Skip to main content
See All Environments

Red Hat OpenShift

Deploy Pomerium with Kubernetes and protect workloads that run on Red Hat OpenShift.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Categories
Kubernetes Distributions, Private Infrastructure

Overview

Red Hat OpenShift is a Kubernetes application platform. OpenShift Container Platform can run on bare metal, virtual infrastructure, and public clouds. It supports standard Kubernetes resources and adds OpenShift platform features.

OpenShift Services can stay private while teams publish selected applications through a standard Kubernetes access path.

Red Hat OpenShift supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install the Pomerium Kubernetes Ingress Controller in the OpenShift cluster. Use standard Kubernetes Ingress resources that select the Pomerium IngressClass. Validate security context constraints, storage, service exposure, DNS, and certificates.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

A private developer portal runs as an OpenShift Service. Its Kubernetes Ingress selects Pomerium and permits an engineering group. Pomerium forwards approved requests to the Service.

Considerations

  • Use Kubernetes Ingress resources to configure the Pomerium Ingress Controller; OpenShift Route objects remain separate.
  • Pomerium does not manage OpenShift users, projects, Operators, cluster policy, or all cluster traffic.

Sources and official resources

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Deploy Pomerium near applications and services that run on Red Hat Enterprise Linux systems.

  • Deploy Pomerium near services in cloud and private infrastructure and apply one access policy model.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo