Oten Access

OTEN GATEWAY

Enforce identity and device-aware access near the resource.

Oten Gateway protects private applications and services at the destination boundary. It applies versioned access policy using identity, qualified device, resource, and session context distributed by Oten Access.

System role: Resource-side Policy Enforcement Point

Evaluation depends on: Gateway behavior, rollout, and failover require implementation evidence by resource mode and failure domain.

Control Plane manages one Gateway Deployment. Profile A is assigned to separate Singapore and Dubai Data Plane Groups, whose compatible nodes form one explicit Failover Set. Profile B is assigned to the Vietnam Data Plane Group and remains outside that set.

One enforcement boundary, multiple protocol-specific modes.

Identity-aware reverse proxy

Internal web applications and APIs: federated identity, route policy, device context, session control, and explicit upstream identity propagation.

Explore Private App Access

Infrastructure access

SSH, databases, and Kubernetes: time-bound roles or certificates, resource scope, and protocol-specific audit.

Explore Privileged Access

Private network routing

Encrypted overlay and resource routes constrained by identity, device, protocol, port, and destination policy.

Explore connectivity

Centralized desired state. Distributed data path.

Control Plane

Owns desired state, versioned policy and configuration, signing, node enrollment, inventory, rollout, health, and audit.

Data Plane

Owns reverse proxy, routing, session handling, local enforcement, telemetry, and health near the protected resource.

Bounded independence

When Control Plane connectivity is interrupted, a node may continue only under signed last-known-good policy, configured TTL, and the applicable fail mode.

GROUP-SCOPED TOPOLOGY

Shared configuration does not automatically mean shared failover.

Control Plane manages one Gateway Deployment. Profile A is assigned to separate Singapore and Dubai Data Plane Groups, whose compatible nodes form one explicit Failover Set. Profile B is assigned to the Vietnam Data Plane Group and remains outside that set.

Gateway Deployment

The administrative boundary for an Oten Gateway installation.

Configuration Profile

Versioned desired state for listeners, routes, policy references, certificate or secret references, and telemetry.

Data Plane Group

A set of nodes assigned the same profile and rollout policy.

Failover Set

An explicit set of compatible nodes allowed to take over for one another.

Gateway Node

One running data-plane instance in a location and failure domain.

Saved, staged, and active are different configuration states.

  1. Author

    An administrator creates or updates a Configuration Profile.

  2. Validate

    Control Plane validates schema, references, compatibility, and target impact.

  3. Sign

    The artifact receives an immutable version, digest, audience binding, and signature.

  4. Target

    The administrator selects a Data Plane Group, canary or batch policy, and maintenance constraints.

  5. Stage

    Each node verifies the signature, stages the artifact, and performs preflight checks.

  6. Activate

    The node activates the configuration and reports health and the applied generation.

  7. Continue or roll back

    Rollout proceeds, pauses, or restores a valid last-known-good version according to policy.

  8. Audit

    Actor, version, group, node result, failure, and rollback reason are correlated.

Failover occurs only inside an eligible, compatible set.

Healthy / serving

The node is eligible and actively serving the configured resource path.

Degraded / draining

The node remains observable while traffic is reduced or removed safely.

Failover in progress

Ownership is moving inside the configured set; session behavior is mode-specific.

Config mismatch

The node is ineligible until profile, version, secrets, and runtime compatibility pass validation.

Split-brain risk

Fencing or ownership uncertainty blocks unsafe takeover and remains visible.

Control Plane unreachable

The node identifies last-known-good state, remaining lease, and the configured fail mode.

FAQ

Questions security and platform teams ask first.

Is Oten Gateway a relay?

No. Relay Service forwards encrypted fallback traffic when a direct path is not feasible. Oten Gateway understands resource routes and session policy and enforces access near the destination.

Does Data Plane Group membership automatically define failover?

No. A Data Plane Group is a configuration and rollout boundary. A Failover Set is a separate takeover boundary whose compatible members must be explicitly selected. Group or deployment membership alone never creates takeover authority.

Does Gateway stop immediately when the Control Plane is unreachable?

Behavior depends on resource criticality, signed configuration validity, authorization lease, and fail mode. The architecture supports bounded last-known-good behavior and converges toward a restrictive state when required trust or configuration expires.

Place enforcement near the resource without blurring failure boundaries.

Explore the private application flow, group-scoped topology, and the evidence requirements for Gateway availability behavior.