System distinction
A load balancer distributes traffic among backends by health and selection policy. A gateway terminates or mediates a boundary between clients and services and can route, translate, authenticate, authorize, or transform traffic. One product can perform both roles.
Request flow
Name each hop: external load balancer, access gateway, internal load balancer, service proxy, and application. Record where TLS ends, which client identity survives, how a backend is chosen, which health signal applies, and where access policy is enforced.
State and evidence
Load balancing can use connection, request, cookie, header, or hash state. Gateways can create session and identity state. Correlate the client request, decision, selected backend, retry, response, and application result.
Failure and residual risk
TLS termination can expose an unprotected next hop. Health failover can select an old or unprotected backend. Retries can duplicate actions. Source addresses and identity headers can be lost or forged. A load-balancer allow rule is not application authorization.
Pomerium boundary
Pomerium acts as an identity-aware gateway and can load balance configured upstreams. Operators own external and internal load balancers, TLS boundaries, health behavior, backend reachability, identity-header protection, and direct-path isolation.
Evaluation checklist
- Which component selects a backend and which component enforces access?
- Where does TLS terminate and restart?
- Which identity and request context survive each hop?
- Can health, retry, or failover create an unprotected path or duplicate action?
- Can a backend be reached without the intended gateway?
