Configure the gateway to support database integrations

Create the gateway configuration file and apply a setup token that's configured for infrastructure orchestration, so that the gateway can service your database integrations.

About this task

Gateways that provide access to database instances require a specific configuration. Managing database access with Okta Privileged Access requires a gateway that's enrolled using a setup token configured for infrastructure orchestration.

Before you begin

Procedure

  1. On the gateway machine, create the configuration file at /etc/sft/sft-gatewayd.yaml and add the following:
    Orchestrator:
      Enabled: true
      BinaryPath: /usr/sbin/sft-orchestrator
  2. Apply the setup token that you created.
    echo 'your-setup-token' | sudo tee /var/lib/sft-gatewayd/setup.token > /dev/null

    Replace your-setup-token with the token value copied from the Okta Privileged Access dashboard.

  3. Confirm that the gateway machine has outbound connectivity to Okta Privileged Access.

    The gateway must reach both the production and preview Okta Privileged Access domains on port 443. From the gateway machine, run the following commands, replacing your-opa-team-name with your team name. A response confirms that the network path works.

    curl -Iv https://your-opa-team-name.pam.okta.com
    curl -Iv https://your-opa-team-name.pam.oktapreview.com
  4. Restart the gateway service.
    sudo systemctl restart sft-gatewayd
  5. Confirm that the gateway enrolled successfully.
    sudo journalctl -u sft-gatewayd -f

    This command streams the full gateway log. Scan the output for the following three entries, which confirm a successful enrollment. Each entry appears within a longer log line, and they don't always appear in this order:

    • Initialization Successful
    • Orchestrator started successfully
    • GatewaySync reported 204

    Press Ctrl+C to stop following the log.

    If the gateway doesn't enroll or the expected messages aren't shown, see Troubleshooting database integrations.

  6. Confirm that the gateway machine can reach the database instance.

    Use these commands to confirm that the gateway machine can reach your database instance. An authentication error still confirms that the network path works. A connection timeout or a host not found error means that the gateway can't reach the instance.

    For MySQL or MariaDB:

    mysql -h hostname -P port -u username -p

    For PostgreSQL:

    psql -h hostname -p port -U username -d database-name

    Other database types use their own command-line client. If the gateway can't reach the instance, see Network access by environment.

  7. In the Okta Privileged Access dashboard, confirm that the gateway has the Infrastructure orchestrator role.

    Go to Resource Administration > Gateways. The Used for column shows the role for each gateway.

Troubleshooting

If the gateway fails to start on Amazon Linux 2023, the required session log directory is missing. Create the directory, add it to the configuration file, then restart the service:

sudo mkdir -p /var/log/sft/sessions/tmp
echo "SessionLogTempStorageDirectory: /var/log/sft/sessions/tmp" | sudo tee -a /etc/sft/sft-gatewayd.yaml
sudo systemctl restart sft-gatewayd

What to do next

After you confirm that the gateway is enrolled with the Infrastructure orchestrator role, you can add a database integration.