
VMware vSphere
Run Pomerium Core in a supported Linux virtual machine and protect selected vSphere application workloads.
Overview
VMware vSphere is a virtualization platform for running and managing virtual machines. Current releases can also supply an integrated Kubernetes runtime through VMware vSphere Kubernetes Service.
Private applications can span many virtual machines and network segments. Pomerium provides selected access without broad reach into the virtual infrastructure.
VMware vSphere supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.
Prerequisites
- A supported Linux host that can accept the user-facing route and reach the private upstream service.
- DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.
How it works
Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.
Create a supported Linux virtual machine for Pomerium Core. Place it on a network that can accept the user-facing route and reach the protected application virtual machines. Use the Kubernetes path for VKS workload clusters.
Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.
Example
A private operations dashboard runs on one vSphere virtual machine. Pomerium runs on a separate Ubuntu virtual machine and forwards approved requests to the dashboard.
Considerations
- Pomerium does not manage ESX hosts, vCenter Server, virtual machine lifecycle, or vSphere network policy.
