Sign inSign up

dxheroes/mcp-gateway-ce

By dxheroes

•Updated about 16 hours ago

DXH Gateway Community Edition. Install and docs: https://github.com/DXHeroes/mcp-gateway

Image
0

10K+

dxheroes/mcp-gateway-ce repository overview

⁠DXH Gateway — Community Edition

Self-hosted governance for MCP tools: one endpoint in front of your MCP servers, with profiles, per-tool permissions, approvals and an audit trail.

This is the public Community Edition (CE) image. Installation materials, documentation and the CE terms live at github.com/DXHeroes/mcp-gateway⁠.

CE is free for eligible production use in companies with at most 50 employees including affiliates, and for nonproduction evaluation at any company size. It includes 25 active accounts, one organization, one REST/OpenAPI connection and one active gateway instance. MCP connections, profiles and tool calls have no commercial quota. Enterprise Edition and trials: [email protected]⁠.

⁠There is no latest tag

docker pull dxheroes/mcp-gateway-ce             # fails: manifest unknown
docker pull dxheroes/mcp-gateway-ce:<version>   # a release, for example v0.4.0

That is deliberate. A moving latest would hand you a breaking configuration change with no warning. Pin a version, or better the digest from that release's release.json. If you would rather take every release of a major as it comes, pin the compatibility line vX instead: it moves, but only inside one major.

TagWhat it is
vX.Y.ZA release. Immutable: never overwritten.
vX.Y, vXCompatibility lines: the newest patch of that minor, and the newest release of that major from 1.0.0 on. They move, but never across a breaking change — that bumps the major. No v0 exists, because a pre-1.0 minor may break compatibility.
vX.Y.Z-beta.N, betaBuilt from every change to the development branch. Audited, scanned and signed like a release, but unsupported; beta moves without notice. Not for production.
sha256-….sigCosign signatures. Not images.

⁠Same image as on GitHub Container Registry

This repository is a copy of ghcr.io/dxheroes/mcp-gateway-ce, not a second build: both serve the same digest with the same SBOM and build provenance for linux/amd64 and linux/arm64. Pull from whichever registry suits you. Releases older than the mirror itself (up to and including v0.3.0) exist only on GHCR.

⁠Install

Follow the installation guide⁠. In short: take compose.yaml and .env.example from the public repository, set GATEWAY_IMAGE to the image and digest from release.json, generate the two secrets, read LICENSE-CE.txt and record your acceptance in GATEWAY_CE_TERMS_ACCEPTED, then:

docker compose config
docker compose pull
docker compose up -d --wait

The gateway refuses to start until the CE terms are accepted. It needs PostgreSQL; the supplied Compose file brings one.

⁠Verify before you run it

Every image is signed with keyless Cosign by the release workflow:

cosign verify dxheroes/mcp-gateway-ce@sha256:<digest> \
  --certificate-identity "$(jq -r .signingIdentity release.json)" \
  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Full procedure, SBOM and provenance: image verification⁠. Upgrading between versions: upgrade notes⁠.

⁠License

The image is distributed under the DXH Gateway CE terms (LICENSE-CE.txt in the public repository). No service source is published.

Tag summary

Content type

Image

Digest

sha256:291fd7e1b…

Size

255 Bytes

Last updated

about 16 hours ago

docker pull dxheroes/mcp-gateway-ce:sha256-87d68ce740ab49d6e240f756ce00da408429a01ed3a7cd82066e850db8f01bd0.sig