
Google Cloud Run
Protect applications and services that run on Google Cloud Run.
Overview
Google Cloud Run is a managed platform for running containerized HTTP services. A Pomerium route can protect a Cloud Run service as an upstream and use Google Cloud serverless authentication where the documented design requires it.
A Cloud Run service can stay private while Pomerium supplies the user sign-in and policy layer and the upstream receives a valid Google serverless identity.
Google Cloud Run supplies the protected service, client, or surrounding network. Pomerium runs on a supported adjacent platform and supplies the identity-aware access point.
Prerequisites
- A private Google Cloud Run service and a Pomerium deployment on a supported host or cluster that can reach it.
- A Google service account with the exact Cloud Run Invoker permission and the route settings required for Google-signed upstream authentication.
How it works
Run Pomerium on a supported host or cluster in front of the serverless upstream. Configure the documented upstream authentication and route behavior for the selected service.
Use the first-party Pomerium Cloud Run guide. Run Pomerium where it can reach the service and obtain the required Google identity token. Configure the exact Cloud Run audience, upstream address, and Pomerium route policy.
Test the exact audience and upstream authentication with an allowed request and a denied request. Confirm that direct origin access is blocked.
Example
A private Cloud Run administration service accepts requests only from an authorized serverless identity. Pomerium authenticates the user, applies route policy, adds the required upstream identity token, and forwards an approved request.
Considerations
- Run Pomerium on a supported host or cluster that can reach the Cloud Run service.
- The Pomerium Kubernetes Ingress Controller does not support signed serverless upstream authentication for this path.
