
Dex
Use Dex as the identity provider for Pomerium through OpenID Connect.
Overview
Dex is an open-source federated OpenID Connect service. It usually authenticates users through another connector, such as LDAP, SAML, GitHub, or a second OpenID Connect provider, and then issues an OpenID Connect response to Pomerium.
Dex lets Pomerium use one OpenID Connect client while Dex bridges the selected upstream identity system and protocol.
The selected upstream identity system authenticates the user and owns the user lifecycle. Dex brokers that authentication and issues the OpenID Connect response. Pomerium validates the response and applies route policy.
How it works
Create a Dex static client for Pomerium or register the client through the deployment management process. Configure the Dex issuer, client secret, exact callback URL, and the connector claims that Pomerium needs.
Configure Pomerium with the exact issuer or provider URL, client ID, and client secret. Use the Pomerium callback URL as an exact redirect URI. Request only the scopes and claims that access policy needs.
Test discovery, signing-key rotation, the authorization code flow, logout, and required claim mappings before production use. Keep provider credentials outside source control.
Example
A team registers Pomerium as a Dex static client and configures an LDAP connector. Dex sends the user through the connector, maps the result, and issues an OpenID Connect response to Pomerium.
Considerations
- Dex normally brokers identity from an upstream connector. It is not a general user store.
- Refresh tokens, groups, and preferred_username claims vary by the selected Dex connector.
- The selected upstream identity system remains responsible for authentication and user lifecycle.
- A standards-based OpenID Connect pattern is not evidence of a vendor-specific connector or partnership.
