
Google Cloud
Deploy Pomerium in Google Cloud and protect private applications across Google Cloud environments.
Overview
Google Cloud is a public cloud platform. It includes Compute Engine virtual machines, Google Kubernetes Engine clusters, Cloud Run services, storage, networking, databases, and other managed services. This is the umbrella infrastructure page.
Private Google Cloud applications can span projects, networks, and runtimes. Pomerium gives users a narrow route to each selected service.
Google Cloud supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Run Pomerium Core on a supported Linux Compute Engine instance in a network that can reach the protected services. Use the separate GKE and Cloud Run pages for those specific runtime models.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
An internal administration service runs behind a private load balancer. Pomerium runs on a Linux Compute Engine instance in a connected network and forwards only approved requests.
Considerations
- The Pomerium Terraform provider does not provision Google Cloud infrastructure.
