Skip to main content
See All Environments

Rancher-managed Kubernetes

Deploy Pomerium in each Rancher-managed downstream cluster that contains protected workloads.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Category
Kubernetes Distributions

Overview

SUSE Rancher Manager manages Kubernetes clusters. A downstream cluster can use RKE2, K3s, a hosted cloud service, or another registered Kubernetes distribution.

A cluster fleet can span cloud, private infrastructure, and edge sites. Each cluster needs a local access path to its selected private Services.

Rancher-managed Kubernetes supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install the Pomerium Kubernetes Ingress Controller in each downstream cluster that contains protected Services. Configure Pomerium, DNS, certificates, persistence, and service exposure separately for each applicable cluster.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

Rancher Manager manages an edge K3s cluster and a cloud cluster. A private dashboard runs in the edge cluster. Pomerium runs in that downstream cluster and protects the dashboard Service.

Considerations

  • There is no product named Rancher Kubernetes. Use Rancher-managed Kubernetes for the cluster model.
  • Installing Pomerium in Rancher Manager does not automatically protect every downstream cluster. Protecting the Rancher interface is a separate integration page.

Sources and official resources

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Deploy Pomerium with Kubernetes and protect workloads that run on K3s.

  • Deploy Pomerium near edge services and apply identity-aware access policy.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo