Skip to main content

Components and Sizing Recommendations

Prerequisites

Ensure that following tools and resources are installed and available:
  • A running GKE cluster with at least 2 worker nodes. ( Best Practice: Use 2 nodes, with 1 node in each Availability Zone, to ensure high availability.)
  • VPC which host GKE cluster must have ACTIVE subnet with purpose REGIONAL_MANAGED_PROXY.
  • gcloud CLI
  • Kubectl
  • Helm (v3 or above)

Create a Strata Cloud Manager account

  • Go to the the AI Gateway website.
  • Sign up for a Strata Cloud Manager account.
  • Once logged in, locate and save your Organisation ID for future reference. You can find it in the browser URL: https://stratacloudmanager.paloaltonetworks.com/<organisation_id>/
  • Contact the Palo Alto Networks team and provide your Organisation ID and the email address used during signup.
  • The Palo Alto Networks team will share the following information with you:
    • Docker credentials for the Gateway images (username and password).
    • License: Client Auth Key.

Setup Project Environment

Image Credentials Configuration

Configure Components

Based on the choice of components and their configuration update the values.yaml.

MCP Gateway (Optional)

By default, only the AI Gateway is enabled in the deployment. To enable the MCP Gateway, add the following configuration to values.yaml:
Note:
  • MCP_GATEWAY_BASE_URL must include the protocol prefix — either http:// or https://.
  • This value is not required for the initial deployment. After the first deployment, once the MCP Load Balancer is provisioned and a hostname is mapped to the MCP Service, set this value and redeploy.
Server Modes
  1. "" (empty or not provided): Deploys only the AI Gateway. This is the default configuration.
  2. "mcp": Deploys only the MCP Gateway.
  3. "all": Deploys both the AI Gateway and MCP Gateway.

Cache Store

The AI Gateway deployment includes a Redis instance pre-installed by default. You can either use this built-in Redis or connect to an external cache like Google Memorystore Redis or Valkey.

Built-in Redis

No additional permissions or network configurations are required.

Google Memorystore

To enable the gateway to work with a Memorystore cache, ensure that network access from GKE cluster on required port.
TLS (Optional) If TLS is enabled on your GCP Memorystore Redis instance, you must provide the self-signed certificate to the Gateway to enable SSL/TLS connections.
  1. Download the certificate file server-ca.pem from your GCP Memorystore Redis cluster.
  2. Create a Kubernetes secret to store the Memorystore certificate:
  3. Add the following configuration to values.yaml:

Log Store

Google Cloud Storage

  1. Create a GCS bucket for storing LLM access logs.
  2. Set up access to the log store. The Gateway supports the following methods for connecting to GCS bucket for log storage:
    • Workload Identity Federation
    • HMAC
    Depending on the chosen GCS access method, update values.yaml with the following configuration.
    To set up IAM-based authentication for AI Gateway to GCP bucket, follow the steps and add following configuration in values.yaml.
  3. (Optional) Configure log path format using LOG_STORE_FILE_PATH_FORMAT. See Log Object Path Format for details.

Data Service (Optional)

The Data Service is a component of the AI Gateway deployment responsible for batch processing, fine-tuning, and log exports. To enable Data Service, add the following configuration to the values.yaml file.

Network Configuration

Set Up External Access

To make the Gateway service accessible externally, you can set up either of the following:
  • GCS Application Load Balancer with Kubernetes Ingress
  • GCS Network Load Balancer with Kubernetes Service
Prerequisites
  • GKE cluster must have HTTP Load Balancing add-on enabled.
  • Load Balancers require an active subnet with purpose REGIONAL_MANAGED_PROXY. If you don’t have one, create it:

GCP Load Balancer Ingress

To create Application Load Balancer Ingress update the values.yaml file with following configuration:
Note: If SERVER_MODE is set to all (i.e., both AI Gateway and MCP Gateway are enabled), you must enable host-based routing by setting hostBased to true and provide the hostname on which the AI Gateway and MCP Gateway will be accessible. GCP Load Balancer Controller provides additional annotations (like TLS, custom health checks etc ) for managing Ingress Load Balancer. For a comprehensive list of available annotations, refer to the GCP Ingress Load Balancer.

GCP Load Balancer Service

To create Load Balancer update the values.yaml with following configuration:
GCP Load Balancer Controller provides additional annotations (like TLS, custom health checks etc ) for managing Service Load Balancer. For a comprehensive list of available annotations, refer to the GCP Service Load Balancer.

Deploying AI Gateway

Verify the deployment

To confirm that the deployment was successful, follow these steps:
  • Verify that all pods are running correctly.
Note: If pods are in a Pending, CrashLoopBackOff, or other error state, inspect the pod logs and events to diagnose potential issues.
  • Test Gateway by sending a cURL request.
    1. Port-forward the Gateway pod
    1. Once port forwarding is active, open a new terminal window or tab and send a test request by running:
    1. Test gateway service integration with Load Balancer.

Integrating Gateway with Management Plane

Outbound Connectivity (Data Plane to Management Plane) The Data Plane integrates with the Management Plane over the internet. Ensure Outbound Network Access By default, Kubernetes allows full outbound access, but if your cluster has NetworkPolicies that restrict egress, configure them to allow outbound traffic. Example NetworkPolicy for Outbound Access:
This allows the gateway to access LLMs hosted both within your VPC and externally. This also enables connection for the sync service to the Management Plane.

Over the Internet

Ensure Gateway has access to following endpoints over the internet.
  • https://aigw.portkey.ai
  • https://albus.portkey.ai

Inbound Connectivity (Management Plane to Data Plane)

IP Whitelisting

Allows management plane to access the Data Plane over the internet by restricting inbound traffic to specific IP address of Management Plane. This method requires the Data Plane to have a publicly accessible endpoint. To whitelist, add an inbound rule to the VPC Firewall allowing connections from the AI Gateway Management Plane’s IPs on Load Balancer listner port. Contact the Palo Alto Networks team for the current address list. To integrate the Management Plane with the Data Plane, contact the Palo Alto Networks team and provide the Public Endpoint of the Data Plane.

Verifying Gateway Integration with the Management Plane

  • Send a test request to Gateway using curl.
  • Go to the AI Gateway website -> Logs.
  • Verify that the test request appears in the logs and that you can view its full details by selecting the log entry.

Uninstalling AI Gateway

Setting up IAM Permission

Follow the steps below to configure permissions based on your chosen access method.

Create Google Service Account

  1. Specify the details:
  2. Create a Google Service Account.
  3. Create an IAM Policy binding to bind GSA to Gateway’s KSA (Workload Identity).

Attach Permissions to GSA

Once the Google Service Account is created and bound to the KSA, grant the required permissions based on the GCP services your gateway needs to access.

Google Memorystore (Optional)

To allow the AI Gateway to authenticate with Google Memorystore using IAM, grant roles/redis.dbConnectionUser to the GSA. Same Project Access
Cross Project Access

GCS Bucket

To allow the AI Gateway to access a GCS bucket for log storage, grant roles/storage.objectAdmin (or a custom role with storage.objects.create and storage.objects.get) to the GSA. Same Project Access
Cross Project Access

Vertex AI (Optional)

To allow the AI Gateway to invoke Vertex AI models, grant roles/aiplatform.user to the GSA. Same Project Access
Cross Project Access

Examples

Built-in Redis with GCS (Workload Identity) The following sample values.yaml shows how to configure the built-in Redis cache and GCS for log storage using Workload Identity Federation.
Memorystore with GCS (Workload Identity) The following sample values.yaml shows how to configure Google Memorystore for caching, and GCS for log storage using Workload Identity Federation.
Built-in Redis with GCS (HMAC) and ALB Ingress The following sample values.yaml shows how to configure the built-in Redis cache, GCS for log storage using HMAC keys, and a GCP Application Load Balancer Ingress.
AI Gateway + MCP Gateway with Host-Based Routing The following sample values.yaml shows how to deploy both AI Gateway and MCP Gateway with host-based routing using a GCP Application Load Balancer, built-in Redis, and GCS with Workload Identity.
Last modified on September 22, 2026