Install the gateway
Install Orca AI Gateway from its public container image or Helm chart.
Orca AI Gateway ships as a Docker image and an OCI Helm chart. The instructions on this page pin
the current release, 0.4.3.
Container image
The release image is docker.io/streamnative/orca-ai-gateway:0.4.3, built on debian:13-slim for
linux/amd64 and linux/arm64. The same image is published as
ghcr.io/orca-ae/orca-ai-gateway:0.4.3. It exposes 8080 (data plane) and 9099 (admin plane),
runs as the non-root UID 65532, and defaults to run --config /etc/orca-gateway/config.yaml.
First write the config.yaml in the quickstart,
then check it:
docker run --rm \
-v "$PWD/config.yaml:/etc/orca-gateway/config.yaml:ro" \
docker.io/streamnative/orca-ai-gateway:0.4.3 \
check /etc/orca-gateway/config.yamldocker run --rm \
-p 127.0.0.1:8080:8080 -p 127.0.0.1:9099:9099 \
-v "$PWD/config.yaml:/etc/orca-gateway/config.yaml:ro" \
-e OPENAI_API_KEY \
docker.io/streamnative/orca-ai-gateway:0.4.3Set OPENAI_API_KEY before starting the container. The published image includes the
orca-gateway CLI; the check command does not need a provider key. See
Releases for the image digest.
Kubernetes with Helm
Install the OCI chart. The chart pulls the GHCR copy of the image by default; set
image.repository and image.tag to pull from Docker Hub instead:
helm install orca-ai-gateway oci://ghcr.io/orca-ae/charts/orca-ai-gateway \
--version 0.4.3 --namespace orca-system --create-namespace \
--set image.repository=docker.io/streamnative/orca-ai-gateway \
--set image.tag=0.4.3The chart starts three replicas by default. On a single-node development cluster, add
--set replicaCount=1 --set pdb.enabled=false. Without a destination, the pods become Ready but
model requests fail. See Deploy with Helm to supply a config and
provider credential.
Verify the install
curl -fsS http://localhost:9099/healthz
curl -fsS http://localhost:9099/readyz
curl -fsS http://localhost:9099/metrics | headThe CLI marks readyz healthy after AppState construction. Plugin initialization errors stop
startup regardless of required, but readiness does not track per-plugin health after boot.
Before you expose the gateway
Both installs above stay private: Docker publishes the ports on the host's loopback address, and the
chart creates a ClusterIP Service. Before you expose the data plane to untrusted clients:
- Configure an auth validator for your callers' credentials.
- Configure an authorizer that denies anonymous principals.
- Keep the admin plane, port
9099, off the network. See Deploy with Helm for Kubernetes.