NocoDB
Protect access to self-hosted NocoDB workspaces as an upstream web application.
Overview
NocoDB is an open-source web application for working with database data through spreadsheet-style interfaces and APIs. Its browser application and API use HTTP.
NocoDB can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to NocoDB. NocoDB remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Configure the NocoDB public site URL and trusted proxy behavior. Test browser, API, attachment, import, export, and webhook flows.
Example
Employees reach a private NocoDB workspace through Pomerium. NocoDB keeps workspace, base, table, field, and record permissions. API clients use a reviewed noninteractive path.
Considerations
- Set NC_SITE_URL to the public Pomerium origin for current releases.
- API clients and integrations need noninteractive authentication.
