Requirements and Limitations

Ensure that the following requirements are met to run Airlock Microgateway successfully. A valid license is required unless Airlock Microgateway is used in the Community Edition.

Compatibility overview

The following table shows the general version range of different platforms Airlock Microgateway supports.

Platform Supported version range Official manufacturer documentation
Kubernetes 1.34 – 1.37 Kubernetes changelog list on GitHub
OpenShift 4.18 – 4.22 The link below opens the latest OpenShift release notes. To access the release notes of a different version, use the selector drop-down menu on the page.
OpenShift Container Platform release notes

Kubernetes Gateway API support

Version Description
  • 1.2 – 1.6 (standard channel)
  • 1.6 (experimental channel)1

1 The Kubernetes Gateway API experimental channel is only required for some incubating features. See article Release Notes and Incubating Features.

Additional components

Airlock Microgateway can run without additional components. However, specific features require additional software to be available.

Session handling

Session handling requires either Redis or Valkey as a session store.
For configuration, see Session Handling.

Component Tested versions Description
Redis 7.2, 7.4, 8.4, 8.6, 8.8, 8.10 Redis documentation
Valkey 7.2, 8.0, 8.1, 9.0, 9.1 Valkey documentation

Dashboards

Airlock Microgateway can automatically provision dashboards to your Grafana instance.
For configuration, see Grafana Dashboards.

Component Tested versions Description
Grafana 13.x Grafana documentation

Network communication

The following network communication is required:

From To To port To protocol
Microgateway Engine Container
  • Label Selector:
    gateway.networking.k8s.io/gateway-name=<Gateway Name>
  • Namespace:
    <Gateway Namespace>
Microgateway Operator Container
  • Default Label Selector:
    app.kubernetes.io/name=microgateway-operator
  • Default Namespace:
    airlock-microgateway-system
13377, 8082 TCP
Microgateway Session Agent Container
  • Label Selector:
    gateway.networking.k8s.io/gateway-name=<Gateway Name>
  • Namespace:
    <Gateway Namespace>
Valkey or Redis
Check your deployment’s namespace and label selectors.

Default ports:

  • Cluster: 6379
  • Standalone: 6379
  • Sentinel: 26379
TCP
Notice
  • The Engine resolves the headless Service via kube-dns, so egress to kube-system/k8s-app=kube-dns on TCP/UDP 53 is also required.
  • Communication with Redis or Valkey is required only when Session Handling is enabled.

Limitations

  • Mixing different versions like Airlock Microgateway Operator in version 5.x and Microgateway Engine in version 5.y is not supported.
  • WebSocket support is limited to HTTP/1.1.