Skip to main content
See All Environments

Amazon EKS

Deploy Pomerium with Kubernetes and protect workloads that run on Amazon EKS.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Categories
Cloud Platforms, Kubernetes Distributions

Overview

Amazon Elastic Kubernetes Service (Amazon EKS) is the managed Kubernetes service in AWS. AWS operates the Kubernetes control plane. Workloads run on managed or self-managed nodes, or on supported Fargate profiles.

EKS Services can stay on private cluster addresses while selected applications receive identity-aware routes through Kubernetes resources.

Amazon EKS supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install the Pomerium Kubernetes Ingress Controller in the EKS cluster. Configure the Pomerium custom resource, service exposure, DNS, TLS, persistence, and replicas. Create a Pomerium Ingress for each selected private Service.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

A private Grafana Service runs in Amazon EKS. Its Ingress selects Pomerium and permits the operations group. Pomerium authenticates the operator and forwards an approved request to the Service.

Considerations

  • Pomerium does not protect the EKS control plane or all east-west traffic automatically.
  • Validate Fargate, load balancer, storage, architecture, and security-context constraints for the selected cluster.

Sources and official resources

  • Deploy Pomerium in AWS and protect private applications across AWS environments.

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Protect container services that run on AWS Fargate.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo