Skip to content

The gateway: pre-publish

Pre-publishing means: the app still runs on your Mac, but testers and customers can already open it at a public address. You find out what people think before you pay for it to run in the cloud.

The gateway is a small server in your own cloud account. ownpaas creates it, keeps it up to date and deletes it when you no longer need it. It has:

  • a public IPv4 address that stays the same when the server behind it is replaced;
  • an encrypted WireGuard tunnel to your Mac, so requests to the public address reach the app in your lab;
  • shared ingress for clusters in the cloud: several clusters can share the gateway’s address instead of each paying for a load balancer;
  • edge protection: a login in front of the app through your identity provider (OpenID Connect), and rate limits per address, per token and per route.

Because the gateway runs in your account, the traffic of your testers goes to your server and your Mac, not through a service run by someone else.

The gateway is one small cloud server and one IPv4 address in your account, billed by your cloud provider: a few euros a month. The app will show the price before it creates the gateway.

The ownpaas licence does not cover these costs, and ownpaas does not add anything to them.

  1. Create the gateway. KUBERNETES › Gateways › Create Gateway…: pick your cloud account, a location and a name.
  2. Connect your Mac. Add Peer… creates a WireGuard key pair on your Mac. Only the public key leaves the Mac; the private key is shown once (as a file to save, or a QR code) and never stored by the app.
  3. Forward the app. Forward Ports… sends traffic for the chosen ports from the gateway’s public address through the tunnel to your Mac.
  4. Protect it (in development). Put a login in front and set rate limits, so only the people you invite get in.

Allow-list and peer changes apply without interrupting traffic. Some other changes replace the gateway’s server; while that happens (about 90 seconds), traffic through the gateway pauses and the tunnel reconnects. The app says so before you confirm.

The same gateway can serve the clusters you create with Move to Cloud: their ingress moves from your Mac to the cluster in your account, and the address your testers use can stay the same.