SonarQube Server
Protect access to SonarQube Server while keeping scanners, webhooks, and automation on compatible noninteractive paths.
Overview
SonarQube Server is a self-managed platform for code quality and security analysis. Its user interface and API normally use HTTP port 9000. Scanners, CI jobs, and webhooks also call the service.
SonarQube Server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to SonarQube Server. SonarQube Server remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Configure the public base URL for the Pomerium origin. Keep analysis tokens and webhook authentication active and separate from browser sign-in.
Example
Developers use a Pomerium HTTPS route for the SonarQube Server interface. CI scanners use a separate reviewed token path. SonarQube keeps project, quality-profile, issue, and administration permissions.
Considerations
- Expose only the main application endpoint through the reverse proxy and preserve required forwarded headers.
- Scanners, CI jobs, webhooks, and API clients need token-based or other noninteractive access.
