Skip to main content
See All Environments

Kubernetes

Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

First-party Pomerium Kubernetes guide

Runs in Kubernetes

Categories
Container Platforms, Kubernetes Distributions

Overview

Kubernetes, also called K8s, is an open-source platform for running and managing containerized workloads. A cluster has a control plane and one or more nodes. Services give workloads stable network identities.

Many Kubernetes Services are reachable only through the cluster network. Teams can expose selected HTTP and HTTPS services through an Ingress. Pomerium adds identity-aware policy while route definitions remain with the Kubernetes resources that application teams manage.

The Pomerium data plane runs inside the cluster boundary and stays close to protected Services. Application teams can manage routes with Kubernetes resources. Security teams can define common identity and policy controls.

How it works

Before installation, verify the current Pomerium requirements. The current guide requires Kubernetes 1.19 or later, Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global Pomerium settings with the Pomerium custom resource.

For each protected service, create an Ingress resource that selects the pomerium IngressClass. Add the route policy and required options with Pomerium annotations.

Configure TLS with Kubernetes Secrets and the certificate process that the cluster uses. Pomerium watches matching resources and updates its route configuration.

Example

A private Grafana Service runs in the observability namespace. Create a TLS-enabled Ingress for its public name. Set the Ingress class to pomerium and attach a policy for the required engineering group. The request reaches Pomerium. Pomerium authenticates the user, evaluates policy, and sends approved traffic to the Grafana Service. Kubernetes then selects a ready backend Pod.

Considerations

  • An Ingress resource has no effect without a working controller.
  • The Pomerium controller does not secure all east-west traffic or the Kubernetes API automatically.
  • Gateway API support is experimental. Use Ingress for the documented production flow.
  • Use the current Pomerium requirements for supported versions and architectures.

Sources and official resources

  • Deploy Pomerium with Kubernetes and protect workloads that run on Amazon EKS.

  • Deploy Pomerium with Kubernetes and protect workloads that run on Google Kubernetes Engine.

  • Deploy Pomerium with Kubernetes and protect workloads that run on Red Hat OpenShift.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo