Requirements
Choose a Linux Docker host in the same private network as the destinations. It needs Docker Compose, outbound HTTPS to Forge, and these paths as applicable:
Create internal DNS for the configured gateway hostname and point it at the
host or a TCP/TLS pass-through load balancer. Do not terminate or rewrite HTTP
in front of the gateway; the same runtime also serves database protocols and
the managed routing tunnel.
Install
- Open Policies → Resources and choose New → Resource gateway.
- Enter a name and the DNS hostname clients will use.
- Select Create deployment command and copy it.
- Run the command on the Docker host.
- Wait for the Console status to change from Setup required to Online.
- Assign one or more Resources to the gateway and run Test connection.
Client trust
Direct clients must trust the organization certificate that the gateway uses for Resource hostnames. Downloadforge-resource-ca.pem from a Resource’s
Connect directly section and use the generated client command. Managed
devices receive the required trust through device setup.
The gateway separately verifies each destination hostname against public roots
or the Resource’s configured private authority. Forge never offers a
skip-verification option.