
containerd
Deploy Pomerium through the Kubernetes or container platform that uses containerd as its runtime.
Overview
containerd is an industry-standard container runtime. Kubernetes and other platforms use it to manage container images and processes. It is a low-level runtime, not a complete application platform or access system.
Teams often see containerd in their node inventory but deploy applications through Kubernetes or another orchestrator. The Pomerium instructions must target that owning platform.
containerd supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Use the supported orchestration layer that operates containerd. In Kubernetes, install the Pomerium Kubernetes Ingress Controller. Assign an owner for networking, configuration, secrets, health checks, and lifecycle.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A Kubernetes cluster uses containerd on its nodes. Pomerium runs as a Kubernetes workload and protects selected Services through Ingress resources.
Considerations
- containerd does not provide a complete workload scheduler, ingress controller, secret manager, or service exposure model.
Sources and official resources
- containerdOfficial website
- containerd source repositoryOfficial repository
- Kubernetes container runtimesOfficial documentation
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
