Skip to main content
A Helm install creates no Ingress by default. Turn on the chart Ingress, which can carry the AI Gateway host too, or write your own routes with Envoy Gateway, another Gateway API implementation, Traefik or a cloud load balancer. This page lists what those routes must expose.

What to expose

LangWatch uses two hostnames. Browsers and SDKs reach the app. LLM clients and coding agents reach the LangWatch AI Gateway. <release> is the Helm release name. The gateway Service forwards port 80 to container port 5563. Do not expose any other gateway path. /healthz, /readyz, /startupz, /metrics, /debug/control-plane and /internal/* are for in-cluster use only. Gemini-native clients also need /v1beta. Add it as a third Prefix rule if you use them. /api/internal on the app is the private control plane that the gateway and the Langy agent call over cluster DNS. The chart Ingress blocks it by default with ingress.blockedPaths. Your own routes must block it too. See Security.

Proxy settings

Envoy and Traefik stream responses without buffering and pass WebSocket upgrades by default. ingress-nginx buffers request bodies by default, caps them at 1 MB, and turns on response buffering when the controller config does, so it needs annotations. On the gateway Ingress the chart sets both buffering annotations to off so a controller-wide setting cannot change them. The app Ingress keeps the controller defaults. See Architecture for the connected-agents WebSocket.

Chart Ingress

The chart renders an Ingress for the app when ingress.enabled is true. Set ingress.gateway.host and it renders a second Ingress, <release>-gateway-ingress, for the gateway host. The second Ingress uses the same className, labels and annotations as the app Ingress. It is a separate object because ingress-nginx and similar controllers apply annotations to a whole Ingress, and the gateway needs streaming settings that the app routes do not. On ingress-nginx:
With className: nginx the chart adds these to the gateway Ingress only: proxy-buffering: "off", proxy-request-buffering: "off", proxy-read-timeout: "3600", proxy-send-timeout: "3600" and proxy-body-size: 32m. They override the same keys from ingress.annotations. Keys in ingress.gateway.annotations override both. The chart matches on the value of className. If className is empty and the cluster default IngressClass is ingress-nginx, the gateway Ingress gets none of these settings. On ingress-nginx, set className: nginx. On another controller, set className to your IngressClass, or leave it empty for the cluster default. Put the gateway settings for that controller in ingress.gateway.annotations. Traefik works with className: traefik and no extra annotations for buffering. It can also serve the HTTPRoutes below through its Gateway API provider.

Gateway API (Envoy Gateway)

Leave the chart Ingress off and attach HTTPRoutes to your Gateway. Set gateway.publicUrl, because the control plane cannot derive the gateway URL without ingress.gateway.host.
These routes are for release langwatch in namespace langwatch, on a Gateway named public in namespace envoy-gateway-system:
request: 0s turns off the total request timeout, so streams are not cut. You do not need to order the two app rules: Gateway API matches the longest prefix first, so /api/internal takes precedence over /. Check that your implementation answers that rule with a 5xx before you rely on it. If your Gateway is in a different namespace from the routes, set allowedRoutes.namespaces on its listener to admit the langwatch namespace. If you set idle timeouts in an Envoy Gateway ClientTrafficPolicy or BackendTrafficPolicy, keep them above the values in the table.

Network policies

gateway.networkPolicy.enabled is off by default. When you turn it on, the default gateway.networkPolicy.ingressFrom admits only the ingress-nginx namespace and Prometheus. Change it to the namespace where your proxy pods run, for example envoy-gateway-system, or the gateway refuses that traffic.
Last modified on October 1, 2026