Skip to main content
See All Environments

Hybrid cloud

Deploy Pomerium near services in cloud and private infrastructure and apply one access policy model.

Pomerium Core deployment pattern

Runs Pomerium Core

Categories
Cloud Platforms, Edge and Hybrid, Private Infrastructure

Overview

A hybrid cloud combines two or more distinct cloud infrastructures that remain separate but support application or data portability. A common design combines public cloud services with private cloud or on-premises infrastructure.

Applications can sit behind different network boundaries and teams. Users need consistent access policy without receiving broad network access to every environment.

Hybrid cloud supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • A supported Linux host or Apple silicon Mac that can accept the user-facing route and reach the private upstream service.
  • DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.

How it works

Run Pomerium Core on a supported Linux or macOS host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.

Run an independent Pomerium Core deployment in each network boundary that needs a local access point. Pomerium Enterprise can manage multiple Core clusters, but each cluster keeps its own routes, policy, certificates, secret, storage, and network reachability.

Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.

Example

An operations tool runs on-premises and a build dashboard runs in a public cloud. Each environment has a local Pomerium Core cluster. Approved traffic stays on the path from the local cluster to its service.

Considerations

  • Each Pomerium Core instance needs a network route to the services it protects.
  • Enterprise routes and policies remain scoped to each managed cluster.

Sources and official resources

  • Deploy Pomerium in Google Cloud and protect private applications across Google Cloud environments.

  • Deploy Pomerium near on-premises applications and protect them with identity-aware policy.

  • Deploy Pomerium near edge services and apply identity-aware access policy.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo