Skip to main content
See All Integrations

CircleCI Server

Protect access to self-hosted CircleCI Server web and API services.

Standard protected service pattern

Categories
Developer Tools, Upstream Applications

Overview

CircleCI Server is the self-hosted CircleCI product. It runs a set of services for the web interface, API, job orchestration, and real-time updates. Use this route for self-hosted CircleCI Server.

CircleCI Server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to CircleCI Server. CircleCI Server remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Configure the CircleCI Server public origin for the Pomerium route. Keep build agents and internal cluster services on the product network unless the official architecture requires another reviewed path.

Example

An organization runs CircleCI Server in its private Kubernetes environment. Pomerium controls access to the selected public web and API endpoints. CircleCI keeps project, organization, and build permissions.

Considerations

  • This route protects self-hosted CircleCI Server.
  • CircleCI Server has several internal services. Expose only the supported public endpoints and preserve WebSocket upgrades.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

  • Protect access to Spinnaker deployment services as upstream web applications.

  • Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo