
VMware vCenter Server
Protect the VMware vCenter Server web interface and API without claiming to cover every vSphere service.
Overview
VMware vCenter Server is the management plane for vSphere environments. Its user interface and APIs use HTTPS port 443 and can use WebSocket and other service endpoints. Appliance management normally uses port 5480 separately.
VMware vCenter Server can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to VMware vCenter Server. VMware vCenter Server remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Expose only the selected vCenter Server interface and API endpoint. Test login, inventory, task, file, virtual machine console, and API flows against the exact vSphere release.
Example
Virtualization administrators reach the private vCenter Server interface through Pomerium. vCenter keeps inventory, datacenter, cluster, host, virtual machine, datastore, and role permissions.
Considerations
- A route to port 443 does not cover ESXi hosts, virtual machine console paths, appliance management, replication, or every vSphere service.
- Preserve vCenter authentication, TLS, WebSocket upgrades, and long-lived task behavior.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
