Skip to main content

Load Balancer and Gateway

A load balancer selects a backend, while a gateway terminates or mediates a protocol boundary and can apply policy.

System distinction

A load balancer distributes traffic among backends by health and selection policy. A gateway terminates or mediates a boundary between clients and services and can route, translate, authenticate, authorize, or transform traffic. One product can perform both roles.

Request flow

Name each hop: external load balancer, access gateway, internal load balancer, service proxy, and application. Record where TLS ends, which client identity survives, how a backend is chosen, which health signal applies, and where access policy is enforced.

State and evidence

Load balancing can use connection, request, cookie, header, or hash state. Gateways can create session and identity state. Correlate the client request, decision, selected backend, retry, response, and application result.

Failure and residual risk

TLS termination can expose an unprotected next hop. Health failover can select an old or unprotected backend. Retries can duplicate actions. Source addresses and identity headers can be lost or forged. A load-balancer allow rule is not application authorization.

Pomerium boundary

Pomerium acts as an identity-aware gateway and can load balance configured upstreams. Operators own external and internal load balancers, TLS boundaries, health behavior, backend reachability, identity-header protection, and direct-path isolation.

Evaluation checklist

  • Which component selects a backend and which component enforces access?
  • Where does TLS terminate and restart?
  • Which identity and request context survive each hop?
  • Can health, retry, or failover create an unprotected path or duplicate action?
  • Can a backend be reached without the intended gateway?

Sources and further reading

Keep learning

Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Application and Service Access

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo