Getting Started

Installation

Run Quayel Gateway with Docker in minutes. APT packages and direct downloads are coming soon.

Installation

Quayel Gateway ships as a Docker image with every IP-intelligence dataset embedded and a ready-to-run demo config. There is nothing else to install — no Redis, no database, no sidecars.

APT packages and direct binary downloads are coming soon. Docker is the supported way to run Quayel Gateway today.

Docker

Prerequisites: Docker 20 or newer.

1. Run the demo

docker run --rm -p 8080:8080 -p 8443:8443 quayel/quayel-gateway

The image starts with a full-featured demo config listening on 8080 (HTTP) and 8443 (HTTPS).

2. Run with your own config

docker run --rm -p 8080:8080 -p 8443:8443 \
  -v $PWD/config.json:/etc/quayel-gateway/config.json:ro \
  -v $PWD/logs:/var/log/quayel \
  quayel/quayel-gateway

The gateway reads /etc/quayel-gateway/config.json and writes access logs to /var/log/quayel/access.jsonl. Any valid config.json works — start from the demo config or the minimal config below.

3. Test it

# The gateway answers immediately (JSON error until a real backend is configured)
curl -i http://localhost:8080/

# Watch the structured access log
tail -f logs/access.jsonl | jq .

The demo's load balancer points at placeholder IPs, so upstream requests return 502 until you set real targets. The gateway itself is up: every request is logged with full IP-intel context.

4. Go to production

Use the bundled docker-compose.yml (ports 80/443, persistent certificates, graceful shutdown) — see below.

Docker Compose

The repository ships an SSL-ready docker-compose.yml:

services:
  gateway:
    build: .
    image: quayel/quayel-gateway:latest
    container_name: quayel-gateway
    restart: unless-stopped
    ports:
      - "80:8080"     # HTTP: ACME HTTP-01 challenges + plain HTTP
      - "443:8443"    # HTTPS: SNI cert resolver / Auto-SSL
    volumes:
      - quayel-certs:/var/lib/quayel/certs
      # - ./config.json:/etc/quayel-gateway/config.json:ro
      # - ./logs:/var/log/quayel
    environment:
      RUST_LOG: ${RUST_LOG:-info}
    stop_grace_period: 15s

volumes:
  quayel-certs:
docker compose up -d --build

To use your own config, put it at ./config.json and uncomment the config mount. Keep auto_ssl.cert_storage_path at /var/lib/quayel/certs so certificates land in the persistent volume.

Auto-SSL in Docker

  • Persist certificates — the ACME account key and issued certs live in cert_storage_path (/var/lib/quayel/certs in the image). Mount a volume over it, otherwise every container start re-issues certificates and hits Let's Encrypt rate limits.
  • Ports — ACME HTTP-01 validation needs port 80 reachable from the internet. Map 80:8080 and 443:8443 (as in the compose file) or bind 80/443 directly in listen.
  • Clean shutdown — the gateway drains in-flight requests on SIGTERM (5s grace + 5s drain) and exits well inside Docker's 10s stop timeout; the compose file sets stop_grace_period: 15s as headroom.

See the Auto-SSL plugin for full configuration docs.

Image tags and dataset refresh

Images are tagged quayel/quayel-gateway:latest and quayel/quayel-gateway:<version> (for example quayel/quayel-gateway:0.1.0).

The image is a multi-stage build: rust:1-bookworm compiles the release binary with all datasets embedded, debian:bookworm-slim runs it. Rebuilding the image is how you refresh the embedded IP-intelligence data — do it monthly for current DB-IP snapshots.

Build the image yourself

git clone https://github.com/quayel/Quayel-Gateway.git
cd Quayel-Gateway
docker build -t quayel/quayel-gateway .

If src/data/*.mmdb is missing at build time the builder runs setup.sh --data-only automatically and downloads the latest datasets.

Coming soon: APT and direct download

MethodCommandStatus
Dockerdocker run quayel/quayel-gateway✅ Available now
APT packageapt install quayel-gateway🚧 Coming soon
Direct downloadstandalone Linux x86_64 binary🚧 Coming soon

Build from source

git clone https://github.com/quayel/Quayel-Gateway.git
cd Quayel-Gateway

./setup.sh                    # datasets into src/data/ + cargo packages
cargo build --release         # data is embedded into the binary

./target/release/quayel-gateway config.demo.json

See Project Structure for what each part of the repository does.

The build compiles ~140 MB of IP intelligence data (MMDB databases + CIDR lists) directly into the binary. See Data Sources for what is embedded and how to refresh it.

System requirements

ResourceMinimumRecommended
CPU1 core2+ cores
RAM64 MB128 MB
Disk200 MB500 MB (for logs)
PlatformLinux x86_64 (Ubuntu 22.04+)—
Binary size~153 MB— (includes embedded data)
Runtime RSS~29 MB—
Copyright © 2026