
Amazon EKS
Deploy Pomerium with Kubernetes and protect workloads that run on Amazon EKS.
Overview
Amazon Elastic Kubernetes Service (Amazon EKS) is the managed Kubernetes service in AWS. AWS operates the Kubernetes control plane. Workloads run on managed or self-managed nodes, or on supported Fargate profiles.
EKS Services can stay on private cluster addresses while selected applications receive identity-aware routes through Kubernetes resources.
Amazon EKS supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in the EKS cluster. Configure the Pomerium custom resource, service exposure, DNS, TLS, persistence, and replicas. Create a Pomerium Ingress for each selected private Service.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private Grafana Service runs in Amazon EKS. Its Ingress selects Pomerium and permits the operations group. Pomerium authenticates the operator and forwards an approved request to the Service.
Considerations
- Pomerium does not protect the EKS control plane or all east-west traffic automatically.
- Validate Fargate, load balancer, storage, architecture, and security-context constraints for the selected cluster.
Sources and official resources
- Amazon EKSOfficial website
- Amazon EKS documentationOfficial documentation
- Pomerium Ingress Controller repositoryOfficial repository
- Amazon EKS integration guideRelated Pomerium guide
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
