Skip to main content
Configuration and security

Using VPC

Configure Qoder CLI CN to reach services through your organization's dedicated VPC endpoint.

VPC mode applies only to Qoder CLI CN. Once configured, the CLI's sign-in, account APIs, and model requests all use your organization's dedicated VPC endpoint.

Before you start

Obtain the VPC endpoint from your organization administrator. This page uses acme.vpc.qoder.com.cn as the example, where acme is the organization's VPC instance name. Confirm that your current network and DNS can reach that domain. You only need to configure this one domain; the CLI handles the remaining request addresses automatically.

Configuring the VPC endpoint

Run the following command to set the VPC endpoint:
qodercn config set vpc_endpoint acme.vpc.qoder.com.cn
The configuration is saved to the user-level ~/.qoder-cn/settings.json and applies to Qoder CLI CN sessions this user starts afterwards. Use the following command to check the saved configuration:
qodercn config get vpc_endpoint
Expected output:
acme.vpc.qoder.com.cn
Setting or changing the VPC endpoint clears the existing login state. Restart the CLI and sign in when prompted:
qodercn
After startup, the top of the TUI shows the current endpoint, for example Endpoint: acme.vpc.qoder.com.cn. Once signed in, send a simple task to confirm that model requests return normally.

Changing or disabling the VPC endpoint

To change instances, run config set again with the new full domain:
qodercn config set vpc_endpoint new-instance.vpc.qoder.com.cn
To disable the VPC endpoint, run:
qodercn config unset vpc_endpoint
Whether you set or change the endpoint with config set or disable it with config unset, the CLI clears the existing login state automatically. Restart the CLI and sign in again once you are done.

FAQ

The VPC endpoint is reported as invalid

config set requires a full domain under vpc.qoder.com.cn, for example acme.vpc.qoder.com.cn. Do not use a bare instance name, an IP address, or any other domain.

Sign-in or model requests fail

Confirm that your current network can resolve and reach the instance's base domain, OpenAPI domain, and gateway domain over HTTPS. VPC mode uses fixed per-instance domains, so your network proxy, firewall, and DNS all need to allow these addresses.