Claude Code

Deploy Claude apps gateway

Private networking, OIDC, Kubernetes, Cloud Run, GCP, Postgres, health checks, upgrades and cache forwarding.

Apps gateway ships in the claude binary. It authenticates users through enterprise IdP and forwards Code requests to Anthropic, Bedrock, Google Agent Platform, Foundry or AWS Platform, adding SSO, settings, limits and telemetry.

The official login endpoint must use private or controlled networking. Public internet addresses fail login safety checks because the gateway can distribute command-executing policies.

#When to use it

OptionSuitable forUnsuitable for
Apps gatewaySSO, groups, managed settings, limits, OTLP and multiple providersUnattended CI without browser login
Passion8/custom gatewayExisting routing, model pools and billingOfficial apps-gateway IdP/managed features
Direct providerSmall teams, CI, simple keys/IAMCentral budgets, audit and per-user attribution

Setting only the URL may still use locally stored claude.ai credentials. Explicit gateway tokens or gateway login place billing behind the gateway's provider account.

#Deployment steps

StageActionAcceptance
IdPConfidential OIDC app with /oauth/callbackDiscovery, email and group/role claims work
ContainerPinned Linux binaryVerified manifest, nonroot user and writable config directory
PlatformKubernetes, Cloud Run or own platformHealth, readiness and OAuth metadata work
PolicyforceLoginMethod and forceLoginGatewayUrlGateway login option appears
OperationsLogs, database, limits, upgrades and secretsAudit/OTLP, backups and rollback runbook

Terminate TLS at the front proxy, use HTTP to replicas, and configure public_url/trusted_proxies for callbacks, per-IP limits and audit addresses.

#OIDC considerations

IdPCheck
OktaOrganization authorization server may need userinfo_fallback for email/groups
Entra IDGroups are often object IDs; app roles can use the roles claim
Google WorkspaceID tokens omit groups; use Directory API or email-domain policy
Keycloak/DexDiscovery, authorization-code flow and refresh tokens

Without refresh tokens, longer session.ttl_hours reduces login frequency but delays revoked-user convergence.

#Kubernetes operations

Deployment outline
containers:
  - name: claude-gateway
    image: registry.example.com/claude-gateway:2.1.x
    command: ["claude", "gateway", "--config", "/etc/claude/gateway.yaml"]
    readinessProbe:
      httpGet:
        path: /readyz
        port: 8080
    livenessProbe:
      httpGet:
        path: /healthz
        port: 8080

Recommendations:

  • Mount configuration through ConfigMap or read-only secret volumes.
  • Store OIDC/JWT secrets, database URL and upstream keys in a secret manager.
  • Use workload identity, not long-lived cloud keys in images.
  • Add ingress/internal-load-balancer addresses to trusted_proxies.
  • Decide whether database failure should remove every replica from readiness.

#Google Cloud topology

Official examples use Cloud Run or GKE, private-IP Cloud SQL, Secret Manager and Vertex Agent Platform upstreams.

ComponentCloud RunGKE
RuntimeCloud Run service,min instances 1GKE Deployment
NetworkInternal/cloud-load-balancing ingress and private DNS/LBInternal ingress and proxy-only subnet
DatabasePrivate-IP PostgreSQLPrivate-IP PostgreSQL
IdentityAgent Platform service accountWorkload Identity
SecretsSecret Manager env / file mountSecret Manager CSI driver

Default run.app hosts resolve publicly. Use an internal application load balancer or Private Service Connect/private DNS for production login.

#Operations and upgrades

ItemHandling
LogsAudit events and gateway operational logs on stderr
Healthhealthz checks process; readyz also checks storage
PostgresGrants, rates, spend, audit and principal emails
JWT rotationAdd new secret first; remove old after TTL
UpgradeNew binary migrates schema; stateless replicas roll
RollbackMigrations append, but older binaries reject unknown configuration

With spend limits, Postgres stores budget state as well as login state. Plan backups, retention and outage policy.

#Cache and protocol forwarding

CheckWhy it matters
Unbuffered SSEIncremental tools and responses rely on streaming
Preserve beta headersSearch, context and one-hour features depend on them
Preserve system arraysOrder matters for attribution and cache keys
Preserve tools/cache_controlRequired by MCP, deferred tools and cache
Preserve usage cache tokensNeeded for read/write analysis

One-hour TTL requires client, gateway and upstream support. Otherwise document a five-minute fallback and mark it in telemetry.

#Official references

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.