
Rundeck
Protect access to Rundeck operations and automation as an upstream web application.
Overview
Rundeck is an operations automation platform with a web interface and HTTP API, normally on port 4440 or 4443. It can also receive webhooks and serve command-line and API clients.
Rundeck can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Rundeck. Rundeck remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Expose only the selected interface and API endpoint. Keep Rundeck ACLs active and separate user browser access from webhook and automation ingress when required.
Example
Operators reach a private Rundeck interface through Pomerium. Rundeck keeps project ACLs, job permissions, node access, keys, and execution controls.
Considerations
- Configure the external URL, forwarded scheme, and proxy headers for the Pomerium origin.
- CLI clients, webhooks, and API automation need a compatible noninteractive authentication path.
