Resource settings
PostgreSQL, MySQL, and Redis always require encrypted, verified destination
connections. HTTP can use plain HTTP or verified HTTPS. Forge does not provide
a skip-verification setting.
Publicly trusted destination certificates need no additional configuration.
For a private PKI, paste only the issuing public CA certificate into Private
authority. Never upload a private key or a destination server certificate’s
private material.
Select an access path
Automatic routing
Enable Automatic routing when enrolled devices should continue using the destination’s original hostname and port. Forge publishes the Resource route to eligible devices. The endpoint intercepts the matching connection, authenticates the device and user, and sends it to the assigned Resource Gateway. The original destination must be expressed as a hostname. Forge does not infer an HTTP Resource from an IP-only flow, and it does not apply a command policy to a database connection that bypasses Forge.Direct access
Assign a Resource Gateway when a client should connect explicitly. The Resource page generates the exact command and a short-lived credential for the signed-in user. Services use an active Forge service account with theresources:connect scope.
Direct and automatic access are independent choices over the same Resource:
How direct clients select a Resource
One Gateway listener can serve many Resources. Selection is protocol-specific and the Console generates it for you.
The short-lived Forge credential authenticates the caller and selects the
Resource. It is not forwarded to the destination. The Gateway separately
chooses the destination credential assigned to that caller.