
Bottlerocket
Deploy Pomerium through Kubernetes and protect workloads that run on Bottlerocket worker nodes.
Overview
Bottlerocket is a Linux-based operating system from AWS for running containers. It has an image-based update model and a limited host environment. Pomerium should run as a Kubernetes workload or container, not as a host package.
An immutable container host needs an access layer that fits the Kubernetes workload model and does not depend on mutable host packages.
Bottlerocket supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install Pomerium in the Kubernetes cluster that uses Bottlerocket worker nodes. Use the Pomerium custom resource and Ingress resources. Keep host updates and node lifecycle in the Bottlerocket and cluster management system.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private Service runs on Bottlerocket-backed Kubernetes nodes. Its Ingress selects Pomerium. Pomerium authenticates the user and forwards an approved request to the Service.
Considerations
- Run Pomerium as a container on Bottlerocket.
- There is no Pomerium Bottlerocket host extension or named certification.
Sources and official resources
- BottlerocketOfficial website
- Bottlerocket source repositoryOfficial repository
- Bottlerocket documentationOfficial documentation
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
