Oracle Cloud Infrastructure
Deploy Pomerium in Oracle Cloud Infrastructure and protect private applications and services.
Overview
Oracle Cloud Infrastructure (OCI) is a public cloud platform. OCI Compute provides bare-metal and virtual machine instances. Oracle Container Engine for Kubernetes provides managed Kubernetes clusters.
Private OCI applications can stay inside virtual cloud networks while users receive a controlled route to selected services.
Oracle Cloud Infrastructure supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Run Pomerium Core on a supported Linux Compute virtual machine in a subnet that can reach each protected service. Use the standard Pomerium Kubernetes path for workloads in Oracle Container Engine for Kubernetes.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
An internal administration service runs on a private Compute instance. Pomerium runs on a separate Linux instance in a connected subnet and forwards only approved requests.
Considerations
- OCI Identity and Access Management and Pomerium route policy remain separate controls.
