
Docker
Run Pomerium with Docker and protect containerized applications and services.
Overview
Docker is a platform and toolset for building and running OCI-compatible containers. Pomerium publishes an official container image and a quickstart that runs Pomerium with a protected application.
Containers give applications a private network boundary, but users still need a secure route. Pomerium can run in the same container model and keep application access policy outside the app.
Docker supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A container runtime that can run the official Pomerium image and provide protected configuration, secrets, storage, and a private path to each upstream service.
- A stable user-facing listener with DNS and TLS for the selected routes.
How it works
Run the official Pomerium container through the environment container runtime. Mount protected configuration and secrets, publish the selected user-facing ports, and provide a network path to each upstream service.
Use the first-party Pomerium quickstart or run the official image with explicit configuration, secrets, networks, ports, health checks, and persistent state. Connect the Pomerium container to a network that can reach each private service.
Check container health, protected configuration and secrets, the private container network, and upstream reachability. Test an allowed request and a denied request. Confirm that direct service exposure cannot bypass Pomerium.
Example
A private web application runs in one Docker container and Pomerium runs in another on a shared private network. User traffic reaches Pomerium first and approved requests go to the application container.
Considerations
- A local quickstart is not a complete production high-availability or secret-management design.
- Pomerium does not manage Docker networking, image policy, host updates, or container orchestration.
