4 KiB
HTML

<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<link rel="preconnect" href="https://fonts.googleapis.com">
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
<link href="https://fonts.googleapis.com/css2?family=Bricolage+Grotesque:opsz,wght@12..96,600;12..96,700;12..96,800&family=Archivo:wght@500;600;700&display=swap" rel="stylesheet">
<style>
:root{
--paper:#F3E8D2; --paper2:#ECDFC2; --ink:#211C14; --ink-soft:#5A5142;
--rust:#B43A2C; --rust-deep:#8F2C20; --cold:#3F6E73; --hi:#E7D6AE; --dim:#A99F88;
}
*{box-sizing:border-box;margin:0;padding:0}
html,body{width:1600px;height:900px}
body{
background:var(--paper);color:var(--ink);font-family:"Archivo",sans-serif;
position:relative;overflow:hidden;
background-image:
linear-gradient(var(--paper2) 1px,transparent 1px),
linear-gradient(90deg,var(--paper2) 1px,transparent 1px);
background-size:40px 40px;
}
.frame{position:absolute;inset:26px;border:3px solid var(--ink);}
.wrap{position:absolute;inset:26px;padding:30px 56px 26px;display:flex;flex-direction:column}
header{display:flex;align-items:flex-end;justify-content:space-between;gap:30px}
.eyebrow{font-weight:700;letter-spacing:.22em;text-transform:uppercase;font-size:17px;color:var(--rust-deep)}
.eyebrow b{color:var(--ink)}
h1{font-family:"Bricolage Grotesque",sans-serif;font-weight:800;font-size:50px;line-height:.98;letter-spacing:-.015em;margin-top:6px}
h1 em{font-style:normal;color:var(--rust)}
.stamp{border:3px solid var(--ink);padding:10px 16px 8px;transform:rotate(3deg);text-align:center;background:var(--paper);box-shadow:6px 6px 0 var(--ink);flex:none}
.stamp .k{font-family:"Bricolage Grotesque";font-weight:800;font-size:21px;letter-spacing:.04em;line-height:1.05}
.stamp .s{font-weight:700;font-size:11px;letter-spacing:.18em;text-transform:uppercase;color:var(--ink-soft);margin-top:5px}
.stage{flex:1;margin-top:8px}
svg{width:100%;height:100%;overflow:visible}
footer{display:flex;align-items:center;justify-content:space-between;margin-top:6px;gap:24px}
.note{font-weight:600;font-size:18px;color:var(--ink-soft);line-height:1.3;max-width:1080px}
.note b{color:var(--ink)}
.url{font-family:"Bricolage Grotesque";font-weight:800;font-size:22px;color:var(--rust-deep);letter-spacing:.01em;flex:none}
.url span{color:var(--ink)}
</style>
</head>
<body>
<div class="frame"></div>
<div class="wrap">
<header>
<div>
<div class="eyebrow">LocalAI <b>&middot;</b> MITM Proxy</div>
<h1>Inspect what you allow, <em>tunnel the rest</em></h1>
</div>
<div class="stamp">
<div class="k">TLS</div>
<div class="s">selective</div>
</div>
</header>
<div class="stage"><svg viewBox="0 0 1480 560" id="svg"></svg></div>
<footer>
<div class="note">Allowlisted hosts are decrypted and scanned; <b>everything else is a blind TCP tunnel.</b></div>
<div class="url">localai.io<span>/features/mitm-proxy</span></div>
</footer>
</div>
<script>
const INK="#211C14", PAPER="#F3E8D2", PAPER2="#ECDFC2", HI="#E7D6AE", SOFT="#5A5142", RUST="#B43A2C", RUSTD="#8F2C20", COLD="#3F6E73", DIM="#A99F88";
function el(t,a,x){const e=document.createElementNS("http://www.w3.org/2000/svg",t);for(const k in a)e.setAttribute(k,a[k]);if(x!=null)e.textContent=x;return e;}
const svg=document.getElementById("svg");
function shadowRect(x,y,w,h,fill,stroke,sw,dash){
svg.appendChild(el("rect",{x:x+7,y:y+7,width:w,height:h,fill:INK}));
svg.appendChild(el("rect",{x,y,width:w,height:h,fill,stroke:stroke||INK,"stroke-width":sw||3.5,"stroke-dasharray":dash||"none"}));
}
function txt(x,y,s,o){o=o||{};svg.appendChild(el("text",{x,y,"font-family":o.f||"Archivo","font-weight":o.w||700,"font-size":o.sz||15,"letter-spacing":o.ls||"0","text-anchor":o.a||"start",fill:o.fill||INK},s));}
function arrow(x1,y1,x2,y2,color,dash){
const mx=(x1+x2)/2;
svg.appendChild(el("path",{d:`M ${x1} ${y1} C ${mx} ${y1}, ${mx} ${y2}, ${x2-11} ${y2}`,fill:"none",stroke:color,"stroke-width":3.5,"stroke-linecap":"round","stroke-dasharray":dash||"none"}));
const a=7;
svg.appendChild(el("path",{d:`M ${x2-11} ${y2} l -${a+4} -${a} M ${x2-11} ${y2} l -${a+4} ${a}`,fill:"none",stroke:color,"stroke-width":3.5,"stroke-linecap":"round"}));
}
// straight-line connector with arrowhead, direction-aware
function line(x1,y1,x2,y2,color,dash){
svg.appendChild(el("line",{x1,y1,x2,y2,stroke:color,"stroke-width":3.5,"stroke-linecap":"round","stroke-dasharray":dash||"none"}));
const ang=Math.atan2(y2-y1,x2-x1), a=11, sp=0.5;
const bx=x2-Math.cos(ang)*0, by=y2-Math.sin(ang)*0;
svg.appendChild(el("path",{d:`M ${bx} ${by} L ${bx-Math.cos(ang-sp)*a} ${by-Math.sin(ang-sp)*a} M ${bx} ${by} L ${bx-Math.cos(ang+sp)*a} ${by-Math.sin(ang+sp)*a}`,fill:"none",stroke:color,"stroke-width":3.5,"stroke-linecap":"round"}));
}
// ============ CLIENT (left) ============
const cx=24, cy=232, cw=178, ch=96;
shadowRect(cx,cy,cw,ch,PAPER2);
txt(cx+cw/2,cy+44,"client",{f:"Bricolage Grotesque",w:800,sz:26,a:"middle"});
txt(cx+cw/2,cy+72,"CONNECT host:443",{w:700,sz:14,a:"middle",fill:SOFT});
// ============ DECISION DIAMOND ============
const dcx=370, dcy=280, dr=92;
// shadow
svg.appendChild(el("path",{d:`M ${dcx+7} ${dcy-dr+7} L ${dcx+dr+7} ${dcy+7} L ${dcx+7} ${dcy+dr+7} L ${dcx-dr+7} ${dcy+7} Z`,fill:INK}));
svg.appendChild(el("path",{d:`M ${dcx} ${dcy-dr} L ${dcx+dr} ${dcy} L ${dcx} ${dcy+dr} L ${dcx-dr} ${dcy} Z`,fill:HI,stroke:INK,"stroke-width":3.5}));
txt(dcx,dcy-6,"host",{f:"Bricolage Grotesque",w:800,sz:21,a:"middle"});
txt(dcx,dcy+22,"allowlisted?",{f:"Bricolage Grotesque",w:800,sz:21,a:"middle"});
// client -> diamond
line(cx+cw, cy+ch/2, dcx-dr-2, dcy, INK);
// YES / NO labels
txt(dcx+18,dcy-dr-12,"YES",{f:"Bricolage Grotesque",w:800,sz:17,fill:RUSTD});
txt(dcx-46,dcy+dr+34,"NO",{f:"Bricolage Grotesque",w:800,sz:17,fill:COLD});
// ============ NO BRANCH (cold teal) - down ============
const ntx=255, nty=448, ntw=288, nth=78;
// connector from diamond bottom down to tunnel box
line(dcx, dcy+dr, ntx+ntw/2, nty, COLD);
shadowRect(ntx,nty,ntw,nth,PAPER,COLD,3.5);
txt(ntx+ntw/2,nty+33,"plain TCP tunnel",{f:"Bricolage Grotesque",w:800,sz:22,a:"middle",fill:COLD});
txt(ntx+ntw/2,nty+58,"no inspection",{w:700,sz:15,a:"middle",fill:SOFT});
// ============ YES BRANCH (rust) - horizontal chain across top ============
const yY=120, yH=92, yW=196;
const steps=[
{x:520, t1:"mint", t2:"leaf cert"},
{x:520, t1:"terminate", t2:"TLS"},
{x:520, t1:"PII scan", t2:""},
{x:520, t1:"re-encrypt", t2:"to upstream"},
];
// lay out 4 steps left->right with gaps
const startX=512, gapX=42;
steps.forEach((s,i)=>{ s.x = startX + i*(yW+gapX); });
steps.forEach((s,i)=>{
shadowRect(s.x,yY,yW,yH,"#EFE0BF",RUST,3.5);
});
// labels (special for PII scan box, two-line endpoint detail)
txt(steps[0].x+yW/2,yY+42,"mint",{f:"Bricolage Grotesque",w:800,sz:22,a:"middle"});
txt(steps[0].x+yW/2,yY+68,"leaf cert",{w:700,sz:15,a:"middle",fill:SOFT});
txt(steps[1].x+yW/2,yY+42,"terminate TLS",{f:"Bricolage Grotesque",w:800,sz:21,a:"middle"});
txt(steps[1].x+yW/2,yY+68,"decrypt stream",{w:700,sz:14,a:"middle",fill:SOFT});
txt(steps[2].x+yW/2,yY+38,"PII scan",{f:"Bricolage Grotesque",w:800,sz:22,a:"middle"});
txt(steps[2].x+yW/2,yY+62,"/v1/messages ·",{w:700,sz:12.5,a:"middle",fill:SOFT});
txt(steps[2].x+yW/2,yY+79,"/v1/chat/completions",{w:700,sz:12.5,a:"middle",fill:SOFT});
txt(steps[3].x+yW/2,yY+42,"re-encrypt",{f:"Bricolage Grotesque",w:800,sz:21,a:"middle"});
txt(steps[3].x+yW/2,yY+68,"to upstream",{w:700,sz:15,a:"middle",fill:SOFT});
// connector diamond top -> first YES step (up then across)
line(dcx, dcy-dr, dcx, yY+yH/2, RUST);
line(dcx, yY+yH/2, steps[0].x-2, yY+yH/2, RUST);
// chain arrows between steps
for(let i=0;i<steps.length-1;i++){
line(steps[i].x+yW, yY+yH/2, steps[i+1].x-2, yY+yH/2, RUST);
}
// ============ UPSTREAM (right) ============
const ux=1276, uy=240, uw=184, uh=92;
shadowRect(ux,uy,uw,uh,PAPER2);
txt(ux+uw/2,uy+42,"upstream",{f:"Bricolage Grotesque",w:800,sz:24,a:"middle"});
txt(ux+uw/2,uy+70,"OpenAI · API host",{w:700,sz:14,a:"middle",fill:SOFT});
// last YES step -> upstream (down then into top edge)
const lastX = steps[3].x+yW/2;
const elbowY = uy-22;
line(lastX, yY+yH, lastX, elbowY, RUST);
line(lastX, elbowY, ux+uw/2, elbowY, RUST);
line(ux+uw/2, elbowY, ux+uw/2, uy-2, RUST);
// NO tunnel -> upstream (cold, dashed) - route below the trust-chain box
const noElbowX = ux+uw/2;
line(ntx+ntw, nty+nth/2, noElbowX, nty+nth/2, COLD, "2 9");
line(noElbowX, nty+nth/2, noElbowX, uy+uh+2, COLD, "2 9");
// ============ TRUST CHAIN (bottom-right corner) ============
const tcX=980, tcY=372, tcW=372, tcH=150;
svg.appendChild(el("rect",{x:tcX,y:tcY,width:tcW,height:tcH,fill:PAPER,stroke:INK,"stroke-width":2.5,"stroke-dasharray":"4 7"}));
txt(tcX+18,tcY+30,"TRUST CHAIN",{w:700,sz:13,ls:".2em",fill:SOFT});
// CA -> leaf
const caX=tcX+30, caY=tcY+52, caW=132, caH=46;
shadowRect(caX,caY,caW,caH,HI,INK,3);
txt(caX+caW/2,caY+30,"local CA",{f:"Bricolage Grotesque",w:800,sz:18,a:"middle"});
const lfX=tcX+212, lfY=caY, lfW=132, lfH=46;
shadowRect(lfX,lfY,lfW,lfH,"#EFE0BF",RUST,3);
txt(lfX+lfW/2,lfY+30,"leaf cert",{f:"Bricolage Grotesque",w:800,sz:18,a:"middle",fill:RUSTD});
line(caX+caW, caY+caH/2, lfX-2, lfY+lfH/2, RUSTD);
txt(tcX+tcW/2, caY+caH/2-12, "signs",{w:700,sz:12,a:"middle",fill:SOFT});
// note inside trust chain
txt(tcX+18,tcY+tcH-26,"the client holds its own",{w:600,sz:14,fill:SOFT});
txt(tcX+18,tcY+tcH-9,"upstream credential",{w:700,sz:14,fill:INK});
</script>
</body>
</html>