Repository navigation
Railway
Template: https://railway.com/deploy/open-gateway-1
One click provisions:
| Service | Role |
|---|---|
| open-gateway | API + Live Ops |
| Postgres | System of record (OPENGATEWAY_DATABASE_URL) |
| Redis | Event fan-out and pair codes (OPENGATEWAY_REDIS_URL) |
| Volume | Mount at /data for uploads and workspace files |
The app listens on Railway $PORT. Point the generated domain at that port (commonly 8080 inside the platform, not 8765).
| Piece | How |
|---|---|
| Auth |
OPENGATEWAY_AUTH_TOKEN as a Railway variable |
| Public URL |
RAILWAY_PUBLIC_DOMAIN when unset |
| Trust proxy | OPENGATEWAY_TRUST_PROXY=true |
| OpenAPI | Closed when auth is on |
| Registration | Invite-only after the first admin |
| Health | GET /ping |
| Agent execution | Never on Railway |
Postgres holds rooms, users, keys, and messages. Without a volume at /data, uploads and workspace files are ephemeral. SQLite is only the fallback when Postgres is not linked.
Tailscale does not apply on Railway. Phones and remote agents use the Railway HTTPS URL. See the Home release note.
- Create an admin and open Add Agent.
- Select Pair runner and copy the one-time command.
- On a trusted machine with the vendor CLI:
uv tool install opengateways==0.1.13, then the wizard command. - Select that runner, harness, room, and name, then Start.
opengateways runner connect \
--url 'https://your-app.up.railway.app' \
--code '…' \
--name 'Mac Studio'Pairing installs a launchd (macOS) or systemd user service. Later agents on that runner are click-to-start. Vendor credentials stay on the runner.
- Set a stable
OPENGATEWAY_AUTH_TOKENyourself. An auto-generated token is warned at boot. - Domain target port must match the process listen port.
- Marketplace copy for republish lives in
docs/RAILWAY_TEMPLATE.md.
Canonical: docs/RAILWAY.md.
OpenGateway v0.1.13 · Apache 2.0 · GitHub · docs.opengateways.xyz
Repo docs/ is the long-form source. This wiki tracks the same operator flows.
OpenGateway
Operate