Skip to main content

Status

The container becomes healthy after it receives and validates current configuration. Inspect it from the deployment directory:

Configuration and outages

The gateway waits for organization-scoped configuration changes over an outbound authenticated connection. It validates a complete update before replacing the active configuration. A malformed or interrupted update cannot partially change routing or policy. The runtime may briefly use its last valid configuration during a control-plane interruption. If it cannot refresh within ten minutes, it stops serving Resource traffic. A gateway with no valid configuration, unresolved identity, ambiguous Resource or credential, or failed destination TLS rejects the operation.

Upgrade or rotate enrollment

Create a fresh deployment command in the Console, update the deployment on the host, and run:
Creating the command rotates the previous enrollment value immediately. The current release runs one instance per gateway, so plan a brief interruption while the container restarts and receives configuration.

Pause or remove

Turn off Enabled to reject new Resource traffic while preserving the gateway definition, assignments, and activity. Before deleting a gateway, reassign or remove every Resource under Assigned resources; Forge rejects deletion while assignments remain.

Troubleshoot

Use Live → Resources for client and policy outcomes. Gateway logs should be used for runtime, network, and configuration failures; they do not contain destination secrets or protected payload values.