Mattermost
Protect access to self-hosted Mattermost workspaces as an upstream web application.
Overview
Mattermost is a self-hosted collaboration platform. Its web application and API use HTTP. Real-time messaging uses WebSocket. Mobile clients, integrations, bots, and API tools also use the public service endpoints.
Mattermost can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Mattermost. Mattermost remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Configure the Mattermost site URL and reverse-proxy settings for Pomerium. Test browser, WebSocket, mobile, file, integration, and webhook flows separately.
Example
Employees reach a private Mattermost deployment through Pomerium. The route preserves WebSocket upgrades for live messages. Mattermost keeps channel, team, administration, and data permissions.
Considerations
- Preserve WebSocket upgrades and the forwarded public origin.
- Mobile clients, integrations, bots, and API clients need a compatible noninteractive authentication design.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
