> ## Documentation Index
> Fetch the complete documentation index at: https://docs.neuraltrust.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> These docs cover three products: TrustGate (AI agent gateway), TrustGuard (runtime security), and TrustTest (AI red teaming). Start from each product overview for the definition and How it works. Prefer the .md URL next to a page in /llms.txt when you need the full article. Use /llms-full.txt for a single-file dump of the site.

# Deploy TrustGate

> Run the TrustGate AI gateway on its own in your cluster, with the control plane on NeuralTrust SaaS.

**TrustGate** is the NeuralTrust AI gateway: it routes, secures, and observes
LLM and MCP traffic between your applications, agents, and model providers.
TrustGate is open source under the Apache 2.0 license.

This page installs TrustGate on its own as a [Hybrid](/neuraltrust/deployment/hybrid)
data plane, with the control plane on NeuralTrust SaaS. The Hybrid page covers
the architecture, [prerequisites](/neuraltrust/deployment/hybrid#prerequisites),
and [network rules](/neuraltrust/deployment/hybrid#network) that apply here too.

| Resource | Where |
| - | - |
| Source code | [github.com/NeuralTrust/TrustGate](https://github.com/NeuralTrust/TrustGate) |
| Container image | [`europe-west1-docker.pkg.dev/neuraltrust-app-prod/nt-docker/agentgateway`](https://console.cloud.google.com/artifacts/docker/neuraltrust-app-prod/europe-west1/nt-docker/agentgateway?project=neuraltrust-app-prod) |
| Product slice | [`values-trustgate.yaml.example`](https://github.com/NeuralTrust/neuraltrust-platform/blob/main/values-trustgate.yaml.example) |

The TrustGate image and its chart values block are named `agentgateway`. That
is the same product; see the
[naming map](/neuraltrust/deployment/console-setup#one-product-four-names).

<Note>
  The TrustGate image is published to the NeuralTrust container registry. Pulling
  it requires a registry key, which NeuralTrust issues with an enterprise offer —
  [contact NeuralTrust](mailto:support@neuraltrust.ai) to get one.
</Note>

This install runs `agentgateway-proxy` (LLM, port 8081), `agentgateway-mcp`
(MCP, port 8082), and one `dataagent`.

<Steps>
  <Step title="Prepare the namespace and chart sources">
    Do step 1 of the [Hybrid install](/neuraltrust/deployment/hybrid#install) to
    create the namespace and the image pull Secret, then [get the chart sources](/neuraltrust/deployment/images#get-the-chart-sources)
    so `values-trustgate.yaml.example` is on disk.
  </Step>

  <Step title="Create the gateway in the console">
    Open **TrustGate → New Gateway**, name it, choose **Private**, then
    **Kubernetes**. Take the `CONFIG_SYNC_TOKEN` and the DataAgent enrollment JWT
    from the wizard output — see
    [Console setup](/neuraltrust/deployment/console-setup).
  </Step>

  <Step title="Create the two Secrets">
    ```bash theme={null}
    kubectl create secret generic agentgateway-config-sync -n neuraltrust \
      --from-literal=CONFIG_SYNC_TOKEN='<trustgate-config-sync-token>'

    kubectl create secret generic dataagent-enrolment-trustgate -n neuraltrust \
      --from-literal=ENROLMENT_TOKEN='<trustgate-enrolment-jwt>'
    ```
  </Step>

  <Step title="Install">
    Put the cluster-specific values in their own file:

    ```yaml values-cluster.yaml theme={null}
    global:
      platform: "kubernetes"          # aws | gcp | azure | openshift | kubernetes
      domain: "platform.example.com"
    ```

    Then install with the TrustGate slice, which turns on
    `global.products.trustgate` and wires the two Secrets:

    ```bash theme={null}
    helm upgrade --install neuraltrust-platform \
      oci://europe-west1-docker.pkg.dev/neuraltrust-app-prod/helm-charts/neuraltrust-platform \
      --version <VERSION> \
      --namespace neuraltrust \
      -f values-cluster.yaml \
      -f values-trustgate.yaml.example
    ```
  </Step>
</Steps>

Then [verify](/neuraltrust/deployment/hybrid#verify) and expose the LLM and MCP
hostnames as described in
[Expose both entry points](/neuraltrust/deployment/hybrid#expose-both-entry-points).
Only the `:8081` and `:8082` entry points need the
[inbound rule](/neuraltrust/deployment/hybrid#inbound), and only
`agentgateway-configsync.neuraltrust.ai`, `databridge.neuraltrust.ai`, and the
telemetry host for your region need egress.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.