Integrations
Integrations connect Gateway to accounts and hosts you already control. Start in Settings > Integrations. The available actions depend on your Gateway permissions, plan, and the credentials accepted by the external system.
Choose the connection
Section titled “Choose the connection”| Goal | Integration | Continue with |
|---|---|---|
| Create and operate provider VMs | Hosting providers: Proxmox VE, DigitalOcean, Hetzner Cloud, HOSTKEY | Add a node |
| Select repositories for builds or source operations | Git hosting: GitLab, GitHub, generic Git | Docker builds, Pages Git deployments |
| Reach a named external host over SSH | SSH connections | Trusted host access and eligible hosting installation |
| Discover DNS zones and manage DNS for Domains and certificates | Cloudflare | Domains, Routes, and TLS |
Container registries are configured in the Docker area; Git integrations can also discover eligible registries. Email and webhooks have their own delivery settings. API and MCP connect tools to Gateway, rather than connecting Gateway to a hosting or Git account.
Three independent access checks
Section titled “Three independent access checks”- Gateway permissions: who may view or administer the connector and act on the selected resource.
- Connector selection: which accounts, repositories, zones, hosts, or allocation pools that connection covers.
- External credentials: what the provider token or remote operating-system account actually permits.
Being a Gateway system administrator does not give a Proxmox API token or SSH account more privileges. Conversely, an administrator token at the provider does not grant a Gateway user permission to every resource. See Permissions.
Connect, verify, and maintain
Section titled “Connect, verify, and maintain”Use a dedicated credential, verify TLS or SSH host identity, and restrict access before enabling automation. A successful connection test establishes connectivity and the capabilities that were checked; it does not prove that a VM was provisioned, a build deployed, or a DNS change reached clients.
Before rotating, disabling, or deleting a connection, identify dependent nodes, source bindings, registries, Domains, and certificates. Verify the replacement with the corresponding workflow. Do not paste provider tokens or private keys into chat, URLs, screenshots, or logs.
