Install on AWS Marketplace
Tyk offers a flexible and powerful API management solution through Tyk Cloud on the AWS Marketplace. Tyk Cloud is an end-to-end managed API platform where both the control plane and gateways are installed on AWS for a seamless, fully cloud-hosted experience. For those who need more deployment flexibility, Tyk Cloud also supports a Hybrid Gateway option. In this setup, the control plane remains hosted and managed by Tyk on AWS, while the gateways can be deployed on your preferred cloud provider or on-premises environment—allowing you to meet data locality and compliance needs without sacrificing control.Available AWS Deployment Regions
You can deploy Tyk Cloud in the following AWS regions:- Singapore:
aws-ap-southeast-1 - Frankfurt, Germany:
aws-eu-central-1 - London, UK:
aws-eu-west-2 - N. Virginia, USA:
aws-us-east-1 - Oregon, USA:
aws-us-west-2 - Australia:
aws-ap-southeast-2
Install Tyk on AWS EC2
-
Spin up an EC2 instance, AWS Linux2 preferably, T2.Medium is fine
- add a public IP
- open up SG access to:
- 3000 for the Tyk Dashboard
- 8080 for the Tyk Gateway
- 22 TCP for SSH
-
SSH into the instance
ssh -i mykey.pem ec2-user@public-ec2-ip -
Install Git, Docker, & Docker Compose
Feel free to copy paste these
-
Clone the Tyk Pro Docker repo
-
Add the license key to
confs/tyk_analytics.confinto thelicense_key variableusing “vi” or “nano”, etc
tyk_analytics.conf, license_key should look something like this, with a real license however:
"license_key": "eyJhbGciOiJSUzI1NiIsInR5cCI...WQ",
-
Run the containers via
docker-compose -
Visit
and fill out the Bootstrap form! If you see any page besides the Bootstrap page, you have pasted the license key incorrectly
- Add the following to
confs/tyk.conf
- Add the following to
confs/tyk_analytics.conf
- Generate self-signed Certs: (Or bring your own CA signed)
- Mount your certs to containers through
docker-compose.yml
- Restart your containers with the mounted files
- Download the bootstrap script onto EC2 machine
- Apply execute permissions to file:
chmod +x bootstrap.sh
- Run the bootstrap script
./bootstrap.sh localhost
- Done! use the generated user and password to log into The Tyk Dashboard
Install with Ansible
RequirementsAnsible is required to run the following commands.
Instructions
-
clone the tyk-ansible repositry
-
cdinto the directory -
Run initialisation script to initialise environment
-
Modify
hosts.ymlfile to update ssh variables to your server(s). You can learn more about the hosts file here -
Run ansible-playbook to install the following:
- Redis
- MongoDB or PostgreSQL
- Tyk Dashboard
- Tyk Gateway
- Tyk Pump
You can choose to not install Redis, MongoDB or PostgreSQL by removing the-t redisor-t mongodbor-t pgsqlHowever Redis and MongoDB or PostgreSQL are a requirement and need to be installed for the Tyk Pro installation to run.For a production environment, we recommend that the Gateway, Dashboard and Pump are installed on separate machines. If installing multiple Gateways, you should install each on a separate machine. See Planning for Production For more details.
Install on Heroku
A full Tyk Self-Managed installation can be deployed to Heroku dynos and workers using Heroku Container Registry and Runtime functionality. This guide will utilize Tyk Docker images with a small amount of customization as well as an external MongoDB service.Prerequisites
- Docker daemon installed and running locally
- Heroku account, the free plan is sufficient for a basic PoC but not recommended for production usage
- Heroku CLI installed
- MongoDB service (such as Atlas, mLab, or your own deployment), this guide is based on MongoDB Atlas but others should work as well
- Tyk License (note that in case of running multiple gateway dynos, license type must match)
- Checkout the Tyk quickstart repository from GitHub
- Python 2 or 3 in order to execute the bootstrap script
Creating Heroku Apps
We will create two Heroku apps, one for the Tyk Gateway (with Redis add-on attached to it) and another for the Dashboard and Pump. Given Heroku CLI is installed and your Heroku account is available, log into it:--space flag must be added to the command if the app is being created in a private space, see more details in the section on Heroku private spaces (below).hobby-dev plan for demonstration purposes but that’s not suitable for production), replacing the app name with your own:
heroku config command and check for the Redis endpoint:
Deploy the Dashboard
It’s recommended to start with the Dashboard so in your Heroku quickstart clone run:Dockerfile.web for the web dyno, a config file for the Dashboard, entrypoint script for the Docker container and a bootstrap script for seeding the dashboard instance with sample data. All these files are editable for your purposes but have sane defaults for a PoC.
You can use the
FROM statement in Dockerfile.web to use specific dashboard version and upgrade when needed instead of relying on the latest tag.tyk_analytics.conf file or injecting them as environment variables via heroku config. In this guide we’ll use the latter for simplicity of demonstration but there is merit to both methods.
First let’s set the license key:
pump.conf file):
analytics directory of the quickstart repo:
dashboard/bootstrap.sh script:
Deploy the Gateway
The process is very similar for the Tyk Gateway, except it doesn’t have a worker process and doesn’t need access to MongoDB.tyk.conf or injected with heroku config.
To get things going we’ll need to set following options for the Dashboard endpoint (substituting the actual endpoint and the app name, now for the gateway app):
heroku logs -a infinite-plains-14949) to check that deployment was successful, also the node should be registered by the Dashboard in “System Management” -> “Nodes and Licenses” section.
You’re ready to follow the guide on creating and managing your APIs with this Heroku deployment.
To use the geographic log distribution feature in the Dashboard please supply the GeoLite2 DB in the
gateway directory, uncomment the marked line in Dockerfile.web and set the analytics_config.enable_geo_ip setting (or TYK_GW_ANALYTICSCONFIG_ENABLEGEOIP env var) to true.Heroku Private Spaces
Most instructions are valid for Heroku Private Spaces runtime. However there are several differences to keep in mind. Heroku app creation commands must include the private space name in the--space flag, e.g.:
private-7. Please refer to Heroku’s Redis with private spaces guide for more information.
Apps in private spaces don’t enable SSL/TLS by default. It needs to be configured in the app settings along with the domain name for it. If it’s not enabled, please make sure that configs that refer to corresponding hosts are using HTTP instead of HTTPS and related ports (80 for HTTP).
Gateway Plugins
In order to enable rich plugins for the Gateway, please set the following Heroku config option to eitherpython or lua depending on the type of plugins used:
Upgrading or Customizing Tyk
Since this deployment is based on Docker images and containers, upgrading or making changes to the deployment is as easy as building a new image and pushing it to the registry. Specifically, upgrading version of any Tyk components is done by editing the correspondingDockerfile and replacing the base image version tag. E.g. changing FROM tykio/tyk-gateway:v2.5.4 to FROM tykio/tyk-gateway:v2.6.1 will pull the Tyk gateway 2.6.1. We highly recommend specifying concrete version tags instead of latest for better house keeping.
Once these changes have been made just run heroku container:push --recursive -a app_name on the corresponding directory as shown previously in this guide. This will do all the building and pushing as well as gracefully deploying on your Heroku app.
Please refer to Heroku documentation on containers and registry for more information.
Install on Microsoft Azure
Azure allows you to install Tyk in the following ways: On-Premises- Via our Ubuntu Setup on an installed Ubuntu Server on Azure.
- Via our Docker Installation using Azure’s Docker support.
We also have a blog post that walks you through installing Tyk on Azure.
Install to Google Cloud
Google Cloud allows you to install Tyk in the following ways: On-Premises- Via our Ubuntu Setup on an installed Ubuntu Server within Google Cloud.
- Via our Docker Installation using Google Cloud’s Docker support.
- Configure Cloud Run to have the CPU always allocated option enabled. Otherwise, the Tyk Pump container needs to warm up, which takes approximately 1 min. Subsequently, by this time the stats are removed from Redis.
- Update the Tyk Gateway configuration to keep the stats for 3 mins to allow Tyk Pump to process them. This value should be greater than the Pump purge delay to ensure the analytics data exists long enough in Redis to be processed by the Pump.