Ingress + TLS
Domains, nginx routes, ACME, internal PKI, access policies and health checks move together.
Good Gateway
Infrastructure control plane
Good Gateway connects ingress, workloads, certificates, databases, monitoring and automation in one control plane — without taking ownership away from you.
Outbound-only node control
AI optional. Operations complete.
Services keep running without Gateway
One operational surface
Stop translating the same change across config files, shell sessions, dashboards and certificate folders. Gateway keeps the operational path connected and reviewable.
Control the whole route
Domains, nginx routes, ACME, internal PKI, access policies and health checks move together.
Containers, Compose Projects, Pages, registries, builds, migrations, logs, files and rollbacks.
PostgreSQL, Redis and ClickHouse connections, health, scoped consoles and private application bindings.
Host metrics, service state, GPU telemetry, live logs, structured ingestion and status pages.
Scoped API tokens, OAuth, CI/CD webhooks and remote MCP access for controlled operations.
Optional scenarios and plan mode with permission-aware tools and explicit execution confirmation.
Choose who operates the control plane
Install Gateway on an isolated Linux host. Your credentials, infrastructure topology and operational data remain in the environment you control.
A maintained Good Gateway control plane with included operational VMs, inference allowance and hosted build capacity — sized to your plan.
Self-hosted installation
curl -sSL https://thesqlabs.com/gateway/install.sh | bash
01Checking Docker runtime…
02Creating gateway network…
03Starting control plane…
04Health check passed.
Explicit by design
Use the Operations Console directly, or describe an outcome in AI Workspace. The same permission model, approvals and audit history apply either way.
Start from a scenario, an API request or the Operations Console. Define the outcome while Gateway resolves the affected services, dependencies and required access.
Inspect the generated plan before anything changes. See every resource, permission, dependency and potentially disruptive action in one readable sequence.
Approve mutations explicitly and follow every operation in real time. Gateway preserves context between steps and pauses whenever another confirmation is required.
Close the loop with health checks, deployment state, logs and an auditable result. Confirm the intended outcome instead of treating a successful command as proof.
Plans
Switch between self-hosted licensing and managed cloud. No per-node or per-user charges beyond the published plan limits.
Core platform for noncommercial use.
Commercial infrastructure ownership without plan quotas.
Build, deploy and observe production workloads.
Advanced trust, export and assisted operations.
A focused managed environment for small teams.
Production capacity, builds and deeper agent context.
A configurable operating envelope for larger fleets.
Trust architecture
Gateway is privileged by design, so identity, transport and execution boundaries are explicit from enrollment onward.
Managed hosts initiate encrypted connections. No inbound management ports are required.
One-time tokens are paired with the Gateway certificate fingerprint before node identity is issued.
Every managed node receives a certificate bound to its identity and checked on control streams.
Existing routes and workloads continue operating if the control plane is temporarily unavailable.
Managed cloud access
Share the size of your team and infrastructure. We will reply with the right Good Gateway cloud plan and onboarding path.
[email protected]