Skip to main content
See All Integrations

Gitea

Protect the Gitea web application and Git Smart HTTP traffic, with a separate route for Git over SSH when required.

Separate standard routes by protocol

Categories
Code Repository, Developer Tools, Upstream Applications

Overview

Gitea is a self-hosted software development service. It provides a web interface, REST API, Git Smart HTTP, and Git over SSH. These endpoints do not all use the same protocol.

Gitea can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Gitea. Gitea remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.

Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.

Use the HTTPS route for the web application, API, and Git Smart HTTP. Use native SSH or a TCP tunnel for Git SSH. Test command-line credentials and noninteractive Git operations separately.

Example

Developers use a Pomerium web route for the Gitea user interface and Git Smart HTTP. A separate native SSH or TCP route carries Git over SSH. Gitea still applies repository permissions.

Considerations

  • Set the Gitea root URL and trusted proxy settings to the public Pomerium origin.
  • An HTTP route does not cover Git over SSH. Use a separate route only when users need that transport.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.

  • Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

  • Protect access to Backstage developer portals and software catalogs as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo