
Red Hat OpenShift
Deploy Pomerium with Kubernetes and protect workloads that run on Red Hat OpenShift.
Overview
Red Hat OpenShift is a Kubernetes application platform. OpenShift Container Platform can run on bare metal, virtual infrastructure, and public clouds. It supports standard Kubernetes resources and adds OpenShift platform features.
OpenShift Services can stay private while teams publish selected applications through a standard Kubernetes access path.
Red Hat OpenShift supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in the OpenShift cluster. Use standard Kubernetes Ingress resources that select the Pomerium IngressClass. Validate security context constraints, storage, service exposure, DNS, and certificates.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private developer portal runs as an OpenShift Service. Its Kubernetes Ingress selects Pomerium and permits an engineering group. Pomerium forwards approved requests to the Service.
Considerations
- Use Kubernetes Ingress resources to configure the Pomerium Ingress Controller; OpenShift Route objects remain separate.
- Pomerium does not manage OpenShift users, projects, Operators, cluster policy, or all cluster traffic.
