Architecture
Four boundaries, one explicitly authorized path
The browser never receives an internal hostname. The connector never accepts an inbound public connection. The relay enforces policy again for every stream.
Browser
HTTPS
HTTPS
Gatehouse Relay
multiplexed WebSocket
multiplexed WebSocket
Gatehouse Connector
private HTTP
private HTTP
Internal Service
allow-listed target
allow-listed target
1. Control plane
Gatehouse Web stores organizations, memberships, connectors, service policy, grants, sessions, and safe audit metadata in PostgreSQL.
2. Relay
The independent ASP.NET Core relay accepts outbound connector WebSockets and browser gateway requests. It validates short-lived session capabilities and durable database state.
3. Connector
The .NET worker consumes a one-time enrollment token, stores a long-lived credential locally, reconnects with jittered backoff, and reaches only the target provided by registered service policy.