Skip to main content
See All Integrations

Docker

Use Docker Compose to connect the official Pomerium container to protected application containers on a private network without publishing each upstream port.

First-party Pomerium Docker guide

Category
Deployment Environments

Overview

The Pomerium Docker integration uses Docker Compose to connect the official Pomerium container to protected application containers on a private Compose network. A Pomerium route targets each upstream by its Compose service name.

The application does not need a public host port. Pomerium can be the only user-facing service and can check identity and route policy before traffic reaches the application container.

Docker starts and connects the containers. Pomerium terminates the user-facing route and sends approved traffic to the upstream service name on the private Compose network.

How it works

Choose the Pomerium Zero or Core Docker quickstart. Create the Pomerium configuration and Compose file with the official Pomerium image.

Attach Pomerium and each protected service to the same private Compose network. Target the upstream by service name. Publish only the Pomerium user-facing ports.

Start the project and test an allowed request and a denied request. Confirm that the upstream has no direct public path. Persist the Pomerium cache. For Core session persistence, set a fixed shared secret and a persistent Databroker store.

Example

A Compose project runs pomerium and verify. Pomerium publishes the selected user-facing ports. The verify service does not publish a host port. The route sends approved requests to http://verify:8000.

Considerations

  • The quickstart is not a complete high-availability or production secret-management design.
  • Publishing an upstream host port can create a path that bypasses Pomerium.
  • Compose service discovery works only on shared networks. Separate Compose projects need an explicit shared network.
  • This integration does not secure the Docker daemon, host, image supply chain, or all container-to-container traffic.

Sources and official resources

  • Use the official Pomerium Ingress Controller to convert selected Kubernetes Ingress resources into TLS routes with identity-aware policy.

  • Run the Pomerium Kubernetes Ingress Controller on Amazon EKS and keep application Services private behind explicit Pomerium Ingress resources.

  • Protect a private Google Cloud Run service with a Pomerium route, identity-aware policy, and Google-signed serverless authentication.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo