Skip to main content
See All Environments

On-premises infrastructure

Deploy Pomerium near on-premises applications and protect them with identity-aware policy.

Pomerium deployment pattern

Runs Pomerium Core

Category
Private Infrastructure

Overview

On-premises infrastructure is a deployment location and ownership model. It can include physical servers, virtual machines, container platforms, Kubernetes clusters, storage systems, network devices, and legacy applications in facilities that an organization operates or controls. It is not one vendor product.

On-premises applications often sit behind private address space, firewalls, and long-lived network boundaries. Users can work from offices, homes, and partner networks. Pomerium protects each selected resource and request instead of treating a network location as the main trust signal.

Pomerium provides one access model for on-premises, cloud, and hybrid services. The data plane stays near the protected resource. Identity and context sources send decision data toward Pomerium. Pomerium sends only approved application traffic toward the service.

How it works

Run Pomerium Core on a Linux host, virtual machine, Docker platform, or Kubernetes cluster inside or near the private environment.

Place it where the user-facing route can reach Pomerium and Pomerium can reach the protected upstream service. Configure DNS, TLS, identity, and route policy.

For a larger deployment, use the documented replica, load-balancer, and persistent-state design. Use Pomerium Enterprise when the organization needs a self-hosted management plane.

Example

A private operations dashboard runs on a virtual machine with no direct public route. Pomerium runs on a separate host in a connected network zone. A user request reaches Pomerium first. Pomerium authenticates the user and evaluates policy. It forwards an approved request to the dashboard and rejects a request that does not meet policy.

Considerations

  • Pomerium is not a firewall, endpoint manager, patch manager, or identity provider.
  • TCP and UDP access needs a Pomerium client. Clientless access applies to supported web flows.
  • High availability needs explicit replicas, load balancing, and supported state storage.
  • Identity, certificate, update, and control-plane requirements depend on the selected product and network design.

Sources and official resources

  • Deploy Pomerium near services that run on bare-metal infrastructure.

  • Run Pomerium Core in a supported Linux virtual machine and protect selected vSphere application workloads.

  • Run Pomerium Core in a supported Linux virtual machine on Proxmox VE infrastructure.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo