
Docker
Use Docker Compose to connect the official Pomerium container to protected application containers on a private network without publishing each upstream port.
Overview
The Pomerium Docker integration uses Docker Compose to connect the official Pomerium container to protected application containers on a private Compose network. A Pomerium route targets each upstream by its Compose service name.
The application does not need a public host port. Pomerium can be the only user-facing service and can check identity and route policy before traffic reaches the application container.
Docker starts and connects the containers. Pomerium terminates the user-facing route and sends approved traffic to the upstream service name on the private Compose network.
How it works
Choose the Pomerium Zero or Core Docker quickstart. Create the Pomerium configuration and Compose file with the official Pomerium image.
Attach Pomerium and each protected service to the same private Compose network. Target the upstream by service name. Publish only the Pomerium user-facing ports.
Start the project and test an allowed request and a denied request. Confirm that the upstream has no direct public path. Persist the Pomerium cache. For Core session persistence, set a fixed shared secret and a persistent Databroker store.
Example
A Compose project runs pomerium and verify. Pomerium publishes the selected user-facing ports. The verify service does not publish a host port. The route sends approved requests to http://verify:8000.
Considerations
- The quickstart is not a complete high-availability or production secret-management design.
- Publishing an upstream host port can create a path that bypasses Pomerium.
- Compose service discovery works only on shared networks. Separate Compose projects need an explicit shared network.
- This integration does not secure the Docker daemon, host, image supply chain, or all container-to-container traffic.
