Skip to content

Plans and entitlements

Gateway uses Community, Personal, Business, and Enterprise plans. Availability, commercial-use terms, Gateway deployment licensing, and separately hosted service quotas are different concepts.

Choose a plan from the operating requirements, not from organization size. Start with the workflows that must be supported, the resource limits they need, the security controls required by policy, and the support or commercial terms required by the buyer. The installation owner is responsible for monitoring license health; resource owners should know which operations depend on paid entitlements.

Ready paid features are enforced at the operation boundary as well as in the UI. Ordinary key expiry preserves existing configured infrastructure and enabled runtime modules while blocking new premium resources, paid-feature expansion, and paid-only operations after grace. An explicit deactivation, activation replacement, revocation, invalid key, or policy violation is an authoritative loss and can disable protected entry points. Grace periods and exact feature availability can change with product releases; review the current matrix before publication.

Community installations do not require a key. A Business or Enterprise key represents one active Gateway instance; resource quotas inside a Gateway instance must not be confused with separate Wiolett Cloud quotas.

Plan Typical capability boundary
Community Core ingress, Docker, external databases, monitoring, identity, automation, AI Workspace, Inference, and up to the documented Community resource limits
Personal Community plus managed databases, managed single-node Compose lifecycle, Pages, status pages, archive/migration operations, and unlimited documented core quotas
Business Personal plus multi-node Workload Availability (HA), Git push-to-deploy, isolated Build Workers, Secure Runtime, vulnerability admission, structured logging, audit export, and optional external registry access
Enterprise Business plus Internal PKI, SIEM audit export, enterprise identity roadmap capabilities, and dedicated commercial benefits

The exact feature matrix is release-specific. Product pages identify prerequisites and this page explains lifecycle behavior; pricing and contract terms belong to the applicable commercial agreement.

Feature Status Community Personal Business Enterprise
Infrastructure Node Management Ready ✅ ✅ ✅ ✅
Multi-Node Nginx Ingress Management Ready ✅ ✅ ✅ ✅
Docker Container Management — Default Runtime (runc) Ready ✅ ✅ ✅ ✅
External Compose Project Discovery, Monitoring, and Logs Ready ✅ ✅ ✅ ✅
Docker ↔ Nginx Secure Links Ready ✅ ✅ ✅ ✅
Private Gateway-Managed Internal Docker Registry Ready ✅ ✅ ✅ ✅
SSL/TLS Certificate Management Ready ✅ ✅ ✅ ✅
Domain and DNS Management Ready ✅ ✅ ✅ ✅
External Database Connections and Explorers Ready ✅ ✅ ✅ ✅
Infrastructure Monitoring Ready ✅ ✅ ✅ ✅
Physical GPU Discovery, Attachment, and Monitoring Ready ✅ ✅ ✅ ✅
Alerts and Webhook Notifications Ready ✅ ✅ ✅ ✅
Authentication, OIDC, and MFA Ready ✅ ✅ ✅ ✅
Folder- and Resource-Scoped Role-Based Access Control Ready ✅ ✅ ✅ ✅
Audit Log Ready ✅ ✅ ✅ ✅
REST API, OAuth, and MCP Automation Ready ✅ ✅ ✅ ✅
General Gateway CLI Expected in 2.13 ✅ ✅ ✅ ✅
GitLab Integration Ready ✅ ✅ ✅ ✅
AI Workspace, Plan Mode, Scenarios, and AI Sandboxes Ready, opt-in ✅ ✅ ✅ ✅
Gateway Inference Ready, opt-in ✅ ✅ ✅ ✅
Automated Installation and Signed Updates Ready ✅ ✅ ✅ ✅
Storage Connections: S3, R2, MinIO, FTP, FTPS, SFTP, and SMB Expected in 2.11 ✅ ✅ ✅ ✅
Gateway Configuration Export for Transfer to Another Instance Expected in 2.12 ✅ ✅ ✅ ✅
Managed Nodes Plan limit 100 Unlimited Unlimited Unlimited
Users Plan limit 10 Unlimited Unlimited Unlimited
Custom Permission Groups Plan limit 5 Unlimited Unlimited Unlimited
Support Level Service level Community Standard Priority Priority + Dedicated
Container Export and Import Ready — ✅ ✅ ✅
Blue/Green Deployments Ready — ✅ ✅ ✅
Cross-Node Container and Deployment Migration Ready — ✅ ✅ ✅
Managed Single-node Compose Deployment and Lifecycle Ready — ✅ ✅ ✅
Managed Databases with Secure Links Ready — ✅ ✅ ✅
Public Status Pages Ready, opt-in — ✅ ✅ ✅
Pages Ready — ✅ ✅ ✅
Automatic GitLab Container Registry Discovery Ready — ✅ ✅ ✅
Managed Database Backup and Restore Expected in 2.12 — ✅ ✅ ✅
Managed Storages with Secure Links Expected in 2.11 — ✅ ✅ ✅
Docker Secure Runtime (runsc/gVisor) Ready — — ✅ ✅
Git Repository Push-To-Deploy for Containers, Deployments, Compose, and Pages; Isolated Build Workers Ready — — ✅ ✅
External Docker-Client Access to the Internal Registry Ready, opt-in — — ✅ ✅
Multi-node Workload Availability (Container, Deployment, Compose) Ready — — ✅ ✅
Git Build Vulnerability Scanning and Admission Policy Ready — — ✅ ✅
Structured Logging Ready, opt-in — — ✅ ✅
Audit Log Export Ready — — ✅ ✅
Bastion / SSH Management Daemon Expected in 2.14 — — ✅ ✅
Broader Workload Vulnerability and Security Scanning In development — — ✅ ✅
Metric Autoscaling In development — — ✅ ✅
Multiple Instances of One Workload on One Machine In development — — ✅ ✅
Guided Onboarding and Configuration Review Plan benefit — — ✅ ✅
Internal PKI Ready — — — ✅
SIEM Audit Export Ready, opt-in — — — ✅
OIDC Group Mapping and SCIM Provisioning In development — — — ✅
Dedicated Technical Contact Plan benefit — — — ✅
Assisted Deployment and Migration Plan benefit — — — ✅

Workload Availability (HA) is available. Storage connections and managed storages are expected in 2.11; managed-database backup/restore and Gateway configuration export for transfer to another instance are expected in 2.12. External storage connections and configuration export are planned for all plans; managed storages and database backups follow managed databases on Personal and higher.

The general Gateway CLI for terminals and CI/CD is expected in 2.13 on every plan; this is not the existing Gateway Inference CLI. The Bastion / SSH management daemon is expected in 2.14 on Business and Enterprise. The plugin system is unfinished Gateway core infrastructure, not a plan feature; its tentative timing is no earlier than 2.20, with no committed release date.

In development and Expected in 2.x are future capabilities, not currently available operations. Checkmarks on future rows express intended plan inclusion; target versions are estimates. Metric autoscaling, same-node replicas, broader workload scanning, and OIDC group mapping/SCIM do not yet have target versions. Git build scanning is already available and is separate from broader workload scanning.

See Workload Availability for HA prerequisites and boundaries, and Updates and backups for current manual recovery procedures.

Ready paid features are enforced in backend operation boundaries as well as the Console. REST, OAuth, MCP, AI Workspace, background workers, and public token endpoints do not bypass entitlement checks.

Missing entitlement returns a permission-style failure without deleting existing resources. Reached plan quotas block creation while preserving current records. A protected policy inconsistency fails closed rather than guessing a more permissive plan.

After an ordinary key expiry, Gateway preserves existing premium resources, running services, data, published Pages deployments, and enabled runtime modules. It does not stop workloads, remove Routes, or switch off Internal PKI, SIEM, structured logging, or an already configured registry entry point merely because renewal was late. New premium resources, paid-feature expansion, and one-shot premium operations are blocked after the plan-specific grace period.

Existing Git-delivered workloads, source settings, build history, and internal-registry artifacts remain in place. New source builds and other paid-only automation stop until the required plan returns. Renewing the key restores full operations without rebuilding existing resources.

If the licensing service is unreachable, a previously valid paid installation uses its cached state for a 100-day technical offline-validation grace period measured from the last valid check. This connectivity grace does not extend a known subscription expiration deadline. After connectivity grace ends, new paid-only operations are blocked while existing configured infrastructure remains in place.

An authoritative loss is different from ordinary expiry. Explicit deactivation, transfer to another installation, revocation, an invalid key, or a policy violation may disable protected entry points and switchable modules while retaining stored configuration and resource data. This distinction prevents accidental renewal delays or a license-service outage from becoming a customer data-plane outage without weakening deliberate revocation.

  • Verify the installation ID and intended active instance before applying a key.
  • Monitor expiry and local grace deadline.
  • Test required premium operations before a production launch.
  • Record which services will stop accepting new work after downgrade.
  • Restore entitlement before manually replacing preserved resources.

Do not use old homelab terminology or infer feature availability from pricing copy, screenshots, or a different Gateway release.

Build a small decision record listing required capabilities, expected resource counts, environments, compliance controls, and the consequence if entitlement is temporarily unavailable. Test the actual operations on the target release before procurement approval. A feature name in a contract or matrix does not prove that the installation has the required Node capability or external provider.

Before downgrade, expiry, or transfer to another installation:

  1. identify premium resources and automation that will stop accepting new work;
  2. preserve source settings, build artifacts, PKI, logging, and SIEM configuration;
  3. confirm which running resources remain operational and whether the state is ordinary expiry or authoritative loss;
  4. communicate the operational deadline and owner;
  5. restore entitlement and explicitly re-enable switchable services where required;
  6. verify customer paths rather than assuming the previous configuration resumed.

Do not delete preserved resources to “clean up” an entitlement warning. Their retained state is the recovery path after the correct plan returns.

The Gateway license covers the active Gateway installation according to its key and agreement. Credentials, quotas, or subscriptions for external providers—cloud DNS, source control, registries, email, AI, or other hosted services—remain separate. Likewise, usage shown by Gateway Inference is operational accounting and should be reconciled with the provider for commercial decisions.

The current source published by Square Labs is available under PolyForm Perimeter 1.0.1. PolyForm Perimeter permits use, modification, and redistribution for noncompeting purposes, including ordinary internal business use. The excluded purpose is providing others with a product marketed as a substitute for Gateway, whether as software, a hosted service, a port, or a free offering.

A Personal, Business, or Enterprise key unlocks paid-plan features and limits; it is not required merely because an organization uses Community internally. An ordinary key does not grant OEM, white-label, resale, competing hosted-service, or other substitute-product rights. Those uses require a separate written agreement with the current Licensor. After ordinary key expiry, the key’s continuity terms preserve paid-plan resources configured before expiry while blocking new paid-only creation and expansion.

Every official release also carries the Product Continuity MIT Grant, a source-continuity backstop for covered Square Labs code. The grant itself is the authoritative source for its scope, conditions, exclusions, and any MIT transition.