Podman
Run the official Pomerium container with Podman and protect private application containers.
Overview
Podman is a daemonless container engine for running and managing Open Container Initiative containers, images, volumes, networks, and pods. Podman can run containers as root or as a nonprivileged user.
Teams can use a daemonless container model while keeping Pomerium and private applications in separate, reviewable containers.
Podman supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A container runtime that can run the official Pomerium image and provide protected configuration, secrets, storage, and a private path to each upstream service.
- A stable user-facing listener with DNS and TLS for the selected routes.
How it works
Run the official Pomerium container through the environment container runtime. Mount protected configuration and secrets, publish the selected user-facing ports, and provide a network path to each upstream service.
Pull the official Pomerium image and run it with Podman. Mount protected configuration and secrets, publish the required port, and connect the container to the private services. Use Quadlet or another documented systemd unit for automatic start.
Check container health, protected configuration and secrets, the private container network, and upstream reachability. Test an allowed request and a denied request. Confirm that direct service exposure cannot bypass Pomerium.
Example
A private administration application and Pomerium run in separate containers on a connected private Podman network. Pomerium forwards only approved requests to the application.
Considerations
- This is OCI image compatibility, not a named Pomerium Podman integration.
- Rootless ports, storage, networking, Quadlet, process lifecycle, and image trust need explicit configuration.
