Skip to content

Gateway command-line flags

Generated from gateway/internal/cli/flags.go. Edit that file and run make docs-generate; CI fails on an uncommitted difference.

The gateway takes all of its configuration from flags. It reads no environment variables and no configuration file, so what a running gateway is doing is visible in its Pod spec or its command line.

Flag Default Description
-discovery-ttl 5m0s how long a cached list of an API group's resources is trusted before being refetched; lower it to notice a deleted custom resource sooner, at the cost of more discovery traffic
-kubeconfig (none) path to a kubeconfig; empty means in-cluster config
-listen :8443 TCP address to listen on
-no-cluster false serve Ping only; Get/List fail with FAILED_PRECONDITION (Phase 0 plumbing mode)
-serve *.* comma-separated resources this gateway serves, as plural[.group] (e.g. "pods,configmaps,widgets.example.com"); "*.group" covers a whole group. Scope the ServiceAccount's RBAC to match: this bounds what is offered, RBAC enforces it
-tls-cert (none) path to PEM server certificate (required)
-tls-key (none) path to PEM server private key (required)

Both -tls-cert and -tls-key are required: the gateway has no plaintext mode, so it refuses to start without a server keypair.