Deployment on your own terms
Regulated, sovereign, and security-sensitive environments dictate where infrastructure can run and who is allowed to operate it. A control point that only exists as someone else’s hosted service is a non-starter when data cannot leave your network, or when your own team has to hold the keys.
What you can do
- Run fully on-premises on bare metal or your own cloud instance so that data and keys never leave infrastructure you control.
- Deploy as a container so that the gateway drops into your existing Docker or orchestration workflow.
- Use a managed Affinidi appliance so that Affinidi runs the infrastructure while you administer policy and identity through the dashboard.
- Operate in restricted or air-gapped networks so that the gateway works with no dependence on public internet access.
- Run active and standby instances with leader election so that a failover keeps the control point available.
How it works
The gateway ships as a single binary and a container image, so the same build runs on bare metal, in a cloud instance, or under Docker; a managed appliance is that same software operated by Affinidi and administered through the dashboard. Wherever it runs, it sits in the request path as a reverse proxy between your callers and their destination services, so the deployment model never changes how traffic is governed.
For availability, instances coordinate through a failover store (filesystem for a single host, DynamoDB for a multi-instance cluster) and elect one leader. Two endpoints drive orchestration: GET /api/v1/alive is a liveness probe that returns 200 once the process is up, and GET /api/v1/health is a readiness probe that returns 200 on the leader and 503 Service Unavailable on a standby, so a load balancer routes only to the active instance. To connect across a network boundary without opening inbound ports, a gateway reaches a cloud-hosted mediator over an outbound connection.
If the leader becomes unavailable, a standby wins the election and its /api/v1/health flips to 200, so the load balancer moves traffic to it without operator action.
Related
- Deploy an Agent Gateway appliance: Provision a managed instance through the Affinidi Portal.
- Architecture: How the gateway’s layers and components fit together across deployment models.
- Gateways: How gateway-to-gateway connections span network zones and organisations.
- DIDComm messaging: The outbound mediator model that lets isolated zones connect without inbound ports.
Glad to hear it! Please tell us how we can improve more.
Sorry to hear that. Please tell us how we can improve.
Thank you for sharing your feedback so we can improve your experience.