What is Micro-segmentation?
The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise. It can use network, host, identity, or application controls. It does not automatically improve performance or simplify operations. Its value depends on accurate flow discovery, narrowly scoped policy, consistent enforcement, and current workload identity.
Why it matters
A flat environment lets one compromised workload reach many other workloads. Small, enforced communication boundaries reduce the reachable set and can contain an incident.
How it works
- Inventory workloads, identities, dependencies, and required communication paths.
- Define narrow policy for each allowed source, destination, protocol, and application action.
- Enforce the policy at suitable gateways, proxies, hosts, or workloads, then use telemetry to review and update it.
Example
A build service can call one deployment API, but it cannot connect to the production database or unrelated administration services.
Pomerium boundary
Pomerium can create an identity-aware route to a protected application and evaluate identity and context policy on each HTTP request. This can provide application-level segmentation for traffic that passes through Pomerium. It does not segment every network flow in an environment.
Limits and non-claims
- An incomplete flow inventory can block required traffic or leave an unsafe path open.
- Many narrow rules can become hard to review when workload identities and dependencies change often.
- A control protects only the paths that pass through its enforcement points.
Evaluation checklist
- Which workloads and resources define each segment, and which identity selects membership?
- Does default deny leave only the required flows and management paths?
- Can an alternate network, shared service, node, or control plane bypass the boundary?
