Configure the gateway to support database integrations
Create the gateway configuration file and apply a setup token that's configured for infrastructure orchestration, so that the gateway can service your database integrations.
About this task
Gateways that provide access to database instances require a specific configuration. Managing database access with Okta Privileged Access requires a gateway that's enrolled using a setup token configured for infrastructure orchestration.
Before you begin
-
You've created a gateway setup token with the Infrastructure orchestrator role. You apply this token to the gateway machine in this task. See Create setup tokens.
-
The gateway machine must have outbound connectivity to the relevant database instances, and to Okta Privileged Access. See Network access by environment.
-
Set up the gateways on your infrastructure before you create the database integrations. Integration creation fails if no gateway can reach the database instance. See Install the Okta Privileged Access gateway on Ubuntu or Debian or Install the Okta Privileged Access gateway on Linux.
A gateway enrolled using a token that isn't configured for infrastructure orchestration causes database integration creation to fail. This includes an existing gateway enrolled for Server access proxy. See Setup Token Gateway Role Known Issues.
Procedure
Troubleshooting
If the gateway fails to start on Amazon Linux 2023, the required session log directory is missing. Create the directory, add it to the configuration file, then restart the service:
sudo mkdir -p /var/log/sft/sessions/tmp
echo "SessionLogTempStorageDirectory: /var/log/sft/sessions/tmp" | sudo tee -a /etc/sft/sft-gatewayd.yaml
sudo systemctl restart sft-gatewayd
What to do next
After you confirm that the gateway is enrolled with the Infrastructure orchestrator role, you can add a database integration.