Skip to main content
A Resource gateway is a small Forge runtime deployed inside a network that can reach private Resources. It accepts direct client connections and managed device routes, resolves the caller, obtains the assigned destination credential, evaluates Resource Policies, and connects separately to the destination. One gateway can serve many HTTP, PostgreSQL, MySQL, and Redis Resources. The listener ports are fixed by protocol, while the Resource assignment determines the destination and policy. Resource definitions, credentials, policies, and certificates are pulled from Forge after startup; they are not duplicated in the deployment file.

Deployment model

Forge publishes a versioned Linux container for AMD64 and ARM64. The Console generates one deployment command for a Docker Compose host and pins an exact image version. The runtime only needs outbound HTTPS to Forge, inbound access from intended clients, and outbound access to assigned destinations. The deployment credential enrolls one gateway and is not a Resource access or destination credential. Store it as a secret and rotate it by generating a new deployment command. The current release supports one runtime instance per gateway. Run separate gateway definitions for separate networks or failure domains.

Security boundary

The gateway receives encrypted configuration and destination credentials only for its assigned Resources. Temporary AWS and OAuth credentials are generated or exchanged at the gateway when possible. Request bodies, raw SQL, result values, and destination secrets do not transit the Forge control plane during normal traffic. If identity, Resource selection, credential selection, policy, TLS, or current configuration cannot be proven, the gateway rejects the operation. Continue with: