Internal admin panels
Protect access to internal administration panels as upstream web applications.
Overview
An internal admin panel is a generic web interface for operating an application, infrastructure service, or business system. It is a concept, not one vendor product. Pomerium can protect a selected HTTP or HTTPS endpoint before it reaches the private application.
Internal admin panels can expose sensitive data and destructive functions. A Pomerium route adds identity-aware policy before a user reaches the selected panel. The application keeps detailed action permissions.
Pomerium controls who can reach the selected panel. The protected application remains responsible for session handling, operation authorization, audit logs, and data.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Configure the application public URL and trusted proxy settings when required. Keep application authorization active for sensitive operations and audit trails.
Example
An operations panel runs on a private address. Its Pomerium route permits only the responsible operations group. The application keeps granular permissions for destructive or sensitive actions.
Considerations
- Application behavior, proxy support, session handling, and authorization differ by product. Test the real application.
