Temporal Web UI
Protect access to Temporal Web UI as an upstream web application without claiming to proxy worker and SDK gRPC traffic.
Overview
Temporal Web UI is the browser interface for viewing and operating Temporal workflows. Temporal workers and SDKs use the separate Temporal frontend gRPC API. An HTTP route for the UI does not carry that gRPC traffic.
Temporal Web UI can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Temporal Web UI. Temporal Web UI remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Expose only the Web UI endpoint through the Pomerium route. Keep Temporal frontend, worker, and SDK gRPC connections on a separate reviewed network and authentication path.
Example
Operators reach private Temporal Web UI through Pomerium. Workers and SDKs connect to the Temporal frontend through their separate supported service path. Temporal keeps namespace and application controls.
Considerations
- An HTTP route for Temporal Web UI does not protect or carry worker and SDK gRPC traffic.
- Configure the UI public origin and its connection to the Temporal frontend separately.
