Cloud and BYOC for Orca Agent Engine are in Private Preview — request an invite
Docs

Install the gateway

Install Orca AI Gateway from its public container image or Helm chart.

Orca AI Gateway ships as a Docker image and an OCI Helm chart. The instructions on this page pin the current release, 0.4.3.

Container image

The release image is docker.io/streamnative/orca-ai-gateway:0.4.3, built on debian:13-slim for linux/amd64 and linux/arm64. The same image is published as ghcr.io/orca-ae/orca-ai-gateway:0.4.3. It exposes 8080 (data plane) and 9099 (admin plane), runs as the non-root UID 65532, and defaults to run --config /etc/orca-gateway/config.yaml.

First write the config.yaml in the quickstart, then check it:

Check the configuration
docker run --rm \
  -v "$PWD/config.yaml:/etc/orca-gateway/config.yaml:ro" \
  docker.io/streamnative/orca-ai-gateway:0.4.3 \
  check /etc/orca-gateway/config.yaml
Run the gateway
docker run --rm \
  -p 127.0.0.1:8080:8080 -p 127.0.0.1:9099:9099 \
  -v "$PWD/config.yaml:/etc/orca-gateway/config.yaml:ro" \
  -e OPENAI_API_KEY \
  docker.io/streamnative/orca-ai-gateway:0.4.3

Set OPENAI_API_KEY before starting the container. The published image includes the orca-gateway CLI; the check command does not need a provider key. See Releases for the image digest.

Kubernetes with Helm

Install the OCI chart. The chart pulls the GHCR copy of the image by default; set image.repository and image.tag to pull from Docker Hub instead:

Install the release chart
helm install orca-ai-gateway oci://ghcr.io/orca-ae/charts/orca-ai-gateway \
  --version 0.4.3 --namespace orca-system --create-namespace \
  --set image.repository=docker.io/streamnative/orca-ai-gateway \
  --set image.tag=0.4.3

The chart starts three replicas by default. On a single-node development cluster, add --set replicaCount=1 --set pdb.enabled=false. Without a destination, the pods become Ready but model requests fail. See Deploy with Helm to supply a config and provider credential.

Verify the install

curl -fsS http://localhost:9099/healthz
curl -fsS http://localhost:9099/readyz
curl -fsS http://localhost:9099/metrics | head

The CLI marks readyz healthy after AppState construction. Plugin initialization errors stop startup regardless of required, but readiness does not track per-plugin health after boot.

Before you expose the gateway

Both installs above stay private: Docker publishes the ports on the host's loopback address, and the chart creates a ClusterIP Service. Before you expose the data plane to untrusted clients:

  1. Configure an auth validator for your callers' credentials.
  2. Configure an authorizer that denies anonymous principals.
  3. Keep the admin plane, port 9099, off the network. See Deploy with Helm for Kubernetes.

Next steps

On this page