Identity-aware reverse proxy
Internal web applications and APIs: federated identity, route policy, device context, session control, and explicit upstream identity propagation.
Explore Private App Access →OTEN GATEWAY
Oten Gateway protects private applications and services at the destination boundary. It applies versioned access policy using identity, qualified device, resource, and session context distributed by Oten Access.
System role: Resource-side Policy Enforcement Point
Evaluation depends on: Gateway behavior, rollout, and failover require implementation evidence by resource mode and failure domain.
Internal web applications and APIs: federated identity, route policy, device context, session control, and explicit upstream identity propagation.
Explore Private App Access →SSH, databases, and Kubernetes: time-bound roles or certificates, resource scope, and protocol-specific audit.
Explore Privileged Access →Approval, credential injection, vault integration, session recording, and command or session policy.
Explore Privileged Access →Encrypted overlay and resource routes constrained by identity, device, protocol, port, and destination policy.
Explore connectivity →Owns desired state, versioned policy and configuration, signing, node enrollment, inventory, rollout, health, and audit.
Owns reverse proxy, routing, session handling, local enforcement, telemetry, and health near the protected resource.
When Control Plane connectivity is interrupted, a node may continue only under signed last-known-good policy, configured TTL, and the applicable fail mode.
GROUP-SCOPED TOPOLOGY
The administrative boundary for an Oten Gateway installation.
Versioned desired state for listeners, routes, policy references, certificate or secret references, and telemetry.
A set of nodes assigned the same profile and rollout policy.
An explicit set of compatible nodes allowed to take over for one another.
One running data-plane instance in a location and failure domain.
An administrator creates or updates a Configuration Profile.
Control Plane validates schema, references, compatibility, and target impact.
The artifact receives an immutable version, digest, audience binding, and signature.
The administrator selects a Data Plane Group, canary or batch policy, and maintenance constraints.
Each node verifies the signature, stages the artifact, and performs preflight checks.
The node activates the configuration and reports health and the applied generation.
Rollout proceeds, pauses, or restores a valid last-known-good version according to policy.
Actor, version, group, node result, failure, and rollback reason are correlated.
The node is eligible and actively serving the configured resource path.
The node remains observable while traffic is reduced or removed safely.
Ownership is moving inside the configured set; session behavior is mode-specific.
The node is ineligible until profile, version, secrets, and runtime compatibility pass validation.
Fencing or ownership uncertainty blocks unsafe takeover and remains visible.
The node identifies last-known-good state, remaining lease, and the configured fail mode.
FAQ
No. Relay Service forwards encrypted fallback traffic when a direct path is not feasible. Oten Gateway understands resource routes and session policy and enforces access near the destination.
No. A Data Plane Group is a configuration and rollout boundary. A Failover Set is a separate takeover boundary whose compatible members must be explicitly selected. Group or deployment membership alone never creates takeover authority.
Behavior depends on resource criticality, signed configuration validity, authorization lease, and fail mode. The architecture supports bounded last-known-good behavior and converges toward a restrictive state when required trust or configuration expires.
Next in Oten Access
Explore the private application flow, group-scoped topology, and the evidence requirements for Gateway availability behavior.