Skip to main content
See All Environments

VMware vSphere

Run Pomerium Core in a supported Linux virtual machine and protect selected vSphere application workloads.

Pomerium Core deployment pattern

Runs Pomerium Core

Category
Private Infrastructure

Overview

VMware vSphere is a virtualization platform for running and managing virtual machines. Current releases can also supply an integrated Kubernetes runtime through VMware vSphere Kubernetes Service.

Private applications can span many virtual machines and network segments. Pomerium provides selected access without broad reach into the virtual infrastructure.

VMware vSphere supplies the runtime or deployment environment. Pomerium runs in that environment and supplies the identity-aware access point for selected services.

Prerequisites

  • A supported Linux host that can accept the user-facing route and reach the private upstream service.
  • DNS, TLS, identity-provider configuration, protected secrets, and durable storage where the selected design requires it.

How it works

Run Pomerium Core on a supported Linux host in the environment. Install the official package, standalone binary, or container. Configure DNS, TLS, identity, route policy, storage, and replicas for the selected design.

Create a supported Linux virtual machine for Pomerium Core. Place it on a network that can accept the user-facing route and reach the protected application virtual machines. Use the Kubernetes path for VKS workload clusters.

Check service health, DNS, TLS, required storage and replicas, and upstream reachability. Confirm that a direct public route cannot bypass Pomerium.

Example

A private operations dashboard runs on one vSphere virtual machine. Pomerium runs on a separate Ubuntu virtual machine and forwards approved requests to the dashboard.

Considerations

  • Pomerium does not manage ESX hosts, vCenter Server, virtual machine lifecycle, or vSphere network policy.

Sources and official resources

  • Deploy Pomerium near on-premises applications and protect them with identity-aware policy.

  • Deploy Pomerium in VMware vSphere Kubernetes Service workload clusters, formerly Tanzu Kubernetes Grid Service.

  • Run Pomerium Core on an adjacent supported host to protect applications and services on Windows Server.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo