Skip to main content

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Missing mediation

A gateway bypass path lets a client reach the protected application or action without passing through the intended enforcement point. The bypass can use a direct origin address, alternate load balancer, old hostname, internal network, service mesh path, maintenance port, protocol upgrade, or trusted peer.

Enumerate paths

Start from the protected action and work backward. List every listener, address, hostname, port, protocol, load balancer, cluster service, tunnel, peering link, administrative endpoint, and recovery path. Include internal and third-party clients. Mark which control authenticates and authorizes each edge.

Close or reproduce the control

Make the origin accept traffic only from the intended gateway or authenticated peer. Use network policy, security groups, private listeners, mutual authentication, and origin request validation as appropriate. If a second path must remain, give it an equivalent explicit policy and independent test.

Failure and residual risk

Blocking public ingress does not close internal paths. Trusting a source IP can fail behind shared networks. A copied identity header can impersonate a gateway. Health, metrics, debug, and recovery ports can expose sensitive actions. Infrastructure changes can silently reintroduce a route.

Pomerium boundary

Pomerium enforces policy only for traffic that reaches a Pomerium route. Network and application owners must prevent direct or alternate access to the upstream. The upstream should validate signed identity context and must keep its own object and action authorization.

Evaluation checklist

  • Is every network and protocol path to the origin inventoried?
  • Can the origin authenticate the intended gateway instead of trusting a copied header?
  • Are internal, administrative, health, debug, and recovery paths tested?
  • Does infrastructure change detection cover new listeners and routes?
  • Can a direct request reproduce neither the gateway identity nor its authorization result?

Sources and further reading

Keep learning

Security Engineering FoundationsAuthorization and Policy

Complete Mediation

Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo