Plans and entitlements
Gateway uses Community, Personal, Business, and Enterprise plans. Availability, commercial-use terms, Gateway deployment licensing, and separately hosted service quotas are different concepts.
Choose a plan from the operating requirements, not from organization size. Start with the workflows that must be supported, the resource limits they need, the security controls required by policy, and the support or commercial terms required by the buyer. The installation owner is responsible for monitoring license health; resource owners should know which operations depend on paid entitlements.
Ready paid features are enforced at the operation boundary as well as in the UI. Ordinary key expiry preserves existing configured infrastructure and enabled runtime modules while blocking new premium resources, paid-feature expansion, and paid-only operations after grace. An explicit deactivation, activation replacement, revocation, invalid key, or policy violation is an authoritative loss and can disable protected entry points. Grace periods and exact feature availability can change with product releases; review the current matrix before publication.
Community installations do not require a key. A Business or Enterprise key represents one active Gateway instance; resource quotas inside a Gateway instance must not be confused with separate Wiolett Cloud quotas.
Plan progression
Section titled “Plan progression”| Plan | Typical capability boundary |
|---|---|
| Community | Core ingress, Docker, external databases, monitoring, identity, automation, AI Workspace, Inference, and up to the documented Community resource limits |
| Personal | Community plus managed databases, managed single-node Compose lifecycle, Pages, status pages, archive/migration operations, and unlimited documented core quotas |
| Business | Personal plus multi-node Workload Availability (HA), Git push-to-deploy, isolated Build Workers, Secure Runtime, vulnerability admission, structured logging, audit export, and optional external registry access |
| Enterprise | Business plus Internal PKI, SIEM audit export, enterprise identity roadmap capabilities, and dedicated commercial benefits |
The exact feature matrix is release-specific. Product pages identify prerequisites and this page explains lifecycle behavior; pricing and contract terms belong to the applicable commercial agreement.
Feature matrix
Section titled “Feature matrix”| Feature | Status | Community | Personal | Business | Enterprise |
|---|---|---|---|---|---|
| Infrastructure Node Management | Ready | ✅ | ✅ | ✅ | ✅ |
| Multi-Node Nginx Ingress Management | Ready | ✅ | ✅ | ✅ | ✅ |
Docker Container Management — Default Runtime (runc) |
Ready | ✅ | ✅ | ✅ | ✅ |
| External Compose Project Discovery, Monitoring, and Logs | Ready | ✅ | ✅ | ✅ | ✅ |
| Docker ↔ Nginx Secure Links | Ready | ✅ | ✅ | ✅ | ✅ |
| Private Gateway-Managed Internal Docker Registry | Ready | ✅ | ✅ | ✅ | ✅ |
| SSL/TLS Certificate Management | Ready | ✅ | ✅ | ✅ | ✅ |
| Domain and DNS Management | Ready | ✅ | ✅ | ✅ | ✅ |
| External Database Connections and Explorers | Ready | ✅ | ✅ | ✅ | ✅ |
| Infrastructure Monitoring | Ready | ✅ | ✅ | ✅ | ✅ |
| Physical GPU Discovery, Attachment, and Monitoring | Ready | ✅ | ✅ | ✅ | ✅ |
| Alerts and Webhook Notifications | Ready | ✅ | ✅ | ✅ | ✅ |
| Authentication, OIDC, and MFA | Ready | ✅ | ✅ | ✅ | ✅ |
| Folder- and Resource-Scoped Role-Based Access Control | Ready | ✅ | ✅ | ✅ | ✅ |
| Audit Log | Ready | ✅ | ✅ | ✅ | ✅ |
| REST API, OAuth, and MCP Automation | Ready | ✅ | ✅ | ✅ | ✅ |
| General Gateway CLI | Expected in 2.13 | ✅ | ✅ | ✅ | ✅ |
| GitLab Integration | Ready | ✅ | ✅ | ✅ | ✅ |
| AI Workspace, Plan Mode, Scenarios, and AI Sandboxes | Ready, opt-in | ✅ | ✅ | ✅ | ✅ |
| Gateway Inference | Ready, opt-in | ✅ | ✅ | ✅ | ✅ |
| Automated Installation and Signed Updates | Ready | ✅ | ✅ | ✅ | ✅ |
| Storage Connections: S3, R2, MinIO, FTP, FTPS, SFTP, and SMB | Expected in 2.11 | ✅ | ✅ | ✅ | ✅ |
| Gateway Configuration Export for Transfer to Another Instance | Expected in 2.12 | ✅ | ✅ | ✅ | ✅ |
| Managed Nodes | Plan limit | 100 | Unlimited | Unlimited | Unlimited |
| Users | Plan limit | 10 | Unlimited | Unlimited | Unlimited |
| Custom Permission Groups | Plan limit | 5 | Unlimited | Unlimited | Unlimited |
| Support Level | Service level | Community | Standard | Priority | Priority + Dedicated |
| Container Export and Import | Ready | — | ✅ | ✅ | ✅ |
| Blue/Green Deployments | Ready | — | ✅ | ✅ | ✅ |
| Cross-Node Container and Deployment Migration | Ready | — | ✅ | ✅ | ✅ |
| Managed Single-node Compose Deployment and Lifecycle | Ready | — | ✅ | ✅ | ✅ |
| Managed Databases with Secure Links | Ready | — | ✅ | ✅ | ✅ |
| Public Status Pages | Ready, opt-in | — | ✅ | ✅ | ✅ |
| Pages | Ready | — | ✅ | ✅ | ✅ |
| Automatic GitLab Container Registry Discovery | Ready | — | ✅ | ✅ | ✅ |
| Managed Database Backup and Restore | Expected in 2.12 | — | ✅ | ✅ | ✅ |
| Managed Storages with Secure Links | Expected in 2.11 | — | ✅ | ✅ | ✅ |
Docker Secure Runtime (runsc/gVisor) |
Ready | — | — | ✅ | ✅ |
| Git Repository Push-To-Deploy for Containers, Deployments, Compose, and Pages; Isolated Build Workers | Ready | — | — | ✅ | ✅ |
| External Docker-Client Access to the Internal Registry | Ready, opt-in | — | — | ✅ | ✅ |
| Multi-node Workload Availability (Container, Deployment, Compose) | Ready | — | — | ✅ | ✅ |
| Git Build Vulnerability Scanning and Admission Policy | Ready | — | — | ✅ | ✅ |
| Structured Logging | Ready, opt-in | — | — | ✅ | ✅ |
| Audit Log Export | Ready | — | — | ✅ | ✅ |
| Bastion / SSH Management Daemon | Expected in 2.14 | — | — | ✅ | ✅ |
| Broader Workload Vulnerability and Security Scanning | In development | — | — | ✅ | ✅ |
| Metric Autoscaling | In development | — | — | ✅ | ✅ |
| Multiple Instances of One Workload on One Machine | In development | — | — | ✅ | ✅ |
| Guided Onboarding and Configuration Review | Plan benefit | — | — | ✅ | ✅ |
| Internal PKI | Ready | — | — | — | ✅ |
| SIEM Audit Export | Ready, opt-in | — | — | — | ✅ |
| OIDC Group Mapping and SCIM Provisioning | In development | — | — | — | ✅ |
| Dedicated Technical Contact | Plan benefit | — | — | — | ✅ |
| Assisted Deployment and Migration | Plan benefit | — | — | — | ✅ |
Workload Availability (HA) is available. Storage connections and managed storages are expected in 2.11; managed-database backup/restore and Gateway configuration export for transfer to another instance are expected in 2.12. External storage connections and configuration export are planned for all plans; managed storages and database backups follow managed databases on Personal and higher.
The general Gateway CLI for terminals and CI/CD is expected in 2.13 on every plan; this is not the existing Gateway Inference CLI. The Bastion / SSH management daemon is expected in 2.14 on Business and Enterprise. The plugin system is unfinished Gateway core infrastructure, not a plan feature; its tentative timing is no earlier than 2.20, with no committed release date.
In development and Expected in 2.x are future capabilities, not currently available operations. Checkmarks on future rows express intended plan inclusion; target versions are estimates. Metric autoscaling, same-node replicas, broader workload scanning, and OIDC group mapping/SCIM do not yet have target versions. Git build scanning is already available and is separate from broader workload scanning.
See Workload Availability for HA prerequisites and boundaries, and Updates and backups for current manual recovery procedures.
Enforcement
Section titled “Enforcement”Ready paid features are enforced in backend operation boundaries as well as the Console. REST, OAuth, MCP, AI Workspace, background workers, and public token endpoints do not bypass entitlement checks.
Missing entitlement returns a permission-style failure without deleting existing resources. Reached plan quotas block creation while preserving current records. A protected policy inconsistency fails closed rather than guessing a more permissive plan.
Downgrade and expiry
Section titled “Downgrade and expiry”After an ordinary key expiry, Gateway preserves existing premium resources, running services, data, published Pages deployments, and enabled runtime modules. It does not stop workloads, remove Routes, or switch off Internal PKI, SIEM, structured logging, or an already configured registry entry point merely because renewal was late. New premium resources, paid-feature expansion, and one-shot premium operations are blocked after the plan-specific grace period.
Existing Git-delivered workloads, source settings, build history, and internal-registry artifacts remain in place. New source builds and other paid-only automation stop until the required plan returns. Renewing the key restores full operations without rebuilding existing resources.
If the licensing service is unreachable, a previously valid paid installation uses its cached state for a 100-day technical offline-validation grace period measured from the last valid check. This connectivity grace does not extend a known subscription expiration deadline. After connectivity grace ends, new paid-only operations are blocked while existing configured infrastructure remains in place.
An authoritative loss is different from ordinary expiry. Explicit deactivation, transfer to another installation, revocation, an invalid key, or a policy violation may disable protected entry points and switchable modules while retaining stored configuration and resource data. This distinction prevents accidental renewal delays or a license-service outage from becoming a customer data-plane outage without weakening deliberate revocation.
Operational checks
Section titled “Operational checks”- Verify the installation ID and intended active instance before applying a key.
- Monitor expiry and local grace deadline.
- Test required premium operations before a production launch.
- Record which services will stop accepting new work after downgrade.
- Restore entitlement before manually replacing preserved resources.
Do not use old homelab terminology or infer feature availability from pricing copy, screenshots, or a different Gateway release.
Choosing and changing a plan
Section titled “Choosing and changing a plan”Build a small decision record listing required capabilities, expected resource counts, environments, compliance controls, and the consequence if entitlement is temporarily unavailable. Test the actual operations on the target release before procurement approval. A feature name in a contract or matrix does not prove that the installation has the required Node capability or external provider.
Before downgrade, expiry, or transfer to another installation:
- identify premium resources and automation that will stop accepting new work;
- preserve source settings, build artifacts, PKI, logging, and SIEM configuration;
- confirm which running resources remain operational and whether the state is ordinary expiry or authoritative loss;
- communicate the operational deadline and owner;
- restore entitlement and explicitly re-enable switchable services where required;
- verify customer paths rather than assuming the previous configuration resumed.
Do not delete preserved resources to “clean up” an entitlement warning. Their retained state is the recovery path after the correct plan returns.
Licensing boundaries
Section titled “Licensing boundaries”The Gateway license covers the active Gateway installation according to its key and agreement. Credentials, quotas, or subscriptions for external providers—cloud DNS, source control, registries, email, AI, or other hosted services—remain separate. Likewise, usage shown by Gateway Inference is operational accounting and should be reconciled with the provider for commercial decisions.
The current source published by Square Labs is available under PolyForm Perimeter 1.0.1. PolyForm Perimeter permits use, modification, and redistribution for noncompeting purposes, including ordinary internal business use. The excluded purpose is providing others with a product marketed as a substitute for Gateway, whether as software, a hosted service, a port, or a free offering.
A Personal, Business, or Enterprise key unlocks paid-plan features and limits; it is not required merely because an organization uses Community internally. An ordinary key does not grant OEM, white-label, resale, competing hosted-service, or other substitute-product rights. Those uses require a separate written agreement with the current Licensor. After ordinary key expiry, the key’s continuity terms preserve paid-plan resources configured before expiry while blocking new paid-only creation and expansion.
Every official release also carries the Product Continuity MIT Grant, a source-continuity backstop for covered Square Labs code. The grant itself is the authoritative source for its scope, conditions, exclusions, and any MIT transition.
