Bare metal
Deploy Pomerium near services that run on bare-metal infrastructure.
Overview
Bare-metal infrastructure runs an operating system and applications directly on physical servers without a hypervisor layer. It is a deployment model, not one vendor product.
Physical application hosts can stay on private networks while users receive only the route they need. The access layer does not need a virtual machine platform.
Bare-metal infrastructure supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host or Apple silicon Mac that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux or macOS host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Install Pomerium Core on a supported Linux server or run it in a connected container or Kubernetes environment. Place it on a network that can accept the user-facing route and reach the protected physical servers.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private manufacturing application runs on a physical Linux server. Pomerium runs on a second physical gateway server. It authenticates technicians and forwards approved requests to the application.
Considerations
- Hardware management, network segmentation, storage, failover, patches, and host security remain deployment responsibilities.
- Use separate Pomerium deployments for disconnected networks.
