Skip to main content

Choose the access enforcement layer

Place access enforcement across identity-aware proxies, API gateways, service meshes, load balancers, and network tunnels.

Learning outcomes

  • Compare identity-aware proxies, API gateways, service meshes, load balancers, and VPNs by protected resource.
  • Place enforcement near the facts and action it must control.
  • Combine layers without duplicate, contradictory, or missing authorization.
  • Test bypass, identity propagation, protocol, and failure boundaries.

Protection need

Start with the subject, resource, action, protocol, fact owner, and bypass paths. An identity-aware proxy protects named user-facing services. An API gateway applies API routing and controls. A service mesh mediates workload-to-workload communication. A load balancer distributes traffic and can terminate transport security. A VPN or network tunnel grants network reachability. An application enforces object and business-action permission.

No layer is the universal owner. The correct placement depends on what the control can identify and intercept.

Security objectives and requirements

Place broad exposure and identity checks at the external route. Place API contract and client controls at an API layer. Place workload identity and service communication policy at workload boundaries. Place object, tenant, and transaction authorization in the application.

For each layer, define the protected resource, authenticated principal, trusted inputs, failure result, decision age, protocol coverage, and evidence. Remove a layer that has no distinct security job.

Security invariants and evidence

  • Every path to an action crosses one named enforcement owner.
  • No layer treats another layer's coarse allow as its complete permission result.
  • Identity changes form and trust explicitly at each termination point.
  • Policy failures have one stated safe result.
  • Evidence can correlate the external request, service calls, and final action.

Failure cases

  • A VPN grants reachability and is treated as user authorization.
  • A load balancer forwards spoofed identity fields.
  • An API gateway authorizes a route but not an object.
  • A mesh authenticates workloads but loses the human actor.
  • External and internal policies drift or contradict each other.
  • An origin, node port, or maintenance listener bypasses all intended layers.

Design tradeoffs and residual risk

More layers can reduce blast radius but increase policy drift, latency, and investigation cost. Central enforcement improves consistency but can lack local facts. Application enforcement has the richest facts but cannot close external exposure alone. Network controls reduce paths but use coarse identities and resources.

Assign one owner per decision. Use defense in depth for independent failure modes, not to repeat the same unclear rule.

Pomerium boundary

Pomerium provides identity-aware enforcement for configured routes and supported protocols. It can complement load balancers, API gateways, service meshes, and network controls. It does not replace workload identity, network segmentation, or application object authorization.

Exercise

For a web user calling an API that calls three workloads and writes a tenant record, assign every control to a layer. Remove duplicated rules. Add an alternate origin, compromised workload, wrong tenant, and policy-service outage.

Explain which layer denies each failure and which evidence proves it.

Evaluation checklist

  • Does each layer protect a resource it can name and intercept?
  • Is the principal at that layer authenticated and preserved correctly?
  • Are route, API, workload, network, and object permissions distinct?
  • Can any protocol or infrastructure path bypass all intended controls?
  • Do failure behavior and evidence remain clear when one layer is unavailable?

Next learning unit

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Sources and further reading

Keep learning

Network and Infrastructure

Virtual Private Network (VPN)

A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Application and Service AccessNetwork and Infrastructure

Gateway Bypass Path

Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo