
Flatcar Container Linux
Run Pomerium as a container or Kubernetes workload near services on Flatcar Container Linux.
Overview
Flatcar Container Linux is a minimal, immutable, container-optimized Linux operating system. It is the active successor to CoreOS Container Linux and runs on cloud platforms, virtual machines, and bare-metal systems.
Immutable hosts need an access layer that fits the container runtime and update model without depending on mutable host packages.
Flatcar Container Linux supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A container runtime that can run the official Pomerium image and provide protected configuration, secrets, storage, and a private path to each upstream service.
- A stable user-facing listener with DNS and TLS for the selected routes.
How it works
Run the official Pomerium container through the environment container runtime. Mount protected configuration and secrets, publish the selected user-facing ports, and provide a network path to each upstream service.
Run the official Pomerium container through the runtime configured for the Flatcar host. Supply configuration and secrets through the site provisioning process. When Flatcar nodes form a Kubernetes cluster, use the Pomerium Kubernetes deployment path.
Check container health, protected configuration and secrets, the private container network, and upstream reachability. Test an allowed request and a denied request. Confirm that direct service exposure cannot bypass Pomerium.
Example
A private administration service runs in containers on Flatcar virtual machines. Pomerium runs in a connected container and forwards only approved requests to the service.
Considerations
- Run Pomerium as a container on Flatcar.
- There is no Pomerium Flatcar extension, image, or named certification.
