
Azure Kubernetes Service
Deploy Pomerium with Kubernetes and protect workloads that run on Azure Kubernetes Service.
Overview
Azure Kubernetes Service (AKS) is the managed Kubernetes service in Microsoft Azure. Azure manages the control plane. Workloads run in Kubernetes clusters connected to Azure networking and identity services.
AKS Services can stay private while teams publish selected applications through Kubernetes resources and identity-aware Pomerium policy.
Azure Kubernetes Service supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in the AKS cluster. Configure the Pomerium custom resource, service exposure, DNS, certificates, persistence, and replicas. Add a Pomerium Ingress for each protected Service.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private developer portal runs as an AKS Service. Its Ingress selects Pomerium and permits the engineering group. Pomerium forwards approved requests to the Service.
Considerations
- Pomerium does not secure the AKS control plane or every cluster network path.
- Validate the selected AKS network model, load balancer, storage, architecture, and security requirements.
Sources and official resources
- Azure Kubernetes ServiceOfficial website
- Azure Kubernetes Service overviewOfficial documentation
- Pomerium Ingress Controller repositoryOfficial repository
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
