> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Deploy Resource gateway

> Install the version-pinned gateway container in a private network.

## Requirements

Choose a Linux Docker host in the same private network as the destinations. It
needs Docker Compose, outbound HTTPS to Forge, and these paths as applicable:

| Direction | Port | Purpose |
| - | - | - |
| Inbound | `443` | HTTP/HTTPS clients and managed routing tunnel |
| Inbound | `5432` | PostgreSQL clients |
| Inbound | `3306` | MySQL clients |
| Inbound | `6379` | Redis clients |
| Outbound | Resource-specific | Assigned destinations |

Create internal DNS for the configured gateway hostname and point it at the
host or a TCP/TLS pass-through load balancer. Do not terminate or rewrite HTTP
in front of the gateway; the same runtime also serves database protocols and
the managed routing tunnel.

## Install

1. Open **Policies → Resources** and choose **New → Resource gateway**.
2. Enter a name and the DNS hostname clients will use.
3. Select **Create deployment command** and copy it.
4. Run the command on the Docker host.
5. Wait for the Console status to change from **Setup required** to **Online**.
6. Assign one or more Resources to the gateway and run **Test connection**.

The generated deployment pins an exact gateway image version. Its enrollment
value is shown once and stored locally for the container. Restrict access to
the deployment directory and do not commit its environment file.

Generating a new deployment command rotates the previous enrollment value
immediately. Replace the value on the host and restart the container promptly.

## Client trust

Direct clients must trust the organization certificate that the gateway uses
for Resource hostnames. Download `forge-resource-ca.pem` from a Resource's
**Connect directly** section and use the generated client command. Managed
devices receive the required trust through device setup.

The gateway separately verifies each destination hostname against public roots
or the Resource's configured private authority. Forge never offers a
skip-verification option.

## Verify

Run one harmless operation through the generated direct command, then open
**Live → Resources** and confirm the gateway, Resource, caller, operation, and
policy outcome. Repeat through automatic routing when that path is enabled.

See [Operate Resource gateways](/resources/operate-resource-gateways) for
status, upgrades, rotation, and failure behavior.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.