Skip to main content
See All Integrations

JupyterHub

Protect access to JupyterHub notebook environments as an upstream web application.

Standard protected service pattern

Categories
AI and Data, Developer Tools, Upstream Applications

Overview

JupyterHub is a multi-user service for starting and managing notebook servers. Its web interface and user notebook connections use HTTP and WebSocket. Spawned notebook URLs must remain under the routed public origin.

JupyterHub can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to JupyterHub. JupyterHub remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Configure the JupyterHub proxy and public origin for the Pomerium route. Test login, spawn, notebook, terminal, file, and WebSocket flows.

Example

Researchers reach a private JupyterHub deployment through Pomerium. Pomerium controls route access. JupyterHub authenticates and spawns each user server and keeps notebook-level security controls.

Considerations

  • Preserve WebSocket upgrades for notebook kernels and terminals.
  • Keep JupyterHub authentication, user isolation, cookie security, and spawned-server access controls active.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect access to Apache Airflow workflows and administration as an upstream web application.

  • Protect access to Backstage developer portals and software catalogs as an upstream web application.

  • Protect access to Metabase analytics and administration as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo