Learning outcomes
- Choose containment points from the compromised authority and active paths.
- Revoke identity, session, token, credential, route, and downstream authority in a safe order.
- Account for caches, queues, direct paths, and offline validation.
- Measure containment from the source event to the last accepted action.
Operating objective
Containment prevents new harmful actions by the affected authority while preserving necessary evidence and recovery capability. It operates at every path where that authority can act: identity provider, authenticator recovery, sessions, refresh and access tokens, service credentials, certificates, Pomerium policy and routes, direct origins, applications, queues, and control planes.
Define the containment clock. Start it at the confirmed compromise or required response trigger. End it at the last accepted action at the protected target, not when an administrator clicks disable.
Signals and evidence
Inventory the subject, actor, credential types, issuers, audiences, sessions, routes, policy, target accounts, delegated grants, active connections, queued work, and recovery methods. Record each containment action, actor, system acknowledgement, propagation expectation, observed rejection, and last successful target action.
Watch for requests that use another session, another audience, a copied client credential, an existing application session, a direct endpoint, an offline-valid token, a stale authorization cache, a long-lived connection, or a queued action. A control-plane acknowledgement is evidence of configuration, not evidence that all data-plane use stopped.
Response and recovery
- Stop new authentication and credential issuance for the affected identity or client.
- Revoke or invalidate active sessions, refresh grants, service credentials, certificates, and delegated authority in scope.
- Deny the subject, credential, route, resource, or action at the enforcement layer. Use a broad deny when scope is uncertain and impact supports it.
- Isolate direct origins and alternate paths. Do not rely on the gateway to contain traffic that bypasses it.
- Terminate active connections and cancel queued, scheduled, or asynchronous work where supported.
- Disable or rotate downstream application credentials and sessions.
- Send controlled probes through each known path until old authority fails at the final target.
- Preserve evidence, investigate persistence, and monitor for replacement identities or credentials.
- Restore narrow authority only through a clean enrollment and approval path.
Design tradeoffs and residual risk
Subject-wide disablement is fast and can disrupt unrelated work. Credential-specific revocation is narrow and may miss copied or derived authority. Short lifetimes reduce maximum replay and increase issuer and clock dependency. Offline validation improves resilience and delays central revocation.
Closing a route protects it and can divert an attacker to another path. Rotating a shared credential can cause a broad outage. Break-glass can preserve response access and become a bypass if it is not independent, expiring, and reviewed.
Residual risk includes actions already accepted, offline systems, derived application sessions, unknown direct paths, compromised recovery, and credentials outside the inventory.
Pomerium boundary
Pomerium can reject future routed requests through policy, route, session, and credential changes supported by the deployment. It cannot revoke identity-provider state, terminate application-owned sessions, cancel queued work, or close direct origins by itself. Operators must verify rejection at each issuer, Pomerium route, network path, and application target.
Exercise
Issue a test human session and a test service credential for one protected application. Start one long-lived connection and one queued action. Simulate compromise, execute the containment order, and send one request per second through the gateway and a controlled direct path.
Measure source event to administrative action, control-plane acknowledgement, first rejection, and last accepted target action. Confirm that the long-lived connection, queue, old credential, direct path, and recovery enrollment have explicit outcomes.
Evaluation checklist
- Does containment cover every form and derivative of the compromised authority?
- Are direct paths, active connections, queues, caches, and offline validation included?
- Is the last accepted action measured at the protected target?
- Can responders preserve recovery access without leaving permanent broad authority?
- Does restoration require clean enrollment and fresh approval?
Next learning unit
Revocation Latency
Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.
