Container Image Registries
You can pull Connector images from either of these registries:- AWS ECR:
654654333078.dkr.ecr.<region>.amazonaws.com/formalco-prod-connector:<tag>Available regions:us-east-1,us-west-1,us-west-2,ap-southeast-1, andeu-west-1. - GCP Artifact Registry:
us-docker.pkg.dev/formal-public-assets/formalco-prod-connector/formalco-prod-connector:<tag>
On AKS, use the GAR image with
azure-gar-cred.
Set pullWithCredentials: true in the Connector Helm values.Amazon ECR Pull-Through Cache
You can cache Formal images in your own Amazon ECR registry with an ECR pull-through cache rule. Your clusters then pull from your registry, so they need no Formal image pull secret. Formal must first allowlist your AWS account ID or organization ID for ECR pulls. Contact Formal support to request access.-
Create an IAM role for the cache
Amazon ECR assumes this role to pull from Formal’s registry. Save this trust policy as
ptc-trust.json:Save this permissions policy asptc-permissions.json:Create the role: -
Create the pull-through cache rule
Run this in the AWS account and region of your registry.
Set
--upstream-registry-urlto a Formal ECR region listed above. -
Pull through your registry
Prefix Formal repository names with
formal/and use your registry host:In the Connector Helm chart, setimage.repositoryto this value and keeppullWithCredentials: false.
Amazon ECR checks Formal’s registry for tag updates at most once every 24 hours.
Pin versioned tags instead of
latest.
Keep cached repositories tag-mutable, or cached tags stop updating.Infrastructure Requirements
- Operating System: Linux environment
- Architecture: AMD64 or ARM64
- Container Runtime: Docker or compatible container runtime
Network Requirements
The Connector requires:- Network access to
api.joinformal.com(Formal Control Plane) - Outbound access to your protected resources
- Inbound access from clients on configured listener ports
AWS VPC Private Link Connectivity
For customers deploying on AWS, the Connector can connect to the Formal Control Plane using AWS VPC Private Link instead of traversing the public internet. This provides enhanced security and network isolation. Service Details:- Service Name:
com.amazonaws.vpce.eu-west-1.vpce-svc-01bfea09d5ec08d36 - Region:
eu-west-1 - Endpoint Type: Interface (services that use NLBs or GWLBs)
-
Create VPC Endpoint
Using AWS Console:
- Navigate to VPC → Endpoints → Create Endpoint
- Select Other endpoint services
- Enter service name:
com.amazonaws.vpce.eu-west-1.vpce-svc-01bfea09d5ec08d36 - Click Verify service
- Select your VPC and subnets where the Connector is deployed
- Configure security groups to allow outbound HTTPS traffic (port 443) from the Connector
- Important: Check Enable Private DNS Name
- If your VPC is in a region other than
eu-west-1, enable Cross-region endpoint and specifyeu-west-1as the target region - Review and create the endpoint
-
Configuration Requirements
- Private DNS: Must be enabled for proper DNS resolution of Control Plane endpoints
- Cross-region Support: Required if your VPC is in any region other than
eu-west-1 - Security Groups: Must allow outbound HTTPS (port 443) from Connector to VPC endpoint
- Network ACLs: Ensure subnet ACLs permit traffic to/from the VPC endpoint
-
Verify Connectivity
Once the endpoint is in Available state, test from your Connector instance:
The VPC endpoint uses Private DNS to automatically redirect
api.joinformal.com traffic through the private connection. No configuration changes are needed on the Connector side.Resource Requirements
The Connector requires adequate resources to apply policies with minimal latency and maintain all necessary context in RAM (Control Plane data, queries metadata, responses data, log buffer, etc.).Production Recommendations
For production deployments, we recommend:- High Availability: Run at least 2 nodes behind a load balancer
- Resource Allocation: 2 CPU cores and 4 GB RAM per node
- Load Distribution: Distribute traffic across multiple Connector instances
- Persistent Storage: Mount a persistent volume to
/formal/logsfor the log spool
When deploying multiple instances, Connectors attempt automatically to form a cluster with shared state. It enables Connectors to coordinate rate limiting across all instances. See the Clustering page for details.
Recommended Deployment Options
AWS ECS Fargate
Deploy as a Fargate service behind a Network Load Balancer with multi-AZ
availability
Kubernetes
Deploy using Formal Helm charts on any Kubernetes cluster (EKS, GKE, AKS, on-premises).
Docker
Run as a standalone container (development/testing only)