
Google Anthos
Understand how legacy Google Anthos environments map to current GKE and connected Kubernetes deployment patterns for Pomerium.
Overview
Google Anthos is a legacy product name. Google moved former Anthos and GKE Enterprise capabilities into the current Google Kubernetes Engine product and archived the former GKE Enterprise documentation. Use the current GKE and Kubernetes deployment guidance.
The current GKE, attached cluster, or Google Distributed Cloud product supplies the Kubernetes runtime. Pomerium runs in the selected current cluster. The Anthos name remains only as a discovery term.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Identify the current GKE or connected Kubernetes cluster that replaced the former Anthos environment. Install the Pomerium Kubernetes Ingress Controller in that cluster and use current Kubernetes resources and Google product guidance.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A team finds an old architecture document that names Anthos. The current workload runs in GKE. The team installs Pomerium in the GKE cluster and protects the selected Service with a Pomerium Ingress.
Considerations
- Legacy names do not prove current feature parity, product support, or compatibility.
