MicroK8s
Deploy Pomerium with Kubernetes and protect workloads that run on MicroK8s.
Overview
MicroK8s is a small, single-package Kubernetes distribution from Canonical. It supports developer workstations, data centers, and edge environments. Additional cluster functions are enabled through add-ons.
MicroK8s can host private development and edge Services. Pomerium exposes selected applications without making the whole cluster public.
MicroK8s supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Enable the cluster networking and service-exposure features that the selected design needs. Install the Pomerium Kubernetes Ingress Controller and create a Pomerium Ingress for each protected Service.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A shared development dashboard runs as a private MicroK8s Service. Its Ingress selects Pomerium and permits an engineering group. Pomerium forwards approved requests to the Service.
Considerations
- Required add-ons, load balancing, storage, certificates, and exposure methods vary by deployment.
