Skip to main content

Control Plane and Data Plane

Separate the systems that define and distribute access policy from the request path that enforces it on live traffic.

Two operating planes

The control plane creates, validates, stores, and distributes desired state. It can include policy administration, identity and route configuration, certificate issuance, deployment controllers, and the systems that provide policy data. The data plane handles live application traffic and applies the effective state at an enforcement point.

The distinction is about responsibility, not host count. One process can contain both roles. A managed control plane can configure a data plane that runs in another environment. A service-mesh control plane can distribute policy to many local proxies.

State and request flow

An administrator or automation changes desired policy through the control plane. The control plane authenticates and authorizes that change, validates it, records a version, and distributes it. A data-plane instance receives and activates one version. When a request arrives, the enforcement path uses its active configuration and decision inputs to allow, deny, or route the request.

Trace both flows. The configuration flow answers who can change protection. The request flow answers which version and context protected one action.

Failure and residual risk

A compromised control plane can distribute broad authority to every enforcement point. A compromised data-plane instance can bypass policy for the traffic it handles. Distribution delay can leave replicas on different versions. A control-plane outage can stop changes while existing traffic continues, or it can stop authorization when the decision path depends on live control services.

Define signed or authenticated distribution, version acceptance, rollback, stale-state limits, degraded operation, and evidence. Network isolation around a control plane helps reduce reachability. It does not replace administrator authorization or change integrity.

Pomerium boundary

Pomerium deployments separate configuration and request-processing responsibilities according to the selected deployment model. The Proxy handles protected traffic and the Authorization service evaluates policy. Operators own control-plane access, configuration delivery, version rollout, and the network paths that keep upstream services behind approved enforcement.

Evaluation checklist

  • Which systems can change routes, policy, identity configuration, and trust?
  • Which components handle live protected requests?
  • Can one request be tied to the exact active configuration and decision?
  • What happens when policy distribution, decision services, or a data-plane replica fails?
  • Can rollback restore a known-good state without restoring compromised authority?

Sources and further reading

Keep learning

Authorization and Policy

Policy Decision Point (PDP)

A Policy Decision Point evaluates the applicable policies and request attributes and returns an authorization decision. It can be centralized or distributed.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo