---
title: "通过 Tailscale 访问本地 AI"
description: "为已有的 Ollama API 配置私有 HTTPS 地址，让获准设备或 agent 连接。"
url: "https://tslink.md/zh/docs/local-ai"
locale: "zh"
product_version: "0.1.1"
source: "https://github.com/anydoor7/tslink/blob/v0.1.1/docs/local-ai.md"
---

> Documentation index: https://tslink.md/zh/llms.txt · Installed binary is authoritative: `tslink manifest`.

TSLink 为已有模型 HTTP API 提供私有 HTTPS 地址。后端负责推理，TSLink 转发流量。获准设备可把地址配置到 Ollama client 或兼容应用中。

Shell 示例使用 bash/zsh 与 curl。

## 先检查后端

[安装 TSLink](https://tslink.md/zh/docs/installation.md)，在发布主机自行运行 Ollama。需要本地推理时，选择并下载本地模型。分享前检查 API：

```bash
curl http://localhost:11434/api/tags
```

响应列出已安装的模型。无法连接时先修复后端；列表为空时仍需安装模型才能推理。

## 注册私有模型地址

将邮箱替换为自己的 Tailscale 登录账户：

```bash
tslink add model --proxy localhost:11434 --allow you@example.com
tslink url model --wait
```

按提示完成节点入网。访问设备需要 Tailscale，网络策略也必须允许连接。使用返回的准确 URL；同名 `add` 会替换服务设置，修改时需重复所有要保留的选项。

从获准的访问设备执行：

```bash
MODEL_URL='PASTE_THE_EXACT_URL_RETURNED_BY_TSLINK'
curl "$MODEL_URL/api/tags"
```

| Client 设置           | 填入的值                |
| ------------------- | ------------------- |
| Ollama server URL   | 返回的 HTTPS origin    |
| 原生 Ollama API base  | 返回的 origin 加 `/api` |
| OpenAI 兼容 `baseURL` | 返回的 origin 加 `/v1`  |

选择已安装的模型名称。Ollama 只兼容部分 OpenAI API 功能，需核对 client 使用的路由与参数。Client 的 API-key 字段不能替代 Tailscale 访问检查。

## 添加网页界面或同事

`local-ai-suite` 模板分别注册 `ollama`（`localhost:11434`）和 `open-webui`（`localhost:8080`）节点。它是上述手工 `model` 注册的另一种选择：

```bash
tslink template apply local-ai-suite
tslink template apply local-ai-suite --yes
tslink url ollama --wait
tslink url open-webui --wait
```

先预览；模板保留已有条目。两个应用都需自行安装与配置，包括 Open WebUI 的模型连接。`tslink apps list` 的 recipes 提供更多应用建议。

给另一个人开放私有模型服务一小时，可以用[人员授权](https://tslink.md/zh/docs/people-sharing.md)：

```bash
tslink people add alice@example.com --apps model --for 1h
```

若选择模板，将 `model` 换成 `ollama`。首次人员授权会收紧该应用的访问范围，也要配置自己的访问权限。

## 明确数据路径

TSLink 不加载模型、不实现 RAG、不索引文档，也不阻止出站请求。Localhost Ollama API 仍可能使用云端模型，远程 agent 也可能在其他主机处理接收的数据。应按数据敏感程度选择本地模型、数据存储和应用日志设置。

TSLink 的 MCP 管理分享；agent 的推理连接需单独使用模型地址配置。其他主机上的 agent 仍需能访问 tailnet。模型 API 应保持私有；Funnel 没有 TSLink 调用者身份检查。

HTTP 响应支持流式转发。上传默认限制为 32 MiB 请求体与 30 秒无读取进展窗口，这不是总推理时限。大输入需明确配置[请求限制](https://tslink.md/zh/docs/health-and-alerts.md#uploads-and-request-limits)；后端与 client 的限制也仍适用。

相关：[Agent/MCP 配置](https://tslink.md/zh/docs/mcp-server.md) · [健康检查](https://tslink.md/zh/docs/health-and-alerts.md)。

来源：[TSLink 本地 AI 指南](https://github.com/anydoor7/tslink/blob/v0.1.1/docs/local-ai.md)、[Ollama 模型列表](https://docs.ollama.com/api/tags)、[Ollama API 兼容说明](https://docs.ollama.com/api/openai-compatibility)。
