From feabdbf55925cc725482197c0a6660e7f424cc4a Mon Sep 17 00:00:00 2001 From: x032205 Date: Wed, 5 Nov 2025 15:49:55 -0500 Subject: [PATCH 1/6] docs: make --relay flag optional --- docs/cli/commands/gateway.mdx | 66 ++++++++++++------- .../platform/gateways/gateway-deployment.mdx | 17 +++-- 2 files changed, 57 insertions(+), 26 deletions(-) diff --git a/docs/cli/commands/gateway.mdx b/docs/cli/commands/gateway.mdx index 59202e46e..d7e9bb768 100644 --- a/docs/cli/commands/gateway.mdx +++ b/docs/cli/commands/gateway.mdx @@ -6,12 +6,12 @@ description: "Run the Infisical gateway or manage its systemd service" ```bash - infisical gateway start --name= --relay= --auth-method= + infisical gateway start --name= --auth-method= ``` ```bash - sudo infisical gateway systemd install --token= --domain= --name= --relay= + sudo infisical gateway systemd install --token= --domain= --name= ``` @@ -33,22 +33,27 @@ If you are moving from Gateway v1 to Gateway v2, this is NOT a drop-in switch. G - Run the Infisical gateway component within your the network where your target resources are located. The gateway establishes an SSH reverse tunnel to the specified relay server and provides secure access to private resources within your network. + Run the Infisical gateway component within your the network where your target resources are located. The gateway establishes an SSH reverse tunnel to a relay server and provides secure access to private resources within your network. ```bash -infisical gateway start --relay= --name= --auth-method= +infisical gateway start --name= --auth-method= ``` + + By default, the gateway automatically connects to the relay with the lowest latency. To target a specific relay, use the `--relay=` flag. + + Once started, the gateway component will: -- Establish outbound SSH reverse tunnels to relay servers (no inbound firewall rules needed) +- Automatically connect to a healthy relay with the lowest latency (unless the `--relay` flag is specified) +- Establish outbound SSH reverse tunnel to relay server (no inbound firewall rules needed) - Authenticate using SSH certificates issued by Infisical - Automatically reconnect if the connection is lost - Provide access to private resources within your network ### Authentication -The Relay supports multiple authentication methods. Below are the available authentication methods, with their respective flags. +The gateway supports multiple authentication methods. Below are the available authentication methods, with their respective flags. @@ -69,7 +74,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=universal-auth --client-id= --client-secret= --relay= --name= + infisical gateway start --auth-method=universal-auth --client-id= --client-secret= --name= ``` @@ -93,7 +98,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=kubernetes --machine-identity-id= --relay= --name= + infisical gateway start --auth-method=kubernetes --machine-identity-id= --name= ``` @@ -114,7 +119,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=azure --machine-identity-id= --relay= --name= + infisical gateway start --auth-method=azure --machine-identity-id= --name= ``` @@ -135,7 +140,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=gcp-id-token --machine-identity-id= --relay= --name= + infisical gateway start --auth-method=gcp-id-token --machine-identity-id= --name= ``` @@ -157,7 +162,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=gcp-iam --machine-identity-id= --service-account-key-file-path= --relay= --name= + infisical gateway start --auth-method=gcp-iam --machine-identity-id= --service-account-key-file-path= --name= ``` @@ -176,7 +181,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=aws-iam --machine-identity-id= --relay= --name= + infisical gateway start --auth-method=aws-iam --machine-identity-id= --name= ``` @@ -198,7 +203,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=oidc-auth --machine-identity-id= --jwt= --relay= --name= + infisical gateway start --auth-method=oidc-auth --machine-identity-id= --jwt= --name= ``` @@ -222,7 +227,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --auth-method=jwt-auth --jwt= --machine-identity-id= --relay= --name= + infisical gateway start --auth-method=jwt-auth --jwt= --machine-identity-id= --name= ``` @@ -238,7 +243,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash - infisical gateway start --token= --relay= --name= + infisical gateway start --token= --name= ``` @@ -250,6 +255,8 @@ The Relay supports multiple authentication methods. Below are the available auth The name of the relay that this gateway should connect to. The relay must be running and registered before starting the gateway. + If this flag is omitted, the gateway will automatically connect to a healthy relay with the lowest latency. + ```bash # Example infisical gateway start --relay=my-relay --name=my-gateway --token= @@ -264,7 +271,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash # Example - infisical gateway start --name=my-gateway --relay=my-relay --token= + infisical gateway start --name=my-gateway --token= ``` @@ -274,7 +281,7 @@ The Relay supports multiple authentication methods. Below are the available auth ```bash # Example - infisical gateway start --domain=https://app.your-domain.com --relay= --name= + infisical gateway start --domain=https://app.your-domain.com --name= ``` @@ -285,7 +292,7 @@ The Relay supports multiple authentication methods. Below are the available auth Install and enable the gateway as a systemd service. This command must be run with sudo on Linux. ```bash -sudo infisical gateway systemd install --token= --domain= --name= --relay= +sudo infisical gateway systemd install --token= --domain= --name= ``` ### Requirements @@ -302,7 +309,7 @@ sudo infisical gateway systemd install --token= --domain= --name= ```bash # Example - sudo infisical gateway systemd install --token= --name= --relay= + sudo infisical gateway systemd install --token= --name= ``` You may also expose the token to the CLI by setting the environment variable `INFISICAL_TOKEN` before executing the install command. @@ -314,7 +321,7 @@ sudo infisical gateway systemd install --token= --domain= --name= ```bash # Example - sudo infisical gateway systemd install --domain=https://app.your-domain.com --name= --relay= + sudo infisical gateway systemd install --domain=https://app.your-domain.com --name= ``` @@ -324,19 +331,23 @@ sudo infisical gateway systemd install --token= --domain= --name= ```bash # Example - sudo infisical gateway systemd install --name=my-gateway --token= --relay= + sudo infisical gateway systemd install --name=my-gateway --token= ``` - The name of the relay that this gateway should connect to. + The name of the relay that this gateway should connect to. The relay must be running and registered before starting the gateway. + + If this flag is omitted, the gateway will automatically connect to a healthy relay with the lowest latency. ```bash # Example sudo infisical gateway systemd install --relay=my-relay --token= --name= ``` + **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server using `infisical relay start` before connecting gateways to it. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. + @@ -671,3 +682,14 @@ sudo systemctl disable infisical-gateway # Disable auto-start on boot + +## Frequently Asked Questions + + + + If the `--relay` flag is omitted, the gateway automatically selects the optimal relay. It first checks for healthy organization relays and connects to the one with the lowest latency. If no organization relays are available, it then performs the same latency-based selection among the available platform relays. + + + No. The first time the gateway starts, it selects the optimal relay (based on latency) and caches that selection. On subsequent restarts, it will prioritize connecting to the cached relay. If it's unable to connect, it will then re-evaluate and connect to the next most optimal relay available. + + diff --git a/docs/documentation/platform/gateways/gateway-deployment.mdx b/docs/documentation/platform/gateways/gateway-deployment.mdx index 9a5b7d816..5c25914c0 100644 --- a/docs/documentation/platform/gateways/gateway-deployment.mdx +++ b/docs/documentation/platform/gateways/gateway-deployment.mdx @@ -122,11 +122,13 @@ To successfully deploy an Infisical Gateway for use, follow these steps in order For production deployments on Linux servers, install the Gateway as a systemd service so that it runs securely in the background and automatically restarts on failure or system reboot: ```bash - sudo infisical gateway systemd install --token --domain --name --relay + sudo infisical gateway systemd install --token --domain --name sudo systemctl start infisical-gateway ``` - + + By default, the gateway connects to the most optimal relay. Use the `--relay` flag to manually specify a different relay server. + The systemd install command requires a Linux operating system with root/sudo @@ -153,10 +155,13 @@ To successfully deploy an Infisical Gateway for use, follow these steps in order --from-literal=INFISICAL_AUTH_METHOD=universal-auth \ --from-literal=INFISICAL_UNIVERSAL_AUTH_CLIENT_ID= \ --from-literal=INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET= \ - --from-literal=INFISICAL_RELAY_NAME= \ --from-literal=INFISICAL_GATEWAY_NAME= ``` + + By default, the gateway connects to the most optimal relay. Use the `--from-literal=INFISICAL_RELAY_NAME=` flag to manually specify a different relay server. + + #### Install the Gateway ```bash @@ -168,8 +173,12 @@ To successfully deploy an Infisical Gateway for use, follow these steps in order For development or testing environments: ```bash - infisical gateway start --token --relay= --name= + infisical gateway start --token --name= ``` + + + By default, the gateway connects to the most optimal relay. Use the `--relay` flag to manually specify a different relay server. + From e0c50fdfc6173e40f2290bf54852562dfb15d02a Mon Sep 17 00:00:00 2001 From: x032205 Date: Wed, 5 Nov 2025 15:56:27 -0500 Subject: [PATCH 2/6] auto select relay for gateway quick setup --- .../components/GatewayCliDeploymentMethod.tsx | 11 +++++++---- .../components/GatewayTab/components/RelayOption.tsx | 8 +++++++- 2 files changed, 14 insertions(+), 5 deletions(-) diff --git a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx index ae44cdd1e..17818f307 100644 --- a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx +++ b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx @@ -80,7 +80,7 @@ export const GatewayCliDeploymentMethod = () => { const [relay, setRelay] = useState(null); + }>({ id: "_auto", name: "Auto Select Relay" }); const [identity, setIdentity] = useState { }; const command = useMemo(() => { - return `infisical gateway start --name=${name} --relay=${ - relay?.name || "" - } --domain=${siteURL} --token=${identityToken}`; + const relayPart = relay?.id !== "_auto" ? ` --relay=${relay?.name || ""}` : ""; + return `infisical gateway start --name=${name}${relayPart} --domain=${siteURL} --token=${identityToken}`; }, [name, relay, identityToken, siteURL]); if (step === "command") { @@ -256,6 +255,10 @@ export const GatewayCliDeploymentMethod = () => { }} isLoading={isRelaysLoading} options={[ + { + id: "_auto", + name: "Auto Select Relay" + }, { id: "_create", name: "Deploy New Relay" diff --git a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx index 90c9a7ebd..4f5426a63 100644 --- a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx +++ b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx @@ -1,6 +1,6 @@ import { components, OptionProps } from "react-select"; import { faCheckCircle } from "@fortawesome/free-regular-svg-icons"; -import { faPlus } from "@fortawesome/free-solid-svg-icons"; +import { faPlus, faWandMagicSparkles } from "@fortawesome/free-solid-svg-icons"; import { FontAwesomeIcon } from "@fortawesome/react-fontawesome"; export const RelayOption = ({ @@ -9,6 +9,7 @@ export const RelayOption = ({ ...props }: OptionProps<{ id: string; name: string }>) => { const isCreateOption = props.data.id === "_create"; + const isAutoOption = props.data.id === "_auto"; return ( @@ -18,6 +19,11 @@ export const RelayOption = ({ Deploy New Relay + ) : isAutoOption ? ( +
+ + Auto Select Relay +
) : ( <>

{children}

From f27708bcf60539a5dc39169a93b8592ca71214f1 Mon Sep 17 00:00:00 2001 From: x032205 Date: Wed, 5 Nov 2025 15:59:24 -0500 Subject: [PATCH 3/6] add sudo to gateway start command examples --- docs/cli/commands/gateway.mdx | 28 +++++++++---------- .../platform/gateways/gateway-deployment.mdx | 2 +- .../components/GatewayCliDeploymentMethod.tsx | 2 +- 3 files changed, 16 insertions(+), 16 deletions(-) diff --git a/docs/cli/commands/gateway.mdx b/docs/cli/commands/gateway.mdx index d7e9bb768..028c97e05 100644 --- a/docs/cli/commands/gateway.mdx +++ b/docs/cli/commands/gateway.mdx @@ -6,7 +6,7 @@ description: "Run the Infisical gateway or manage its systemd service" ```bash - infisical gateway start --name= --auth-method= + sudo infisical gateway start --name= --auth-method= ``` @@ -36,7 +36,7 @@ If you are moving from Gateway v1 to Gateway v2, this is NOT a drop-in switch. G Run the Infisical gateway component within your the network where your target resources are located. The gateway establishes an SSH reverse tunnel to a relay server and provides secure access to private resources within your network. ```bash -infisical gateway start --name= --auth-method= +sudo infisical gateway start --name= --auth-method= ``` @@ -74,7 +74,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=universal-auth --client-id= --client-secret= --name= + sudo infisical gateway start --auth-method=universal-auth --client-id= --client-secret= --name= ``` @@ -98,7 +98,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=kubernetes --machine-identity-id= --name= + sudo infisical gateway start --auth-method=kubernetes --machine-identity-id= --name= ``` @@ -119,7 +119,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=azure --machine-identity-id= --name= + sudo infisical gateway start --auth-method=azure --machine-identity-id= --name= ``` @@ -140,7 +140,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=gcp-id-token --machine-identity-id= --name= + sudo infisical gateway start --auth-method=gcp-id-token --machine-identity-id= --name= ``` @@ -162,7 +162,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=gcp-iam --machine-identity-id= --service-account-key-file-path= --name= + sudo infisical gateway start --auth-method=gcp-iam --machine-identity-id= --service-account-key-file-path= --name= ``` @@ -181,7 +181,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=aws-iam --machine-identity-id= --name= + sudo infisical gateway start --auth-method=aws-iam --machine-identity-id= --name= ``` @@ -203,7 +203,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=oidc-auth --machine-identity-id= --jwt= --name= + sudo infisical gateway start --auth-method=oidc-auth --machine-identity-id= --jwt= --name= ``` @@ -227,7 +227,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --auth-method=jwt-auth --jwt= --machine-identity-id= --name= + sudo infisical gateway start --auth-method=jwt-auth --jwt= --machine-identity-id= --name= ``` @@ -243,7 +243,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash - infisical gateway start --token= --name= + sudo infisical gateway start --token= --name= ``` @@ -259,7 +259,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash # Example - infisical gateway start --relay=my-relay --name=my-gateway --token= + sudo infisical gateway start --relay=my-relay --name=my-gateway --token= ``` **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server using `infisical relay start` before connecting gateways to it. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. @@ -271,7 +271,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash # Example - infisical gateway start --name=my-gateway --token= + sudo infisical gateway start --name=my-gateway --token= ``` @@ -281,7 +281,7 @@ The gateway supports multiple authentication methods. Below are the available au ```bash # Example - infisical gateway start --domain=https://app.your-domain.com --name= + sudo infisical gateway start --domain=https://app.your-domain.com --name= ``` diff --git a/docs/documentation/platform/gateways/gateway-deployment.mdx b/docs/documentation/platform/gateways/gateway-deployment.mdx index 5c25914c0..c7b8763c2 100644 --- a/docs/documentation/platform/gateways/gateway-deployment.mdx +++ b/docs/documentation/platform/gateways/gateway-deployment.mdx @@ -173,7 +173,7 @@ To successfully deploy an Infisical Gateway for use, follow these steps in order For development or testing environments: ```bash - infisical gateway start --token --name= + sudo infisical gateway start --token --name= ``` diff --git a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx index 17818f307..fd2e9b444 100644 --- a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx +++ b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/GatewayCliDeploymentMethod.tsx @@ -184,7 +184,7 @@ export const GatewayCliDeploymentMethod = () => { const command = useMemo(() => { const relayPart = relay?.id !== "_auto" ? ` --relay=${relay?.name || ""}` : ""; - return `infisical gateway start --name=${name}${relayPart} --domain=${siteURL} --token=${identityToken}`; + return `sudo infisical gateway start --name=${name}${relayPart} --domain=${siteURL} --token=${identityToken}`; }, [name, relay, identityToken, siteURL]); if (step === "command") { From 261745b622e1b6204eb9693cad0b9fcd634c7ee0 Mon Sep 17 00:00:00 2001 From: x032205 Date: Wed, 5 Nov 2025 16:06:29 -0500 Subject: [PATCH 4/6] lint + fixes --- .../components/GatewayTab/components/RelayOption.tsx | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx index 4f5426a63..256c32288 100644 --- a/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx +++ b/frontend/src/pages/organization/NetworkingPage/components/GatewayTab/components/RelayOption.tsx @@ -14,17 +14,19 @@ export const RelayOption = ({ return (
- {isCreateOption ? ( + {isCreateOption && (
Deploy New Relay
- ) : isAutoOption ? ( + )} + {isAutoOption && (
Auto Select Relay
- ) : ( + )} + {!isCreateOption && !isAutoOption && ( <>

{children}

{isSelected && ( From a17996ca806025857075e19f760e07b414ed8b56 Mon Sep 17 00:00:00 2001 From: x032205 Date: Mon, 10 Nov 2025 12:42:26 -0500 Subject: [PATCH 5/6] addressed reviews --- docs/cli/commands/gateway.mdx | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/docs/cli/commands/gateway.mdx b/docs/cli/commands/gateway.mdx index 028c97e05..48c223a66 100644 --- a/docs/cli/commands/gateway.mdx +++ b/docs/cli/commands/gateway.mdx @@ -53,7 +53,7 @@ Once started, the gateway component will: ### Authentication -The gateway supports multiple authentication methods. Below are the available authentication methods, with their respective flags. +The Gateway supports multiple authentication methods. Below are the available authentication methods, with their respective flags. @@ -262,7 +262,7 @@ The gateway supports multiple authentication methods. Below are the available au sudo infisical gateway start --relay=my-relay --name=my-gateway --token= ``` - **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server using `infisical relay start` before connecting gateways to it. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. + **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. For more information on deploying relays, refer to the [Relay Deployment Guide](/documentation/platform/gateways/relay-deployment). @@ -346,7 +346,7 @@ sudo infisical gateway systemd install --token= --domain= --name= sudo infisical gateway systemd install --relay=my-relay --token= --name= ``` - **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server using `infisical relay start` before connecting gateways to it. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. + **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. For more information on deploying relays, refer to the [Relay Deployment Guide](/documentation/platform/gateways/relay-deployment). @@ -687,7 +687,7 @@ sudo systemctl disable infisical-gateway # Disable auto-start on boot - If the `--relay` flag is omitted, the gateway automatically selects the optimal relay. It first checks for healthy organization relays and connects to the one with the lowest latency. If no organization relays are available, it then performs the same latency-based selection among the available platform relays. + If the `--relay` flag is omitted, the gateway automatically selects the optimal relay. It first checks for healthy organization relays and connects to the one with the lowest latency. If no organization relays are available, it then performs the same latency-based selection among the available managed relays. No. The first time the gateway starts, it selects the optimal relay (based on latency) and caches that selection. On subsequent restarts, it will prioritize connecting to the cached relay. If it's unable to connect, it will then re-evaluate and connect to the next most optimal relay available. From 2f9007d36f657549386c1aed3516232ee1d83dfd Mon Sep 17 00:00:00 2001 From: x032205 Date: Mon, 10 Nov 2025 13:04:58 -0500 Subject: [PATCH 6/6] small docs tweak --- docs/cli/commands/gateway.mdx | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docs/cli/commands/gateway.mdx b/docs/cli/commands/gateway.mdx index 48c223a66..32612938a 100644 --- a/docs/cli/commands/gateway.mdx +++ b/docs/cli/commands/gateway.mdx @@ -262,7 +262,7 @@ The Gateway supports multiple authentication methods. Below are the available au sudo infisical gateway start --relay=my-relay --name=my-gateway --token= ``` - **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. For more information on deploying relays, refer to the [Relay Deployment Guide](/documentation/platform/gateways/relay-deployment). + **Note:** For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. If using organization relays or self-hosted instance relays, you must first start a relay server. For more information on deploying relays, refer to the [Relay Deployment Guide](/documentation/platform/gateways/relay-deployment). @@ -346,7 +346,7 @@ sudo infisical gateway systemd install --token= --domain= --name= sudo infisical gateway systemd install --relay=my-relay --token= --name= ``` - **Note:** If using organization relays or self-hosted instance relays, you must first start a relay server. For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. For more information on deploying relays, refer to the [Relay Deployment Guide](/documentation/platform/gateways/relay-deployment). + **Note:** For Infisical Cloud users using instance relays, the relay infrastructure is already running and managed by Infisical. If using organization relays or self-hosted instance relays, you must first start a relay server. For more information on deploying relays, refer to the [Relay Deployment Guide](/documentation/platform/gateways/relay-deployment).