Operations guide¶
This section is the how-to-run-it guide for HOG: installing it, writing its configuration, wiring authentication and authorization, turning on observability, hardening it for production, scaling it, and diagnosing problems.
Running HOG always comes down to the same three things:
- A binary.
hog(or a custom binary composed withhog-build— see developer: building a custom binary). - A config directory. A single YAML file or a directory of
*.yaml/*.ymlfiles, by default/etc/hog, holding yourGateway,Route, and other resources. - Content, if you're serving one. A directory of static assets (a
single-page app build, typically
/srv/web) that astaticroute serves.
The entrypoint takes one flag:
--config accepts either a single file or a directory; when it's a
directory, files load in lexical filename order and that order becomes the
document order used to resolve plugin and policy layering. Every value in
the config supports ${ENV} interpolation, resolved once at startup.
In this section¶
- Installation and images — the
hog-runtime/hog-static/hog-builderimage family and how to run them. - Configuration reference — every resource kind and
specfield, with minimal and annotated YAML examples. - Authentication — wiring OIDC login, sessions, and protected routes.
- Authorization — writing and applying
Policyresources. - Observability — enabling OpenTelemetry traces, metrics, and the access log.
- Security hardening — a checklist for running HOG safely in production.
- Scaling and availability — how HOG scales horizontally and what state (if any) it needs to share.
- Troubleshooting — common failure symptoms, their causes, and fixes.