Skip to main content
See All Environments

NixOS

Run Pomerium on NixOS or on an adjacent supported host and protect private applications in the environment.

Pomerium Core deployment pattern

Runs Pomerium Core

Category
Operating Systems

Overview

NixOS is a Linux distribution built on the Nix package manager. It lets operators declare packages, services, users, and system settings as configuration. Nixpkgs contains a community-maintained pomerium package.

NixOS teams can keep access configuration reproducible and reviewed with the rest of the host while Pomerium protects private services.

NixOS supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • A supported Linux host that can accept the user-facing route and reach the private upstream service.
  • DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.

How it works

Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.

Use the community-maintained Nixpkgs package or the official Pomerium container. If you use the standalone Linux binary, package or wrap it for NixOS and verify its dynamic-loader and library paths. Define service supervision, secrets, updates, and network placement.

Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.

Example

A private administration service runs on NixOS. The declarative host configuration starts Pomerium and supplies protected route configuration. Pomerium forwards approved requests to the service.

Considerations

  • The Nixpkgs package is community-maintained.
  • Check Nixpkgs for the available package version.

Sources and official resources

  • Deploy Pomerium near services that run on bare-metal infrastructure.

  • Run Pomerium with Docker and protect containerized applications and services.

  • Protect local and shared development applications with the same access policy used in production.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo