Skip to main content
See All Integrations

GitHub Enterprise Server

Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.

Separate standard routes by protocol

Categories
Code Repository, Developer Tools, Upstream Applications

Overview

GitHub Enterprise Server is the self-hosted GitHub appliance. It exposes a web interface, REST and GraphQL APIs, Git Smart HTTP, Git over SSH, administrative SSH, and other appliance services. One HTTP route does not cover every endpoint.

GitHub Enterprise Server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to GitHub Enterprise Server. GitHub Enterprise Server remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.

Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.

Expose only the required user endpoints. Configure the appliance public origin and trusted proxy behavior. Give command-line Git and automation a compatible authentication path.

Example

Employees use a Pomerium HTTPS route for the GitHub Enterprise Server web interface and Git Smart HTTP. A separate SSH route supports Git over SSH where required. GitHub keeps repository and organization permissions.

Considerations

  • An HTTP route does not cover Git SSH, administrative SSH, replication, or every appliance service.
  • Pomerium protects the configured GitHub Enterprise Server routes.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
  • For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.

Sources and official resources

  • Protect the Gitea web application and Git Smart HTTP traffic, with a separate route for Git over SSH when required.

  • Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

  • Protect access to Backstage developer portals and software catalogs as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo