Skip to main content

Requirements

Choose a Linux Docker host in the same private network as the destinations. It needs Docker Compose, outbound HTTPS to Forge, and these paths as applicable: Create internal DNS for the configured gateway hostname and point it at the host or a TCP/TLS pass-through load balancer. Do not terminate or rewrite HTTP in front of the gateway; the same runtime also serves database protocols and the managed routing tunnel.

Install

  1. Open Policies → Resources and choose New → Resource gateway.
  2. Enter a name and the DNS hostname clients will use.
  3. Select Create deployment command and copy it.
  4. Run the command on the Docker host.
  5. Wait for the Console status to change from Setup required to Online.
  6. Assign one or more Resources to the gateway and run Test connection.
The generated deployment pins an exact gateway image version. Its enrollment value is shown once and stored locally for the container. Restrict access to the deployment directory and do not commit its environment file. Generating a new deployment command rotates the previous enrollment value immediately. Replace the value on the host and restart the container promptly.

Client trust

Direct clients must trust the organization certificate that the gateway uses for Resource hostnames. Download forge-resource-ca.pem from a Resource’s Connect directly section and use the generated client command. Managed devices receive the required trust through device setup. The gateway separately verifies each destination hostname against public roots or the Resource’s configured private authority. Forge never offers a skip-verification option.

Verify

Run one harmless operation through the generated direct command, then open Live → Resources and confirm the gateway, Resource, caller, operation, and policy outcome. Repeat through automatic routing when that path is enabled. See Operate Resource gateways for status, upgrades, rotation, and failure behavior.