Skip to main content
See All Environments

Talos Linux

Deploy Pomerium with Kubernetes and protect workloads that run on Talos Linux clusters.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Categories
Kubernetes Distributions, Operating Systems

Overview

Talos Linux is a minimal, immutable Linux distribution built for Kubernetes. Operators manage it through an authenticated API. Talos has no interactive shell, SSH service, package manager, or general mutable user space.

An immutable Kubernetes node system needs an access layer that runs as a cluster workload and does not depend on host packages.

Talos Linux supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install the Pomerium Kubernetes Ingress Controller in the Talos Kubernetes cluster. Configure Pomerium through Kubernetes resources. Do not install a Pomerium binary or package on the Talos host.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

A private monitoring Service runs on Talos Linux Kubernetes nodes. Its Ingress selects Pomerium and permits the operations group. Pomerium forwards approved requests to the Service.

Considerations

  • Pomerium does not change the Talos image, install host packages, or manage the Talos API.

Sources and official resources

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Deploy Pomerium through the Kubernetes or container platform that uses containerd as its runtime.

  • Deploy Pomerium near services that run on bare-metal infrastructure.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo