Skip to main content
See All Environments

Amazon ECS

Deploy Pomerium with container services and protect workloads that run on Amazon ECS.

Official Pomerium container image pattern

Runs the Pomerium container

Categories
Cloud Platforms, Container Platforms

Overview

Amazon Elastic Container Service (Amazon ECS) is an AWS service for running and managing container workloads. ECS can use EC2 instances or AWS Fargate for task compute. The official Pomerium image can fit a reviewed ECS container pattern.

Container services can keep applications on private task addresses. Pomerium can provide the selected user-facing route without exposing the whole container network.

Amazon ECS supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • A container runtime that can run the official Pomerium image and provide protected configuration, secrets, storage, and a private path to each upstream service.
  • A stable user-facing listener with DNS and TLS for the selected routes.

How it works

Run the official Pomerium container through the environment container runtime. Mount protected configuration and secrets, publish the selected user-facing ports, and provide a network path to each upstream service.

Create a task definition for the official Pomerium container. Supply protected configuration and secrets, a stable public listener, health checks, storage when required, and network access to the private services. Treat this as container compatibility, not a named Pomerium ECS installer.

Check container health, protected configuration and secrets, the private container network, and upstream reachability. Test an allowed request and a denied request. Confirm that direct service exposure cannot bypass Pomerium.

Example

Amazon ECS runs a private administration service and a Pomerium task in connected subnets. User traffic reaches Pomerium first. Pomerium authenticates the user and forwards an approved request to the service.

Considerations

  • There is no first-party Pomerium Amazon ECS task definition or deployment guide.
  • Load balancing, service discovery, task networking, secrets, storage, and replica behavior need an explicit ECS design.

Sources and official resources

  • Deploy Pomerium in AWS and protect private applications across AWS environments.

  • Protect container services that run on AWS Fargate.

  • Run Pomerium with Docker and protect containerized applications and services.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo