Install and Upgrade in Kubernetes

The instructions below cover the required steps to install and upgrade the Airlock Microgateway Operator in Kubernetes.

Prerequisites

A valid license is required to use Airlock Microgateway unless you use the Community Edition. To try premium features without first contacting a sales partner, request an evaluation license. For a comparison of the available editions, see Editions.

Request one of the following licenses

  • Request an evaluation license.

    • The license is sent automatically within a few minutes.
  • Request a premium license.

    • A sales partner will contact you to discuss licensing.

Install

Deploy Kubernetes Gateway API CRDs

Airlock Microgateway requires the Kubernetes Gateway API CRDs. To use incubating features, install the experimental channel. Otherwise, the standard channel.

​
1
kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.0/standard-install.yaml
1
kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.0/experimental-install.yaml
Info

More details, including release notes and upgrade information, can be found in the official Kubernetes Gateway API installation documentation.

Deploy Airlock Microgateway license

If you use the Community Edition, you can skip license deployment.

  1. Create the airlock-microgateway-system namespace:

    1
    
    kubectl create namespace airlock-microgateway-system
  2. Store the license in the Microgateway Operator namespace, in a Kubernetes secret with the name airlock-microgateway-license and the key microgateway-license.txt. Use the following command:

    1
    2
    3
    
    kubectl create secret generic airlock-microgateway-license \
      -n airlock-microgateway-system \
      --from-file=microgateway-license.txt=<path-to-your-local-microgateway-license.txt>
Notice

For more information about license monitoring, see Monitor Microgateway Licenses.

Deploy Airlock Microgateway Operator

  1. CRDs are included via the standard Helm 3 mechanism, i.e., Helm will handle initial installation but not upgrades.

    1
    2
    3
    4
    5
    
    helm install airlock-microgateway \
      oci://quay.io/airlockcharts/microgateway \
      --version 5.2.0 \
      --namespace airlock-microgateway-system \
      --wait
    Notice

    When using a Premium license, set license.mode to required. This ensures that gateways without a valid license are rejected, allowing missing or misconfigured licenses to be detected early. Use optional if you intentionally want the Operator to fall back to the Community Edition when no license is configured.

    The logs should show the message Thank you for installing Airlock Microgateway. ... including further information about successful installation.

What’s next

  1. Gateway Deployment
    • Deploy the gateway either as an Ingress or as an in-cluster Gateway.
  2. Session Handling
    • Enable session handling to persist session information and correlate requests with a session ID. This is a prerequisite for OIDC-based authentication.
  3. Configuration Guides
    • Learn how to use Airlock Microgateway for other typical scenarios such as request routing, request filtering or authentication enforcement.

Upgrade

The following instructions explain how to upgrade running Airlock Microgateway deployments to a newer version without interrupting service.

Notice
  • These instructions may not apply when upgrading to an Airlock Microgateway release that contains breaking changes. Additional upgrade steps may be required.
  • Do not add the --reuse-values flag to the helm upgrade command when upgrading to a different version of Airlock Microgateway/Helm charts. The flag would prevent updating some required settings and changes.
  1. For information on what to consider when upgrading the Gateway API CRDs, follow the instructions in the section Upgrading to a new version of the official CRD Management Guide of the Gateway API.

    In most cases, you can upgrade the CRDs using one of the following commands, depending on the installed Gateway API channel:

    ​
    1
    
    kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.0/standard-install.yaml
    1
    
    kubectl apply --server-side -f https://github.com/kubernetes-sigs/gateway-api/releases/download/v1.6.0/experimental-install.yaml
  2. Upgrade the Airlock Microgateway CRDs.

    1
    2
    3
    
    kubectl apply -k https://github.com/airlock/microgateway/deploy/charts/airlock-microgateway/crds/?ref=5.2.0 \
      --server-side \
      --force-conflicts
  3. Upgrade the Microgateway Operator.

    1
    2
    3
    4
    
    helm upgrade airlock-microgateway \
      oci://quay.io/airlockcharts/microgateway \
      --version '5.2.0' \
      --namespace airlock-microgateway-system

    You can verify the current Pod status by checking the version label.

External links: