IBM Cloud
Deploy Pomerium in IBM Cloud and protect private applications and services.
Overview
IBM Cloud is a cloud platform with virtual private cloud networks, virtual server instances, Kubernetes services, storage, databases, and other managed services.
Private IBM Cloud services can span compute models. Pomerium adds one identity-aware application route without exposing the whole virtual network.
IBM Cloud supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Run Pomerium Core on a supported Linux virtual server instance in a network that can reach the private services. For IBM Cloud Kubernetes Service, use the standard Pomerium Kubernetes deployment path.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private administration application runs on a virtual server instance. Pomerium runs on a separate Linux instance in the same VPC and forwards approved requests.
Considerations
- IBM Cloud IAM and Pomerium route policy remain separate systems.
