
Google Kubernetes Engine
Deploy Pomerium with Kubernetes and protect workloads that run on Google Kubernetes Engine.
Overview
GKE is Google Cloud's managed Kubernetes service. Google manages the control plane. Workloads run on cluster nodes, and Kubernetes Services give those workloads stable network identities.
GKE Services can stay on private cluster addresses while selected applications receive identity-aware routes through Kubernetes resources.
Google Kubernetes Engine supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in the GKE cluster. Define global settings with the Pomerium custom resource and create a Pomerium Ingress for each selected Service.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private Grafana Service runs in GKE. Its Ingress selects Pomerium and requires an engineering group. Pomerium authenticates the user and forwards an approved request to the Service.
Considerations
- Pomerium does not manage the GKE control plane, node lifecycle, Google Cloud IAM, or all east-west traffic.
Sources and official resources
- Google Kubernetes EngineOfficial website
- Pomerium Ingress Controller repositoryOfficial repository
- Google Kubernetes Engine integration guideRelated Pomerium guide
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
