GitHub Enterprise Server
Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.
Overview
GitHub Enterprise Server is the self-hosted GitHub appliance. It exposes a web interface, REST and GraphQL APIs, Git Smart HTTP, Git over SSH, administrative SSH, and other appliance services. One HTTP route does not cover every endpoint.
GitHub Enterprise Server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to GitHub Enterprise Server. GitHub Enterprise Server remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a separate Pomerium route for each required HTTP, TCP, UDP, or SSH endpoint. Do not send internal cluster, gossip, replication, or control-plane traffic through a user route.
Use a web route for browser traffic and a supported Pomerium client or native access flow for non-HTTP traffic. Keep service-level TLS, authentication, and authorization active.
Expose only the required user endpoints. Configure the appliance public origin and trusted proxy behavior. Give command-line Git and automation a compatible authentication path.
Example
Employees use a Pomerium HTTPS route for the GitHub Enterprise Server web interface and Git Smart HTTP. A separate SSH route supports Git over SSH where required. GitHub keeps repository and organization permissions.
Considerations
- An HTTP route does not cover Git SSH, administrative SSH, replication, or every appliance service.
- Pomerium protects the configured GitHub Enterprise Server routes.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
Sources and official resources
- GitHub Enterprise ServerOfficial website
- GitHub Enterprise Server network portsOfficial documentation
- GitHub Enterprise Server load balancer configurationPrimary source
- Tunneled Git connections with PomeriumPomerium documentation
- Pomerium HTTP routingPomerium documentation
- Pomerium non-HTTP accessPomerium documentation
- Pomerium clientsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
