Alibaba Cloud
Protect private applications and services that run in Alibaba Cloud.
Overview
Alibaba Cloud is a public cloud platform. Elastic Compute Service provides virtual machines, Virtual Private Cloud provides network isolation, and Alibaba Cloud Container Service for Kubernetes provides managed Kubernetes.
Private applications can span cloud accounts, virtual networks, and compute models. Pomerium gives users a narrow route to selected services without granting broad VPC access.
Alibaba Cloud supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Use a supported Linux Elastic Compute Service instance in a VPC that can reach the protected services. For Kubernetes workloads, use the standard Pomerium Kubernetes deployment path in the selected cluster. Keep Alibaba Cloud IAM and Pomerium route policy as separate controls.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private administration service runs on an Elastic Compute Service instance. Pomerium runs on a separate Linux instance in the same VPC. Pomerium authenticates the user, evaluates route policy, and forwards an approved request to the service.
Considerations
- There is no Alibaba Cloud-native Pomerium service or named infrastructure installer.
- The Pomerium Terraform provider configures a running Pomerium deployment. It does not provision Alibaba Cloud infrastructure.
