Skip to main content
See All Integrations

Cockpit

Put the Cockpit Linux administration interface behind Pomerium so users pass identity-aware route policy before Cockpit host login.

First-party Pomerium integration guide

Overview

Cockpit is a web administration interface for Linux servers. Pomerium can control access to the Cockpit route before Cockpit asks for the host login.

Cockpit can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Cockpit. Cockpit remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Enable WebSockets, preserve the public host, set the exact HTTPS and WSS origins, and set ProtocolHeader to X-Forwarded-Proto. Run Cockpit without upstream TLS only on the private path behind Pomerium, and restrict port 9090 to Pomerium.

Example

A server team exposes Cockpit only through Pomerium. Pomerium policy limits route access to administrators. Cockpit then uses its normal PAM or SSH host authentication.

Considerations

  • Pomerium gates the route. It does not sign the user into Cockpit.
  • Cockpit still uses its normal PAM or SSH host authentication and host authorization.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect a self-hosted code-server browser IDE with Pomerium authentication and route policy, with WebSocket support and the correct public host.

  • Protect self-hosted Grafana dashboards with Pomerium route policy and SSO, then pass a signed identity JWT for seamless Grafana login.

  • Put the Argo Workflows UI and API behind Pomerium so users pass identity-aware route policy before traffic reaches Argo Server.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo