TCP services
Protect access to private TCP services through Pomerium routes.
Overview
A TCP service is any private service that uses the Transmission Control Protocol and is compatible with a byte-stream tunnel. This is a generic access concept, not a vendor connector.
TCP services can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can start the selected TCP route. The upstream service remains responsible for protocol security, authentication, data, and service authorization.
How it works
Create a Pomerium TCP route for the private service. Start a local tunnel with Pomerium CLI or Pomerium Desktop and point the normal service client to the loopback listener.
Keep upstream TLS, service authentication, and service authorization active. Use a distinct local port for each protected route.
Confirm that the client can connect through one stable endpoint. Cluster discovery, redirects, or advertised peer addresses can need several routes.
Example
A user starts a local Pomerium tunnel for a private TCP service and points the normal protocol client to the loopback port. Pomerium checks the route policy when the connection starts.
Considerations
- Pomerium carries bytes. It does not add protocol-level authorization or inspect the application protocol.
- Keep upstream TLS or mTLS for end-to-end encryption. Each route needs a distinct local port.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
- For TCP tunnels, place Pomerium behind an L4 or TCP edge. Any HTTP proxy in front of Pomerium must forward CONNECT traffic.
