
OpenStack
Deploy Pomerium in OpenStack environments and protect private applications and services.
Overview
OpenStack is open-source cloud infrastructure software. It supplies services for compute, networking, storage, identity, and image management. Organizations use it to build public and private infrastructure clouds.
OpenStack workloads can stay on private project networks while users receive controlled access to selected services.
OpenStack supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Run Pomerium Core on a supported Linux Nova instance in a network that can accept the user-facing route and reach the protected services. Use the Kubernetes path when applications run in a cluster hosted on OpenStack.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private administration service runs on a Nova instance. Pomerium runs on a separate Linux instance in a connected project network and forwards approved requests.
Considerations
- OpenStack identity, security groups, and Pomerium route policy remain separate controls.
