Access without a network tunnel
Clientless zero trust access lets a user reach a named private application without installing a broad network tunnel client for that resource. A browser can provide this path for HTTP and HTTPS. The browser is still client software. Clientless describes the absence of a dedicated access connector, not the absence of a client.
Choose by protocol
HTTP applications can use browser redirects, cookies, and proxy routes. Native SSH can use an ordinary SSH client when the server trusts the required certificate authority and the access system supports that flow. Arbitrary TCP and UDP protocols usually need a local connector or protocol-specific integration.
Preserve the boundary
Publish only the named resource. Keep the origin private from direct clients. Authenticate and authorize each supported connection. Define what happens to long-lived connections when identity, policy, or device state changes. Keep application object and action authorization active.
Failure and residual risk
Calling all access clientless can hide a required connector, device enrollment, or protocol limit. Browser access can still be phished or run on an unsafe device. An open origin bypasses route policy. Long-lived connections can outlast the context that allowed them.
Pomerium boundary
Pomerium can protect HTTP and HTTPS applications through browser routes. It can also provide documented native SSH and client-assisted TCP or UDP paths. Pomerium does not make every protocol clientless and does not secure an unmanaged endpoint or unsafe application by itself.
Evaluation checklist
- Is every required protocol and client component named accurately?
- Does the design grant one named resource instead of broad network membership?
- Can any client reach the origin without Pomerium?
- Are connection lifetime and reevaluation limits explicit?
- Does the upstream keep its own object and action authorization?
