Skip to main content
See All Environments

Bottlerocket

Deploy Pomerium through Kubernetes and protect workloads that run on Bottlerocket worker nodes.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Categories
Operating Systems, Container Platforms

Overview

Bottlerocket is a Linux-based operating system from AWS for running containers. It has an image-based update model and a limited host environment. Pomerium should run as a Kubernetes workload or container, not as a host package.

An immutable container host needs an access layer that fits the Kubernetes workload model and does not depend on mutable host packages.

Bottlerocket supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install Pomerium in the Kubernetes cluster that uses Bottlerocket worker nodes. Use the Pomerium custom resource and Ingress resources. Keep host updates and node lifecycle in the Bottlerocket and cluster management system.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

A private Service runs on Bottlerocket-backed Kubernetes nodes. Its Ingress selects Pomerium. Pomerium authenticates the user and forwards an approved request to the Service.

Considerations

  • Run Pomerium as a container on Bottlerocket.
  • There is no Pomerium Bottlerocket host extension or named certification.

Sources and official resources

  • Deploy Pomerium with Kubernetes and protect workloads that run on Amazon EKS.

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Deploy Pomerium through the Kubernetes or container platform that uses containerd as its runtime.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo