Skip to main content
A project can have several gateways. All of them enforce the project’s one policy and share approvals and taint: an agent tainted on one is tainted on all.

Another network or region

When a database lives where your first gateway can’t reach it, run a second gateway there: Gateways, Set up another gateway, and run its commands in that network.
  • Its config lists every database of the project. Delete the ones it can’t reach before you start it.
  • A database can be served by more than one gateway. List it in each config.
  • An agent connects to one gateway. For databases behind two, add each gateway to the agent as its own MCP server and sign in to each.

Replicas

For availability, run several processes of one gateway behind one URL. They share one identity (enroll once with midplane enroll, as on platforms without a disk), and each keeps its own audit file. A new enrollment token always makes a new gateway, so don’t use one for a replica. More in linked mode.

Adding databases

1

Add it in the dashboard

+ Add database under Databases, with its id.
2

Add it to the gateway's config

Copy a line under databases: and change the id in both places, then write the connection string to the file the new line names:
In Docker, the paths start with /etc/midplane/secrets/, and secrets/ belongs to the container’s user: write the file with sudo, then run the sudo sh -c '…' line from the start block again.
3

Restart the gateway

On your machine, stop it with Ctrl-C and start it again; in Docker, run docker restart midplane-gw-…. It reads the new database’s tables, and the policy editor shows them.
If you change the config first, the gateway still starts: on Gateways its line reads billing · in its config, not in this project. Add beside it adds the database with its id filled in, and the gateway sends its tables within seconds.