Install and Upgrade in Kubernetes
The instructions below cover the required steps to install and upgrade the Airlock Microgateway Operator in Kubernetes.
Prerequisites
A valid license is required to use Airlock Microgateway unless you use the Community Edition. To try premium features without first contacting a sales partner, request an evaluation license. For a comparison of the available editions, see Editions.
Request one of the following licenses
-
Request an evaluation license.
- The license is sent automatically within a few minutes.
-
Request a premium license.
- A sales partner will contact you to discuss licensing.
Install
Deploy Kubernetes Gateway API CRDs
Airlock Microgateway requires the Kubernetes Gateway API CRDs. To use incubating features, install the experimental channel. Otherwise, the standard channel.
Info
More details, including release notes and upgrade information, can be found in the official Kubernetes Gateway API installation documentation.
Deploy Airlock Microgateway license
If you use the Community Edition, you can skip license deployment.
-
Create the
airlock-microgateway-systemnamespace: -
Store the license in the Microgateway Operator namespace, in a Kubernetes secret with the name
airlock-microgateway-licenseand the keymicrogateway-license.txt. Use the following command:
Notice
For more information about license monitoring, see Monitor Microgateway Licenses.
Deploy Airlock Microgateway Operator
-
CRDs are included via the standard Helm 3 mechanism, i.e., Helm will handle initial installation but not upgrades.
Notice
When using a Premium license, set
license.modetorequired. This ensures that gateways without a valid license are rejected, allowing missing or misconfigured licenses to be detected early. Useoptionalif you intentionally want the Operator to fall back to the Community Edition when no license is configured.The logs should show the message
Thank you for installing Airlock Microgateway. ...including further information about successful installation.
What’s next
- Gateway Deployment
- Deploy the gateway either as an Ingress or as an in-cluster Gateway.
- Session Handling
- Enable session handling to persist session information and correlate requests with a session ID. This is a prerequisite for OIDC-based authentication.
- Configuration Guides
- Learn how to use Airlock Microgateway for other typical scenarios such as request routing, request filtering or authentication enforcement.
Upgrade
The following instructions explain how to upgrade running Airlock Microgateway deployments to a newer version without interrupting service.
Notice
- These instructions may not apply when upgrading to an Airlock Microgateway release that contains breaking changes. Additional upgrade steps may be required.
- Before upgrading, review the release notes published on GitHub.
- Do not add the
--reuse-valuesflag to thehelm upgradecommand when upgrading to a different version of Airlock Microgateway/Helm charts. The flag would prevent updating some required settings and changes.
-
For information on what to consider when upgrading the Gateway API CRDs, follow the instructions in the section Upgrading to a new version of the official CRD Management Guide of the Gateway API.
In most cases, you can upgrade the CRDs using one of the following commands, depending on the installed Gateway API channel:
-
Upgrade the Airlock Microgateway CRDs.
-
Upgrade the Microgateway Operator.
You can verify the current Pod status by checking the
versionlabel.
Further information and links
External links: