Skip to main content
See All Environments

VMware vSphere Kubernetes Service

Deploy Pomerium in VMware vSphere Kubernetes Service workload clusters, formerly Tanzu Kubernetes Grid Service.

Pomerium Kubernetes deployment pattern

Runs in Kubernetes

Categories
Kubernetes Distributions, Private Infrastructure

Overview

VMware vSphere Kubernetes Service (VKS) is the current vSphere-native Kubernetes runtime. It was formerly called VMware Tanzu Kubernetes Grid Service. VMware Tanzu Platform is now a broader application platform and is not the same entity.

Existing documents and searches still use Tanzu Kubernetes names. A precise bridge to VKS helps teams use the current runtime and instructions.

VMware vSphere Kubernetes Service supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • Kubernetes 1.19 or later with Linux nodes on amd64 or arm64, PostgreSQL 11 or later, and a certificate management solution.
  • Cluster access that can install the Pomerium Ingress Controller and create the required custom resources, IngressClass, Services, Secrets, and Ingress resources.

How it works

Install the official Pomerium Kubernetes Ingress Controller in the cluster. Define global settings with the Pomerium custom resource. Create a TLS-enabled Ingress that selects the Pomerium IngressClass for each protected Service.

Install the Pomerium Kubernetes Ingress Controller in the VKS workload cluster that contains the protected Services. Use current VKS and Kubernetes resources, not obsolete Tanzu Kubernetes Grid Service instructions.

Check the controller status, Pomerium custom resource, IngressClass, TLS Secret, and backend Service endpoints. Test an allowed request and a denied request.

Example

A private developer portal runs as a Service in a VKS workload cluster. Its Ingress selects Pomerium and permits an engineering group. Pomerium forwards approved requests to the Service.

Considerations

  • Keep the legacy slug for search discovery, but do not present VMware Tanzu as the current name of one Kubernetes distribution.

Sources and official resources

  • Run Pomerium Core in a supported Linux virtual machine and protect selected vSphere application workloads.

  • Deploy Pomerium on Kubernetes and protect services across Kubernetes clusters.

  • Deploy Pomerium near services in cloud and private infrastructure and apply one access policy model.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo