Skip to content

In a VM

gangway holds the Docker socket, which is root on its host, and treats preview code as hostile. On a machine that does other work, give gangway a VM of its own: a bad preview can then only damage the VM.

vm/cloud-init.yaml turns a stock Debian 13 or Ubuntu 24.04 cloud image into a gangway VM on its first boot. It installs Docker, the QEMU guest agent and unattended upgrades, then runs the installer. It works in any hypervisor that takes cloud-init user-data: Proxmox, Unraid, libvirt, Multipass, or a cloud provider. On Unraid, gangway-inabox does all of this for you.

Edit GANGWAY_ARGS in the file; the value is passed to the installer:

write_files:
- path: /etc/gangway/install-args
content: |
GANGWAY_ARGS="--tls proxy --domain preview.example.com --listen :: --trusted-proxies 192.168.1.10/32"
Mode GANGWAY_ARGS
behind a proxy on another box --tls proxy --domain preview.example.com --listen :: --trusted-proxies <proxy-ip>/32
holds 80/443 itself --tls acme --domain preview.example.com --cf-token <token>
no domain, on your network --lan

--listen :: makes gangway answer on the VM’s own address, where a proxy on another machine can reach it. --trusted-proxies names that proxy, so gangway believes its X-Forwarded-For.

Add your SSH key under ssh_authorized_keys to log in to the VM later.

Terminal window
multipass launch 24.04 --name gangway --cpus 2 --memory 4G --disk 40G --cloud-init cloud-init.yaml

The first boot takes two or three minutes. The installer’s output, with the first-admin link, goes to /var/log/gangway-install.log and to the serial console.

To upgrade, run the installer again in the VM:

Terminal window
curl -fsSL gangway.sh/install | sudo sh