CircleCI Server
Protect access to self-hosted CircleCI Server web and API services.
Overview
CircleCI Server is the self-hosted CircleCI product. It runs a set of services for the web interface, API, job orchestration, and real-time updates. Use this route for self-hosted CircleCI Server.
CircleCI Server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to CircleCI Server. CircleCI Server remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Configure the CircleCI Server public origin for the Pomerium route. Keep build agents and internal cluster services on the product network unless the official architecture requires another reviewed path.
Example
An organization runs CircleCI Server in its private Kubernetes environment. Pomerium controls access to the selected public web and API endpoints. CircleCI keeps project, organization, and build permissions.
Considerations
- This route protects self-hosted CircleCI Server.
- CircleCI Server has several internal services. Expose only the supported public endpoints and preserve WebSocket upgrades.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
