Skip to main content
See All Environments

Cloudflare network services

Use Pomerium as the application access layer behind or beside selected Cloudflare network services.

Adjacent network service pattern

Surrounding network service

Categories
Cloud Platforms, Edge and Hybrid

Overview

Cloudflare provides network, proxy, DNS, and security services. It is not a runtime for Pomerium Core in this model. A deployment can place Cloudflare in front of Pomerium or use selected Cloudflare network services around the Pomerium access route.

A surrounding proxy changes the request and TLS path. Teams need a clear boundary: Cloudflare carries the selected network path, and Pomerium makes the application access decision.

Cloudflare network services supply the surrounding network path. Pomerium runs on a supported adjacent platform and supplies the identity-aware access point.

Prerequisites

  • A supported Pomerium compute environment with a path to the protected service and an explicit path through the surrounding network service.
  • A reviewed plan for TLS, client address handling, origin reachability, and each required application protocol.

How it works

Run Pomerium on a supported compute environment with a network path to the protected service. Configure the surrounding network product to preserve the Pomerium route, TLS, client address, and required protocol behavior.

Run Pomerium on a supported host or cluster near the protected service. For an origin that Cloudflare can reach directly, use a proxied DNS record and restrict direct origin access. For a non-public origin, select a named Cloudflare private-connectivity path and verify its source-IP and protocol limits. Preserve TLS, the correct host, client address information, WebSocket upgrades, and required non-HTTP behavior.

Test host and TLS handling, client address preservation, and required protocol behavior. Confirm that direct access to the protected service cannot bypass Pomerium.

Example

Cloudflare proxies an application name to a reachable Pomerium origin or reaches a non-public Pomerium origin through a selected private-connectivity path. Pomerium authenticates the user and applies route policy before it forwards an approved request to the private application.

Considerations

  • Cloudflare is not a Pomerium deployment environment and does not replace Pomerium identity-aware policy.

Sources and official resources

  • Deploy Pomerium near edge services and apply identity-aware access policy.

  • Deploy Pomerium near services in cloud and private infrastructure and apply one access policy model.

  • Deploy Pomerium near on-premises applications and protect them with identity-aware policy.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo