> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Operate Resource gateways

> Monitor, upgrade, rotate, pause, and troubleshoot gateways.

## Status

| Console status | Meaning |
| - | - |
| Setup required | The gateway has not enrolled |
| Online | Contact and validated configuration are current |
| Offline | No check-in has arrived for two minutes |
| Disabled | The gateway is paused and rejects new traffic |

The container becomes healthy after it receives and validates current
configuration. Inspect it from the deployment directory:

```sh theme={"system"}
docker compose ps
docker compose logs --tail=200 gateway
```

## Configuration and outages

The gateway waits for organization-scoped configuration changes over an
outbound authenticated connection. It validates a complete update before
replacing the active configuration. A malformed or interrupted update cannot
partially change routing or policy.

The runtime may briefly use its last valid configuration during a control-plane
interruption. If it cannot refresh within ten minutes, it stops serving
Resource traffic. A gateway with no valid configuration, unresolved identity,
ambiguous Resource or credential, or failed destination TLS rejects the
operation.

## Upgrade or rotate enrollment

Create a fresh deployment command in the Console, update the deployment on the
host, and run:

```sh theme={"system"}
docker compose pull
docker compose up -d
docker compose ps
```

Creating the command rotates the previous enrollment value immediately. The
current release runs one instance per gateway, so plan a brief interruption
while the container restarts and receives configuration.

## Pause or remove

Turn off **Enabled** to reject new Resource traffic while preserving the
gateway definition, assignments, and activity. Before deleting a gateway,
reassign or remove every Resource under **Assigned resources**; Forge rejects
deletion while assignments remain.

## Troubleshoot

| Symptom | Check |
| - | - |
| Gateway stays in Setup required | Enrollment value, outbound HTTPS, container logs, and system clock |
| Gateway is Offline | Container health, DNS, egress, and current enrollment value |
| Client TLS error | Gateway hostname, internal DNS, and organization trust certificate |
| Destination TLS error | Resource hostname, certificate chain, and private authority |
| Authentication fails | Caller identity, credential assignment, expiry, and upstream permissions |
| Policy appears stale | Gateway contact time and current policy revision |

Use **Live → Resources** for client and policy outcomes. Gateway logs should be
used for runtime, network, and configuration failures; they do not contain
destination secrets or protected payload values.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.