Edge environments
Deploy Pomerium near edge services and apply identity-aware access policy.
Overview
Edge environments place compute and services close to a physical site, device fleet, user group, or data source. An edge site can use a small data center, branch network, industrial location, Kubernetes cluster, virtual machine, or container host. It is a deployment pattern, not one vendor product.
Edge services can sit on private local networks. Pomerium gives approved users a route to the selected application without broad access to every service at the site.
Edge environments supply the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host or Apple silicon Mac that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux or macOS host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Run Pomerium Core at the site or in a connected network. The deployment must accept the user-facing route and reach the local private services. Use separate Pomerium deployments when network boundaries do not allow one data plane to reach all sites.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private maintenance application runs at a manufacturing site. Pomerium runs on a Linux host in the same connected network. It authenticates a technician and forwards an approved request to the local application.
Considerations
- Network reachability, DNS, TLS, upgrades, and local high availability need a site design.
