---
title: "Create a Gateway"
method: POST
path: "/networking/v1/gateways"
tags: ["Gateways (networking/v1)"]
---

# Create a Gateway

`POST /networking/v1/gateways`

[![General Availability](https://img.shields.io/badge/Lifecycle%20Stage-General%20Availability-%2345c6e8)](#section/Versioning/API-Lifecycle-Policy)

Make a request to create a gateway.

## Request body

- object — A Gateway represents a slice of traffic capacity in a region that is reserved for a customer. ## The Gateways Model <SchemaDefinition schemaRef="#/components/schemas/networking.v1.Gateway" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `gateways_per_region_per_environment` | Number of Gateways per region per environment |
  - `api_version` 'networking/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'Gateway' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `spec` object, required — The desired state of the Gateway
    - `display_name` string — The name of the gateway.
    - `config` union, required — Gateway type specific configuration. Please note that Peering configs are not supported in Create requests.
      - object — AWS Egress Private Link Gateway details from AWS.
        - `kind` 'AwsEgressPrivateLinkGatewaySpec', required — AWS Egress Private Link Gateway Spec kind type.
        - `region` string, required — AWS region of the Egress Private Link Gateway.
      - object — AWS Private Network Interface Gateway details from AWS.
        - `kind` 'AwsPrivateNetworkInterfaceGatewaySpec', required — AWS Private Network Interface Gateway Spec kind type.
        - `region` string, required — AWS region of the Private Network Interface Gateway.
        - `zones` string[], required — AWS availability zone ids of the Private Network Interface Gateway.
      - object — AWS Ingress Private Link Gateway details from AWS.
        - `kind` 'AwsIngressPrivateLinkGatewaySpec', required — AWS Ingress Private Link Gateway Spec kind type.
        - `region` string, required — AWS region of the Ingress Private Link Gateway.
      - object — AWS Peering Gateway details from AWS.
        - `kind` 'AwsPeeringGatewaySpec', required — AWS Peering Gateway Spec kind type.
        - `region` string, required — AWS region of the Peering Gateway.
      - object — Azure Peering Gateway details from Azure.
        - `kind` 'AzurePeeringGatewaySpec', required — Azure Peering Gateway Spec kind type.
        - `region` string, required — Azure region of the Peering Gateway.
      - object — Azure Egress Private Link Gateway details from Azure.
        - `kind` 'AzureEgressPrivateLinkGatewaySpec', required — Azure Egress Private Link Gateway Spec kind type.
        - `region` string, required — Azure region of the Egress Private Link Gateway.
      - object — Azure Ingress Private Link Gateway details from Azure.
        - `kind` 'AzureIngressPrivateLinkGatewaySpec', required — Azure Ingress Private Link Gateway Spec kind type.
        - `region` string, required — Azure region of the Ingress Private Link Gateway.
      - object — GCP Peering Gateway details.
        - `kind` 'GcpPeeringGatewaySpec', required — GCP Peering Gateway Spec kind type.
        - `region` string, required — GCP region of the Peering Gateway.
      - object — GCP Private Service Connect Gateway details from GCP.
        - `kind` 'GcpEgressPrivateServiceConnectGatewaySpec', required — GCP Private Service Connect Gateway Spec kind type.
        - `region` string, required — GCP region of the Egress Private Service Connect Gateway.
      - object — GCP Ingress Private Service Connect Gateway details from GCP.
        - `kind` 'GcpIngressPrivateServiceConnectGatewaySpec', required — GCP Ingress Private Service Connect Gateway Spec kind type.
        - `region` string, required — GCP region of the Ingress Private Service Connect Gateway.
    - `environment` object, required — The environment to which this belongs.
      - `id` string, required — ID of the referred resource
      - `environment` string — Environment of the referred resource, if env-scoped
      - `related` string, uri, required — API URL for accessing or modifying the referred object
      - `resource_name` string, uri, required — CRN reference to the referred resource
      - `api_version` string — API group and version of the referred resource
      - `kind` string — Kind of the referred resource
  - `status` NetworkingV1GatewayStatus — The status of the Gateway
    - `phase` string, required — The lifecycle phase of the gateway: CREATED: gateway exists without an Access Point. PROVISIONING: gateway provisioning is in progress; READY: gateway is ready; FAILED: gateway is in a failed state; DEPROVISIONING: gateway deprovisioning is in progress; EXPIRED: gateway has timed out waiting for connections, can only be deleted;
    - `error_code` string — Error code if gateway is in a failed state. May be used for programmatic error checking.
    - `error_message` string — Displayable error message if gateway is in a failed state
    - `cloud_gateway` union — Gateway type specific status.
      - object — AWS Egress Private Link Gateway details from AWS.
        - `kind` 'AwsEgressPrivateLinkGatewayStatus', required — AWS Egress Private Link Gateway Status kind type.
        - `principal_arn` string — The principal ARN used by the AWS Egress Private Link Gateway.
      - object — AWS Ingress Private Link Gateway details from AWS.
        - `kind` 'AwsIngressPrivateLinkGatewayStatus', required — AWS Ingress Private Link Gateway Status kind type.
        - `vpc_endpoint_service_name` string — The ID of the AWS VPC Endpoint Service that can be used to establish connections for all zones.
      - object — AWS Private Network Interface Gateway details from AWS.
        - `kind` 'AwsPrivateNetworkInterfaceGatewayStatus', required — AWS Private Network Interface Gateway Status kind type.
        - `account` string — The AWS account ID associated with the Private Network Interface Gateway.
      - object — Azure Egress Private Link Gateway details from Azure.
        - `kind` 'AzureEgressPrivateLinkGatewayStatus', required — Azure Egress Private Link Gateway Status kind type.
        - `subscription` string — The Azure Subscription ID associated with the Confluent Cloud VPC.
      - object — Azure Ingress Private Link Gateway details from Azure.
        - `kind` 'AzureIngressPrivateLinkGatewayStatus', required — Azure Ingress Private Link Gateway Status kind type.
        - `private_link_service_alias` string — Alias of the Confluent Cloud Private Link Service.
        - `private_link_service_resource_id` string — Resource ID of the Confluent Cloud Private Link Service.
      - object — GCP Peering Gateway details from GCP.
        - `kind` 'GcpPeeringGatewayStatus', required — GCP Peering Gateway Status kind type.
        - `iam_principal` string — The IAM principal email used by the GCP Peering Gateway.
      - object — GCP Private Service Connect Gateway details from GCP.
        - `kind` 'GcpEgressPrivateServiceConnectGatewayStatus', required — GCP Private Service Connect Gateway Status kind type.
        - `project` string — The GCP project used by the GCP Private Service Connect Gateway.
      - object — GCP Ingress Private Service Connect Gateway details from GCP.
        - `kind` 'GcpIngressPrivateServiceConnectGatewayStatus', required — GCP Ingress Private Service Connect Gateway Status kind type.
        - `private_service_connect_service_attachment` string — URI of the Private Service Connect Service Attachment in Confluent Cloud.

## Response `202`

A Gateway is being created.

- object — A Gateway represents a slice of traffic capacity in a region that is reserved for a customer. ## The Gateways Model <SchemaDefinition schemaRef="#/components/schemas/networking.v1.Gateway" /> ## Quotas and Limits This resource is subject to the [following quotas](https://docs.confluent.io/cloud/current/quotas/overview.html): | Quota | Description | | --- | --- | | `gateways_per_region_per_environment` | Number of Gateways per region per environment |
  - `api_version` 'networking/v1' — APIVersion defines the schema version of this representation of a resource.
  - `kind` 'Gateway' — Kind defines the object this REST resource represents.
  - `id` string — ID is the "natural identifier" for an object within its scope/namespace; it is normally unique across time but not space. That is, you can assume that the ID will not be reclaimed and reused after an object is deleted ("time"); however, it may collide with IDs for other object `kinds` or objects of the same `kind` within a different scope/namespace ("space").
  - `metadata` object — ObjectMeta is metadata that all persisted resources must have, which includes all objects users must create.
    - `self` string, uri, required — Self is a Uniform Resource Locator (URL) at which an object can be addressed. This URL encodes the service location, API version, and other particulars necessary to locate the resource at a point in time
    - `resource_name` string, uri — Resource Name is a Uniform Resource Identifier (URI) that is globally unique across space and time. It is represented as a Confluent Resource Name
    - `created_at` string, date-time — The date and time at which this object was created. It is represented in RFC3339 format and is in UTC.
    - `updated_at` string, date-time — The date and time at which this object was last updated. It is represented in RFC3339 format and is in UTC.
    - `deleted_at` string, date-time — The date and time at which this object was (or will be) deleted. It is represented in RFC3339 format and is in UTC.
  - `spec` object, required — The desired state of the Gateway
    - `display_name` string — The name of the gateway.
    - `config` union, required — Gateway type specific configuration. Please note that Peering configs are not supported in Create requests.
      - object — AWS Egress Private Link Gateway details from AWS.
        - `kind` 'AwsEgressPrivateLinkGatewaySpec', required — AWS Egress Private Link Gateway Spec kind type.
        - `region` string, required — AWS region of the Egress Private Link Gateway.
      - object — AWS Private Network Interface Gateway details from AWS.
        - `kind` 'AwsPrivateNetworkInterfaceGatewaySpec', required — AWS Private Network Interface Gateway Spec kind type.
        - `region` string, required — AWS region of the Private Network Interface Gateway.
        - `zones` string[], required — AWS availability zone ids of the Private Network Interface Gateway.
      - object — AWS Ingress Private Link Gateway details from AWS.
        - `kind` 'AwsIngressPrivateLinkGatewaySpec', required — AWS Ingress Private Link Gateway Spec kind type.
        - `region` string, required — AWS region of the Ingress Private Link Gateway.
      - object — AWS Peering Gateway details from AWS.
        - `kind` 'AwsPeeringGatewaySpec', required — AWS Peering Gateway Spec kind type.
        - `region` string, required — AWS region of the Peering Gateway.
      - object — Azure Peering Gateway details from Azure.
        - `kind` 'AzurePeeringGatewaySpec', required — Azure Peering Gateway Spec kind type.
        - `region` string, required — Azure region of the Peering Gateway.
      - object — Azure Egress Private Link Gateway details from Azure.
        - `kind` 'AzureEgressPrivateLinkGatewaySpec', required — Azure Egress Private Link Gateway Spec kind type.
        - `region` string, required — Azure region of the Egress Private Link Gateway.
      - object — Azure Ingress Private Link Gateway details from Azure.
        - `kind` 'AzureIngressPrivateLinkGatewaySpec', required — Azure Ingress Private Link Gateway Spec kind type.
        - `region` string, required — Azure region of the Ingress Private Link Gateway.
      - object — GCP Peering Gateway details.
        - `kind` 'GcpPeeringGatewaySpec', required — GCP Peering Gateway Spec kind type.
        - `region` string, required — GCP region of the Peering Gateway.
      - object — GCP Private Service Connect Gateway details from GCP.
        - `kind` 'GcpEgressPrivateServiceConnectGatewaySpec', required — GCP Private Service Connect Gateway Spec kind type.
        - `region` string, required — GCP region of the Egress Private Service Connect Gateway.
      - object — GCP Ingress Private Service Connect Gateway details from GCP.
        - `kind` 'GcpIngressPrivateServiceConnectGatewaySpec', required — GCP Ingress Private Service Connect Gateway Spec kind type.
        - `region` string, required — GCP region of the Ingress Private Service Connect Gateway.
    - `environment` object, required — The environment to which this belongs.
      - `id` string, required — ID of the referred resource
      - `environment` string — Environment of the referred resource, if env-scoped
      - `related` string, uri, required — API URL for accessing or modifying the referred object
      - `resource_name` string, uri, required — CRN reference to the referred resource
      - `api_version` string — API group and version of the referred resource
      - `kind` string — Kind of the referred resource
  - `status` NetworkingV1GatewayStatus, required — The status of the Gateway
    - `phase` string, required — The lifecycle phase of the gateway: CREATED: gateway exists without an Access Point. PROVISIONING: gateway provisioning is in progress; READY: gateway is ready; FAILED: gateway is in a failed state; DEPROVISIONING: gateway deprovisioning is in progress; EXPIRED: gateway has timed out waiting for connections, can only be deleted;
    - `error_code` string — Error code if gateway is in a failed state. May be used for programmatic error checking.
    - `error_message` string — Displayable error message if gateway is in a failed state
    - `cloud_gateway` union — Gateway type specific status.
      - object — AWS Egress Private Link Gateway details from AWS.
        - `kind` 'AwsEgressPrivateLinkGatewayStatus', required — AWS Egress Private Link Gateway Status kind type.
        - `principal_arn` string — The principal ARN used by the AWS Egress Private Link Gateway.
      - object — AWS Ingress Private Link Gateway details from AWS.
        - `kind` 'AwsIngressPrivateLinkGatewayStatus', required — AWS Ingress Private Link Gateway Status kind type.
        - `vpc_endpoint_service_name` string — The ID of the AWS VPC Endpoint Service that can be used to establish connections for all zones.
      - object — AWS Private Network Interface Gateway details from AWS.
        - `kind` 'AwsPrivateNetworkInterfaceGatewayStatus', required — AWS Private Network Interface Gateway Status kind type.
        - `account` string — The AWS account ID associated with the Private Network Interface Gateway.
      - object — Azure Egress Private Link Gateway details from Azure.
        - `kind` 'AzureEgressPrivateLinkGatewayStatus', required — Azure Egress Private Link Gateway Status kind type.
        - `subscription` string — The Azure Subscription ID associated with the Confluent Cloud VPC.
      - object — Azure Ingress Private Link Gateway details from Azure.
        - `kind` 'AzureIngressPrivateLinkGatewayStatus', required — Azure Ingress Private Link Gateway Status kind type.
        - `private_link_service_alias` string — Alias of the Confluent Cloud Private Link Service.
        - `private_link_service_resource_id` string — Resource ID of the Confluent Cloud Private Link Service.
      - object — GCP Peering Gateway details from GCP.
        - `kind` 'GcpPeeringGatewayStatus', required — GCP Peering Gateway Status kind type.
        - `iam_principal` string — The IAM principal email used by the GCP Peering Gateway.
      - object — GCP Private Service Connect Gateway details from GCP.
        - `kind` 'GcpEgressPrivateServiceConnectGatewayStatus', required — GCP Private Service Connect Gateway Status kind type.
        - `project` string — The GCP project used by the GCP Private Service Connect Gateway.
      - object — GCP Ingress Private Service Connect Gateway details from GCP.
        - `kind` 'GcpIngressPrivateServiceConnectGatewayStatus', required — GCP Ingress Private Service Connect Gateway Status kind type.
        - `private_service_connect_service_attachment` string — URI of the Private Service Connect Service Attachment in Confluent Cloud.

## Other responses

- `400` — Bad Request
- `401` — The request lacks valid authentication credentials for this resource.
- `402` — The request would exceed one or more quotas.
- `403` — The access credentials were considered insufficient to grant access
- `409` — The request is in conflict with the current server state
- `422` — Validation Failed
- `429` — Rate Limit Exceeded
- `500` — Oops, something went wrong!

---

[API](https://skmtc.dev/confluent/apis/confluent-cloud-apis.md) · [All operations](https://skmtc.dev/confluent/apis/confluent-cloud-apis/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/confluent/confluent-cloud-apis/revisions/a6a73f98a698/schema)
