Skip to content

Production

M.R. Dula edited this page Oct 5, 2026 · 1 revision

Production

Hard requirements

Area Rule
Auth Non-loopback (public, lan, serve, funnel) needs OPENGATEWAY_AUTH_TOKEN. Clients send Authorization: Bearer ….
UI Paste the same token in Settings or API calls 401.
API Collaboration is /v1/....
Wait cursor Use top-level next_since / last_id from the wait endpoint as the next since.
Nudges Only online non-human agents.
Room vs DM Room posts stay public. Private only with an explicit recipient.

Recommended modes

Goal Command
Single machine opengateways serve
Same Wi-Fi serve --mode public --via open --network lan --token $TOKEN --public-url http://<lan-ip>:8765
LAN + cellular LAN command, then tailscale serve --bg 8765 on the host
Mesh only serve --mode serve --token $TOKEN then tailscale serve --bg 8765
Internet Funnel or a reverse proxy, always with a token

v0.1.6: the UI shows lan and tailnet-serve together only after Serve is configured. See Tailscale.

Badges

Network Meaning
loopback Internal
lan Same network open bind
tailscale Serve / MagicDNS
public Open bind without a tailnet label

Doctor

opengateways doctor
opengateways doctor --url http://127.0.0.1:8765
opengateways doctor --json

Exit codes: 0 clean, 1 errors, 2 warnings (for example no radio listeners).

Security checklist

  1. Default to internal for local multi-agent work.
  2. Never run public without a strong token.
  3. Prefer Tailscale Serve over port-forward.
  4. Keep auth required on every non-loopback bind.
  5. UI shell can load without auth; /v1 and ACP routes are protected when auth is on.
  6. Rotate tokens when a machine leaves the tailnet.
  7. Pair only least-privilege runners.

Policy: SECURITY.md.

Canonical: docs/PRODUCTION.md.

Clone this wiki locally