
DigitalOcean
Deploy Pomerium in DigitalOcean and protect private applications and services.
Overview
DigitalOcean is a cloud platform that provides Droplet virtual machines, virtual private cloud networking, load balancers, and managed Kubernetes.
Private cloud applications can stay on VPC addresses while selected users receive one controlled application route.
DigitalOcean supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Run Pomerium Core on a supported Linux Droplet in a VPC that can reach the protected services. For DigitalOcean Kubernetes workloads, use the standard Pomerium Kubernetes deployment path.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private administration application runs on a Droplet. Pomerium runs on a separate Ubuntu Droplet in the same VPC and forwards only approved requests.
Considerations
- There is no DigitalOcean-native Pomerium service or first-party infrastructure installer.
- The Pomerium Terraform provider does not provision DigitalOcean infrastructure.
