Skip to main content

Pomerium Core

Open-source identity-aware access, self-managed

Install and operate the open-source Pomerium gateway in your environment. Protect selected applications and services with identity-aware route policy.

What this pattern controls

Open source

Inspect the source and run the Pomerium server in infrastructure that you control.

Self-managed

Own configuration, identity-provider setup, certificates, persistence, scaling, and upgrades.

Application access

Protect a selected application or service through an identity-aware route.

Own the software and the operating boundary

Open-source project

The Pomerium server and its configuration are available in the public Core repository.

Route enforcement

Core applies identity-aware policy before it proxies an approved request to a private upstream.

Identity-aware gateway

Put identity and policy in the request path

Core combines the proxy, authentication, authorization, and data-broker services that enforce access to each configured route.

  • Define public-to-private routes in configuration.
  • Connect an OpenID Connect identity provider or use the hosted authenticate service.
  • Write route policy with Pomerium Policy Language.

Self-managed operations

Choose the deployment that fits your infrastructure

You install, configure, scale, and operate Core. The open-source project supports several deployment paths without a Pomerium-managed control plane.

  • Run Core with Docker Compose for a direct starting path.
  • Deploy Core on Kubernetes with the Pomerium Ingress Controller.
  • Use binaries or operating-system packages when those fit your environment.

Deployment paths

Run Core where your private services live

Docker

Start with a compact deployment

Use the Core quickstart to run Pomerium with Docker and Docker Compose.

Kubernetes

Run Core as a Kubernetes ingress

Use the Pomerium Ingress Controller to define routes and policy with Kubernetes resources.

Packages

Run Core on a host

Install a published binary or operating-system package when a container platform is not the right fit.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo