Missing mediation
A gateway bypass path lets a client reach the protected application or action without passing through the intended enforcement point. The bypass can use a direct origin address, alternate load balancer, old hostname, internal network, service mesh path, maintenance port, protocol upgrade, or trusted peer.
Enumerate paths
Start from the protected action and work backward. List every listener, address, hostname, port, protocol, load balancer, cluster service, tunnel, peering link, administrative endpoint, and recovery path. Include internal and third-party clients. Mark which control authenticates and authorizes each edge.
Close or reproduce the control
Make the origin accept traffic only from the intended gateway or authenticated peer. Use network policy, security groups, private listeners, mutual authentication, and origin request validation as appropriate. If a second path must remain, give it an equivalent explicit policy and independent test.
Failure and residual risk
Blocking public ingress does not close internal paths. Trusting a source IP can fail behind shared networks. A copied identity header can impersonate a gateway. Health, metrics, debug, and recovery ports can expose sensitive actions. Infrastructure changes can silently reintroduce a route.
Pomerium boundary
Pomerium enforces policy only for traffic that reaches a Pomerium route. Network and application owners must prevent direct or alternate access to the upstream. The upstream should validate signed identity context and must keep its own object and action authorization.
Evaluation checklist
- Is every network and protocol path to the origin inventoried?
- Can the origin authenticate the intended gateway instead of trusting a copied header?
- Are internal, administrative, health, debug, and recovery paths tested?
- Does infrastructure change detection cover new listeners and routes?
- Can a direct request reproduce neither the gateway identity nor its authorization result?
