Skip to main content
A Resource identifies one protected destination. Its protocol determines the client listener, available credentials, policy fields, and enforcement depth. The same Resource definition is used for direct access and automatic routing.

Resource settings

PostgreSQL, MySQL, and Redis always require encrypted, verified destination connections. HTTP can use plain HTTP or verified HTTPS. Forge does not provide a skip-verification setting. Publicly trusted destination certificates need no additional configuration. For a private PKI, paste only the issuing public CA certificate into Private authority. Never upload a private key or a destination server certificate’s private material.

Select an access path

Automatic routing

Enable Automatic routing when enrolled devices should continue using the destination’s original hostname and port. Forge publishes the Resource route to eligible devices. The endpoint intercepts the matching connection, authenticates the device and user, and sends it to the assigned Resource Gateway. The original destination must be expressed as a hostname. Forge does not infer an HTTP Resource from an IP-only flow, and it does not apply a command policy to a database connection that bypasses Forge.

Direct access

Assign a Resource Gateway when a client should connect explicitly. The Resource page generates the exact command and a short-lived credential for the signed-in user. Services use an active Forge service account with the resources:connect scope. Direct and automatic access are independent choices over the same Resource:

How direct clients select a Resource

One Gateway listener can serve many Resources. Selection is protocol-specific and the Console generates it for you. The short-lived Forge credential authenticates the caller and selects the Resource. It is not forwarded to the destination. The Gateway separately chooses the destination credential assigned to that caller.

Test before enabling access

Use Test connection after assigning a Gateway and credential. The test runs from the Gateway, so it verifies private-network reachability, DNS, destination TLS, and supported authentication from the same environment that will serve traffic. Identity token exchange needs a real caller token, so its test covers reachability and TLS; verify authentication with a real request. A successful test does not bypass policy. Run an actual client operation to verify policy and activity behavior, then open Live → Resources to see the result.

Disable or remove a Resource

Disabling a Resource prevents new traffic while preserving its definition, credentials, policies, and activity. Before deleting a Gateway, reassign or remove all Resources that use it. Forge rejects deletion while assignments remain. See Deploy a Resource gateway for installation and client trust, and Resource Policies for enforcement.