
Rancher-managed Kubernetes
Deploy Pomerium in each Rancher-managed downstream cluster that contains protected workloads.
Overview
SUSE Rancher Manager manages Kubernetes clusters. A downstream cluster can use RKE2, K3s, a hosted cloud service, or another registered Kubernetes distribution.
A cluster fleet can span cloud, private infrastructure, and edge sites. Each cluster needs a local access path to its selected private Services.
Rancher-managed Kubernetes supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in each downstream cluster that contains protected Services. Configure Pomerium, DNS, certificates, persistence, and service exposure separately for each applicable cluster.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
Rancher Manager manages an edge K3s cluster and a cloud cluster. A private dashboard runs in the edge cluster. Pomerium runs in that downstream cluster and protects the dashboard Service.
Considerations
- There is no product named Rancher Kubernetes. Use Rancher-managed Kubernetes for the cluster model.
- Installing Pomerium in Rancher Manager does not automatically protect every downstream cluster. Protecting the Rancher interface is a separate integration page.
Sources and official resources
- SUSE Rancher ManagerOfficial website
- Rancher Manager glossaryOfficial documentation
- Rancher downstream cluster architecturePrimary source
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
