Gate form factor
Sidecar
RoadmapPer-workload enforcement alongside the service it protects. Planned for pods and local processes that need Gate without a shared reverse proxy.
Status
A per-workload sidecar form factor is planned; it is not shipping yet.RoadmapNo sidecar implementation exists in system/.
Sidecar is on the roadmap. It does not exist in the codebase today. This page describes intent only (there is no evaluation SKU and no purchase path).
Intended shape
- One Gate process co-located with the workload it protects.
- Same eight-stage check order and per-endpoint policy as proxy and SDK.
- Useful where network topology makes a shared reverse proxy awkward.
Until sidecar ships, use reverse proxy or SDK middleware.
