
K3s
Deploy Pomerium with Kubernetes and protect workloads that run on K3s.
Overview
K3s is a lightweight, conformant Kubernetes distribution. It packages Kubernetes and selected supporting services for edge sites, development systems, and smaller clusters while using standard Kubernetes APIs.
K3s Services can remain private at edge and small-cluster sites while Pomerium publishes only the applications that users need.
K3s supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in the K3s cluster. Configure service exposure, DNS, certificates, persistence, replicas, and the K3s high-availability design where required.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private monitoring Service runs in an edge K3s cluster. Its Ingress selects Pomerium and permits the operations group. Pomerium forwards approved requests to the Service.
Considerations
- K3s datastore, cluster lifecycle, service exposure, storage, and high availability remain deployment responsibilities.
