Door APIM¶
Door APIM is where a hostname on the internet reaches a service that is already running. Door Hub places an environment on a cluster. Door DevOps builds an application into that environment. Door APIM publishes a host and a path in front of that application, or in front of any other address you name.
The console section is API-Management. It has five pages:
| Page | What it is |
|---|---|
| Overview | Requests, success, latency, and the busiest endpoints |
| Endpoints | One public host and path, and the service behind it |
| Gateways | The ingress on a cluster. External is public. Internal stays inside the cluster |
| AuthServer | OIDC, basic auth, or a static token, stored on an environment |
| Domains | A hostname you own, tied to a cluster or to one environment |
A caller goes through them in this order:
- The hostname is a domain.
- DNS sends that name to a gateway address.
- The endpoint matches the host and the path, then forwards to a backend.
- An auth server on the same environment can require a login or a token before the backend sees the request.
Start here¶
- Sign in at https://door.cloud and select your organization.
- Use an environment that already exists. A Project Owner or a Super Admin creates it in Door Hub. The service you want to publish should already be running there, from Door DevOps or from anything else in that namespace.
- Open Domains and register the hostname. See Domains.
- Open Gateways. An external gateway on that cluster is the public address. Many organizations already have one. See Gateways.
- At your DNS provider, add an A record for the hostname. The address is the gateway address. On Domains, the info icon next to the gateway says: "Please use this address to add an A record to your DNS manager."
- Open Endpoints and choose New Endpoint. Pick the domain, the subdomain, the path, and the backend. See Endpoints.
- When the endpoint should require a caller to authenticate, create an auth server on the same environment, then turn Authentication on under the endpoint's Security Policy. See Auth servers.
- Open Overview to watch requests, success, and latency. See Overview.
Publish one service¶
Use names you control. This example assumes an application named orders is already running in environment shop/dev, listening on port 8080.
- On Domains, New Domain. Register the parent host you own, for example
example.com. Scope Environment, and pick shop/dev, when that host should serve that one environment. Scope Cluster when the same host should be available across the cluster. The endpoint form will then ask you to pick the environment. - Security: Secure when you have a certificate secret name and namespace. Not Secure when you do not. A secure domain starts the endpoint on HTTPS and port 443. A Not Secure domain starts it on HTTP and port 80.
- On Gateways, find the External gateway on that same cluster. Copy its address. If the cluster has none, New gateway, class External, and select the cluster. An Internal gateway stays inside the cluster.
- At your DNS provider, add an A record for the public host to that address. On Domains, the info icon says: Please use this address to add an A record to your DNS manager.
- On Endpoints, New Endpoint. Domain
example.com. The Subdomain field shows.example.combeside the value. Typeorders. The public host isorders.example.com. Door fills a short value there until you replace it. Path/. Backend In-cluster service, the service name of the running application, port 8080. - Create endpoint. Wait until the row says Ready.
- Open the public URL. When the endpoint should require a login, add an auth server on shop/dev, then turn Authentication on under Security Policy. Do that after the URL answers without authentication, so a failure is either the route or the login, not both at once.
An address that is not in the cluster uses External URL on the same drawer: scheme, host, and port. The domain and the DNS record stay the same.
If the hostname does not open¶
Check these in order. Stop at the first one that is wrong.
| Check | Where | What good looks like |
|---|---|---|
| The application is running | Apps, or the environment's Resources | A workload in that namespace, on the port you will enter |
| The cluster is reachable | Hub Clusters | Ready |
| The domain exists | Domains | The host is in the list, on the right cluster |
| DNS | Your DNS provider, and Gateway DNS information | An A record to the gateway address on that domain |
| The endpoint | Endpoints | Ready, host and path as you expect, backend port equal to the port the process listens on |
| Authentication | Security Policy | Authentication off while you are still proving the route. Turn it on after the URL answers |
| Traffic | Overview, period Last hour | The endpoint appears, or the endpoint page shows requests |
Managed traffic policy on an endpoint means the route is already owned by a deployment strategy. The banner says: This endpoint uses a managed deployment strategy. Traffic routing is controlled by Door CD and cannot be edited here.
What you will see in the pictures¶
The pictures in this section are the default organization on 5 October 2026. Counts and charts move. The labels on the buttons and fields stay the same.
Guides¶
| Guide | What you will do |
|---|---|
| Overview | Read the period, the four figures, the charts, and the top endpoints |
| Endpoints | Create a route, set the backend and the health check, then shape traffic and security |
| Gateways | Add an external or internal gateway on a cluster, and see which endpoints use it |
| Auth servers | Connect OIDC, basic auth, or static tokens to an environment |
| Domains | Register a hostname, choose cluster or environment scope, and point DNS at the gateway |
When a plan limit stops a create¶
New Domain stays available until the organization reaches its domain limit. New gateway stays available until the organization reaches its IP address limit. At the limit, the button is replaced by a message that names the current plan and the limit, with an upgrade action such as Upgrade to Team. Endpoints and auth servers use their own create buttons and are separate from those two limits.