Skip to main content
See All Environments

Google Kubernetes Engine

Deploy Pomerium with Kubernetes and protect workloads that run on Google Kubernetes Engine.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Categories
Cloud Platforms, Kubernetes Distributions

Overview

GKE is Google Cloud's managed Kubernetes service. Google manages the control plane. Workloads run on cluster nodes, and Kubernetes Services give those workloads stable network identities.

GKE Services can stay on private cluster addresses while selected applications receive identity-aware routes through Kubernetes resources.

Google Kubernetes Engine supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install the Pomerium Kubernetes Ingress Controller in the GKE cluster. Define global settings with the Pomerium custom resource and create a Pomerium Ingress for each selected Service.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

A private Grafana Service runs in GKE. Its Ingress selects Pomerium and requires an engineering group. Pomerium authenticates the user and forwards an approved request to the Service.

Considerations

  • Pomerium does not manage the GKE control plane, node lifecycle, Google Cloud IAM, or all east-west traffic.

Sources and official resources

  • Deploy Pomerium in Google Cloud and protect private applications across Google Cloud environments.

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Deploy Pomerium near services in cloud and private infrastructure and apply one access policy model.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo