Skip to content

Door APIM

Door APIM is where a hostname on the internet reaches a service that is already running. Door Hub places an environment on a cluster. Door DevOps builds an application into that environment. Door APIM publishes a host and a path in front of that application, or in front of any other address you name.

The console section is API-Management. It has five pages:

Page What it is
Overview Requests, success, latency, and the busiest endpoints
Endpoints One public host and path, and the service behind it
Gateways The ingress on a cluster. External is public. Internal stays inside the cluster
AuthServer OIDC, basic auth, or a static token, stored on an environment
Domains A hostname you own, tied to a cluster or to one environment

A caller goes through them in this order:

  1. The hostname is a domain.
  2. DNS sends that name to a gateway address.
  3. The endpoint matches the host and the path, then forwards to a backend.
  4. An auth server on the same environment can require a login or a token before the backend sees the request.

Start here

  1. Sign in at https://door.cloud and select your organization.
  2. Use an environment that already exists. A Project Owner or a Super Admin creates it in Door Hub. The service you want to publish should already be running there, from Door DevOps or from anything else in that namespace.
  3. Open Domains and register the hostname. See Domains.
  4. Open Gateways. An external gateway on that cluster is the public address. Many organizations already have one. See Gateways.
  5. At your DNS provider, add an A record for the hostname. The address is the gateway address. On Domains, the info icon next to the gateway says: "Please use this address to add an A record to your DNS manager."
  6. Open Endpoints and choose New Endpoint. Pick the domain, the subdomain, the path, and the backend. See Endpoints.
  7. When the endpoint should require a caller to authenticate, create an auth server on the same environment, then turn Authentication on under the endpoint's Security Policy. See Auth servers.
  8. Open Overview to watch requests, success, and latency. See Overview.

Publish one service

Use names you control. This example assumes an application named orders is already running in environment shop/dev, listening on port 8080.

  1. On Domains, New Domain. Register the parent host you own, for example example.com. Scope Environment, and pick shop/dev, when that host should serve that one environment. Scope Cluster when the same host should be available across the cluster. The endpoint form will then ask you to pick the environment.
  2. Security: Secure when you have a certificate secret name and namespace. Not Secure when you do not. A secure domain starts the endpoint on HTTPS and port 443. A Not Secure domain starts it on HTTP and port 80.
  3. On Gateways, find the External gateway on that same cluster. Copy its address. If the cluster has none, New gateway, class External, and select the cluster. An Internal gateway stays inside the cluster.
  4. At your DNS provider, add an A record for the public host to that address. On Domains, the info icon says: Please use this address to add an A record to your DNS manager.
  5. On Endpoints, New Endpoint. Domain example.com. The Subdomain field shows .example.com beside the value. Type orders. The public host is orders.example.com. Door fills a short value there until you replace it. Path /. Backend In-cluster service, the service name of the running application, port 8080.
  6. Create endpoint. Wait until the row says Ready.
  7. Open the public URL. When the endpoint should require a login, add an auth server on shop/dev, then turn Authentication on under Security Policy. Do that after the URL answers without authentication, so a failure is either the route or the login, not both at once.

An address that is not in the cluster uses External URL on the same drawer: scheme, host, and port. The domain and the DNS record stay the same.

If the hostname does not open

Check these in order. Stop at the first one that is wrong.

Check Where What good looks like
The application is running Apps, or the environment's Resources A workload in that namespace, on the port you will enter
The cluster is reachable Hub Clusters Ready
The domain exists Domains The host is in the list, on the right cluster
DNS Your DNS provider, and Gateway DNS information An A record to the gateway address on that domain
The endpoint Endpoints Ready, host and path as you expect, backend port equal to the port the process listens on
Authentication Security Policy Authentication off while you are still proving the route. Turn it on after the URL answers
Traffic Overview, period Last hour The endpoint appears, or the endpoint page shows requests

Managed traffic policy on an endpoint means the route is already owned by a deployment strategy. The banner says: This endpoint uses a managed deployment strategy. Traffic routing is controlled by Door CD and cannot be edited here.

What you will see in the pictures

The pictures in this section are the default organization on 5 October 2026. Counts and charts move. The labels on the buttons and fields stay the same.

Guides

Guide What you will do
Overview Read the period, the four figures, the charts, and the top endpoints
Endpoints Create a route, set the backend and the health check, then shape traffic and security
Gateways Add an external or internal gateway on a cluster, and see which endpoints use it
Auth servers Connect OIDC, basic auth, or static tokens to an environment
Domains Register a hostname, choose cluster or environment scope, and point DNS at the gateway

When a plan limit stops a create

New Domain stays available until the organization reaches its domain limit. New gateway stays available until the organization reaches its IP address limit. At the limit, the button is replaced by a message that names the current plan and the limit, with an upgrade action such as Upgrade to Team. Endpoints and auth servers use their own create buttons and are separate from those two limits.