Skip to main content
See All Environments

Amazon Web Services

Deploy Pomerium in AWS and protect private applications across AWS environments.

Pomerium deployment pattern

Runs Pomerium Core

Category
Cloud Platforms

Overview

Amazon Web Services (AWS) is a public cloud platform. An AWS environment can contain VPC networks, EC2 virtual machines, ECS container services, EKS Kubernetes clusters, managed databases, and application services.

Teams often keep administrative tools, dashboards, APIs, and business applications inside private AWS networks. These services can span accounts, VPCs, Regions, and compute models. Pomerium gives users one identity-aware route model for the selected services.

AWS supplies the deployment environment. Pomerium supplies the identity-aware access point. Identity and context data move toward Pomerium. Approved application traffic moves from Pomerium toward the private AWS service.

How it works

Run Pomerium Core on a Linux EC2 instance with the official binary, operating system package, or Docker image. For applications in Amazon EKS, install the Pomerium Kubernetes Ingress Controller in the cluster.

Place Pomerium in a VPC or connected network that can reach the protected services. Configure DNS and TLS for the user-facing route. Keep the upstream service on a private address when the network design lets Pomerium reach it.

Use the documented storage and high-availability options when the deployment needs multiple Pomerium replicas.

Example

An internal administration application runs behind an internal load balancer in private subnets. Create a Pomerium route from the public application name to the internal service address. The request reaches Pomerium first. Pomerium authenticates the user and evaluates the route policy. It forwards an approved request to the internal load balancer. It does not forward a denied request.

Considerations

  • Pomerium is not an AWS-native service or an AWS IAM integration.
  • DNS, TLS, load balancers, routing, and inbound access depend on the selected architecture.
  • The Pomerium Terraform provider manages Pomerium configuration. It does not deploy the AWS infrastructure for this pattern.

Sources and official resources

  • Deploy Pomerium with Kubernetes and protect workloads that run on Amazon EKS.

  • Deploy Pomerium with container services and protect workloads that run on Amazon ECS.

  • Protect container services that run on AWS Fargate.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo