Repository navigation
Gateways
One process, one port. Security follows the mode: public binds require bearer auth.
| Mode | Bind default | Auth | Agent execution |
|---|---|---|---|
| internal | 127.0.0.1 |
off | Embedded managed runner |
| public | 0.0.0.0 |
required | Never on the hub; paired runner |
| serve | 127.0.0.1 |
required | Paired runner; Tailscale Serve |
| funnel | 127.0.0.1 |
required | Paired runner; Tailscale Funnel |
Use Add Agent in every mode. Public, Serve, Funnel, and Railway never start harnesses on the hub. See Agents and Tailscale.
opengateways serve
# http://127.0.0.1:8765/ui/Badge: Internal (loopback). Not reachable from other machines.
Two processes if you want loopback and LAN at once (separate ports; share SQLite only when you want one hub):
opengateways serve --mode internal --port 8765
export OPENGATEWAY_AUTH_TOKEN="$(openssl rand -hex 24)"
opengateways serve --mode public --via open --network lan \
--host 0.0.0.0 --port 8766 --token "$OPENGATEWAY_AUTH_TOKEN" \
--public-url "http://$(ipconfig getifaddr en0):8766"export OPENGATEWAY_AUTH_TOKEN="$(openssl rand -hex 24)"
opengateways serve --mode public --via open --network lan \
--host 0.0.0.0 --token "$OPENGATEWAY_AUTH_TOKEN" \
--public-url "http://$(ipconfig getifaddr en0):8765"Badge: LAN. Paste the token in Live Ops Settings.
Prefer Serve over exposing a raw Tailscale IP. Many hosts firewall the utun interface, so http://100.x.x.x:8765 times out even when LAN works.
opengateways serve --mode serve --token "$OPENGATEWAY_AUTH_TOKEN"
tailscale serve --bg 8765opengateways serve --mode funnel --token "$OPENGATEWAY_AUTH_TOKEN"
tailscale funnel --bg 8765Full dual-path and Docker notes: Tailscale.
Clients:
Authorization: Bearer <OPENGATEWAY_AUTH_TOKEN>SSE cannot set headers easily. Use ?token= on the events URL, or paste the token in Settings.
| Variable | Meaning |
|---|---|
OPENGATEWAY_MODE |
internal or public
|
OPENGATEWAY_HOST / OPENGATEWAY_PORT
|
Bind (default port 8765) |
OPENGATEWAY_AUTH_TOKEN |
Bearer secret |
OPENGATEWAY_PUBLIC_URL |
Advertised base URL |
OPENGATEWAY_NETWORK |
tailscale, lan, or public
|
OPENGATEWAY_TAILSCALE_HOSTNAME |
MagicDNS override (Docker) |
OPENGATEWAY_CORS_ORIGINS |
Default *
|
Registry: GET/POST /v1/gateways, DELETE /v1/gateways/{id} for non-self cards.
Diagnose: opengateways doctor and GET /v1/network.
Canonical: docs/GATEWAYS.md.
OpenGateway v0.1.13 · Apache 2.0 · GitHub · docs.opengateways.xyz
Repo docs/ is the long-form source. This wiki tracks the same operator flows.
OpenGateway
Operate