
HashiCorp Nomad
Run the official Pomerium container as a Nomad workload or protect services from an adjacent host.
Overview
HashiCorp Nomad is a workload orchestrator that schedules containerized and non-containerized workloads across client nodes. Its Docker task driver can run OCI-compatible images. This environment page covers running Pomerium as a workload, not protecting the Nomad interface.
Nomad services can stay on private network addresses while Pomerium runs as a scheduled access workload near them.
HashiCorp Nomad supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A container runtime that can run the official Pomerium image and provide protected configuration, secrets, storage, and a private path to each upstream service.
- A stable user-facing listener with DNS and TLS for the selected routes.
How it works
Run the official Pomerium container through the environment container runtime. Mount protected configuration and secrets, publish the selected user-facing ports, and provide a network path to each upstream service.
Schedule the official Pomerium container as a Nomad Docker task. The job specification must provide configuration, secrets, ports, network access, storage, health checks, and restart behavior. An adjacent supported host is another option.
Check container health, protected configuration and secrets, the private container network, and upstream reachability. Test an allowed request and a denied request. Confirm that direct service exposure cannot bypass Pomerium.
Example
Nomad schedules a private administration application and a Pomerium container in a connected network. Pomerium authenticates the user and forwards an approved request to the application.
Considerations
- There is no official Pomerium Nomad job specification, service-discovery connector, or Nomad certification.
- Keep this page separate from the integration page that protects the Nomad UI and API.
