
HashiCorp Nomad
Protect access to the HashiCorp Nomad user interface and HTTP API as upstream applications.
Overview
HashiCorp Nomad is a workload orchestrator. Its user interface and client-facing HTTP API normally use port 4646. Internal RPC on 4647 and Serf traffic on 4648 are cluster protocols, not user endpoints.
HashiCorp Nomad can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to HashiCorp Nomad. HashiCorp Nomad remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Configure the public interface origin and route only the selected port 4646 endpoint. Keep the Nomad control plane and cluster network private.
Example
Platform operators use a Pomerium HTTPS route for the private Nomad user interface. Nomad keeps ACLs for jobs, namespaces, variables, nodes, and administrative operations.
Considerations
- Expose only the client-facing interface and API. Do not send Nomad RPC or Serf traffic through the user route.
- Preserve Nomad ACLs and TLS. CLI and automation need compatible noninteractive credentials.
