Infrastructure control plane

Run infrastructure as one system.

Good Gateway connects ingress, workloads, certificates, databases, monitoring and automation in one control plane — without taking ownership away from you.

Outbound-only node control

AI optional. Operations complete.

Services keep running without Gateway

One operational surface

From public traffic to the last log line.

Stop translating the same change across config files, shell sessions, dashboards and certificate folders. Gateway keeps the operational path connected and reviewable.

01control plane
04managed node types
00inbound management ports

Control the whole route

The daily infrastructure stack, connected.

Ingress + TLS

Domains, nginx routes, ACME, internal PKI, access policies and health checks move together.

Docker + delivery

Containers, Compose Projects, Pages, registries, builds, migrations, logs, files and rollbacks.

Databases

PostgreSQL, Redis and ClickHouse connections, health, scoped consoles and private application bindings.

Monitoring + logs

Host metrics, service state, GPU telemetry, live logs, structured ingestion and status pages.

Automation

Scoped API tokens, OAuth, CI/CD webhooks and remote MCP access for controlled operations.

AI Workspace

Optional scenarios and plan mode with permission-aware tools and explicit execution confirmation.

Choose who operates the control plane

Own every layer — or let us run one.

Self-hosted

Keep the control plane yours.

Install Gateway on an isolated Linux host. Your credentials, infrastructure topology and operational data remain in the environment you control.

  • One-command Docker install
  • Community and commercial plans
  • Update on your schedule
Install on your infrastructure
Managed cloud

We run Gateway. You run the systems.

A maintained Good Gateway control plane with included operational VMs, inference allowance and hosted build capacity — sized to your plan.

  • Managed control plane resources
  • Included infrastructure topology
  • Cloud access by request
Request cloud access

Self-hosted installation

One command. Your control plane.

Good Gateway — zsh
gateway@control-plane ~ % curl -sSL https://thesqlabs.com/gateway/install.sh | bash

01Checking Docker runtime…

02Creating gateway network…

03Starting control plane…

04Health check passed.

Installer ready Docker · Linux · guided browser setup

Explicit by design

Every change has a readable path.

Use the Operations Console directly, or describe an outcome in AI Workspace. The same permission model, approvals and audit history apply either way.

AIAI is an interface, not a dependency.
  1. 01

    Describe

    Start from a scenario, an API request or the Operations Console. Define the outcome while Gateway resolves the affected services, dependencies and required access.

  2. 02

    Review

    Inspect the generated plan before anything changes. See every resource, permission, dependency and potentially disruptive action in one readable sequence.

  3. 03

    Execute

    Approve mutations explicitly and follow every operation in real time. Gateway preserves context between steps and pauses whenever another confirmation is required.

  4. 04

    Verify

    Close the loop with health checks, deployment state, logs and an auditable result. Confirm the intended outcome instead of treating a successful command as proof.

Plans

Start with ownership. Add managed capacity when you need it.

Switch between self-hosted licensing and managed cloud. No per-node or per-user charges beyond the published plan limits.

Community

Core platform for noncommercial use.

$0/mo
  • Up to 100 managed nodes
  • 10 users
  • Core ingress, Docker, monitoring and AI Workspace
Choose plan

Personal

Commercial infrastructure ownership without plan quotas.

$29/mo
  • Commercial-use grant
  • Compose, managed databases and Pages
  • Migrations, archives and blue/green delivery
Choose plan

Enterprise

Advanced trust, export and assisted operations.

On request
  • Internal PKI and SIEM export
  • Dedicated technical contact
  • Assisted deployment and migration
Request access

Trust architecture

Trust starts before the first command.

Gateway is privileged by design, so identity, transport and execution boundaries are explicit from enrollment onward.

01

Outbound-only nodes

Managed hosts initiate encrypted connections. No inbound management ports are required.

02

Pinned enrollment

One-time tokens are paired with the Gateway certificate fingerprint before node identity is issued.

03

mTLS identity

Every managed node receives a certificate bound to its identity and checked on control streams.

04

Failure isolation

Existing routes and workloads continue operating if the control plane is temporarily unavailable.

Read the security model

Managed cloud access

Tell us what you need to operate.

Share the size of your team and infrastructure. We will reply with the right Good Gateway cloud plan and onboarding path.

[email protected]