
SUSE Rancher Manager
Protect access to SUSE Rancher Manager cluster administration as an upstream web application.
Overview
SUSE Rancher Manager is a platform for managing Kubernetes clusters. Its user interface and API use HTTP and long-lived WebSocket connections. Downstream cluster agents and Kubernetes API access are separate flows.
SUSE Rancher Manager can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to SUSE Rancher Manager. SUSE Rancher Manager remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Configure the Rancher Manager public hostname for the Pomerium origin. Test login, API, shell, logs, cluster views, and long-lived watches.
Example
Platform operators reach private Rancher Manager through Pomerium. The route preserves WebSocket connections. Rancher keeps its cluster, project, namespace, role, and resource permissions.
Considerations
- Preserve WebSocket upgrades, forwarded headers, and long read and write timeouts.
- Cluster agents and downstream Kubernetes API access are separate from the Rancher Manager user interface route.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- SUSE Rancher ManagerOfficial website
- Rancher Manager Helm optionsOfficial documentation
- Rancher Manager layer 7 proxy guidePrimary source
- Rancher source repositoryOfficial repository
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
