
Talos Linux
Deploy Pomerium with Kubernetes and protect workloads that run on Talos Linux clusters.
Overview
Talos Linux is a minimal, immutable Linux distribution built for Kubernetes. Operators manage it through an authenticated API. Talos has no interactive shell, SSH service, package manager, or general mutable user space.
An immutable Kubernetes node system needs an access layer that runs as a cluster workload and does not depend on host packages.
Talos Linux supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
- Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.
How it works
Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.
Install the Pomerium Kubernetes Ingress Controller in the Talos Kubernetes cluster. Configure Pomerium through Kubernetes resources. Do not install a Pomerium binary or package on the Talos host.
Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.
Example
A private monitoring Service runs on Talos Linux Kubernetes nodes. Its Ingress selects Pomerium and permits the operations group. Pomerium forwards approved requests to the Service.
Considerations
- Pomerium does not change the Talos image, install host packages, or manage the Talos API.
Sources and official resources
- Talos LinuxOfficial website
- Talos for Linux administratorsOfficial documentation
- Talos FAQPrimary source
- Talos Linux source repositoryOfficial repository
- Pomerium Kubernetes installation requirementsPomerium documentation
- Pomerium Kubernetes quickstartPomerium documentation
- Configure Pomerium Ingress resourcesPomerium documentation
