Skip to main content

Named Resource Access

Grant access to one named application or service without extending general reachability to its network or neighboring systems.

Resource before network

Named resource access grants a principal a path to an identified application, API, administrative endpoint, or service. It does not make the principal a member of the private network. The resource name, protocol, action boundary, and policy are explicit.

Build the path

Publish only the required hostname, route, port, or service identity through an enforcement point. Keep the origin private from untrusted clients. Authenticate the requester, authorize the named resource, forward only approved traffic, and let the upstream authorize its internal objects and actions.

Distinguish reachability

Network reachability answers whether packets can travel to an address or subnet. Resource access answers whether an identified principal can use a specific protected service. Segmentation can reduce paths but cannot replace application identity, route policy, or business authorization.

Failure and residual risk

Wildcard routes, shared hostnames, open origin paths, DNS confusion, and protocol upgrades can expose more than the named resource. A permitted application can still reach sensitive neighbors. Access to one route can reveal every object behind it if the application lacks local authorization.

Pomerium boundary

Pomerium creates identity-aware routes to named upstream services. It can avoid broad client network membership for supported traffic. It does not segment the upstream network by itself or authorize the application's internal objects and actions.

Evaluation checklist

  • Does the grant name one service, hostname, protocol, and intended action boundary?
  • Can the client reach any private address that the grant did not name?
  • Can traffic reach the origin without the intended enforcement point?
  • Are wildcard hosts, alternate ports, upgrades, and redirects bounded?
  • Does the upstream still authorize its records and business actions?

Sources and further reading

Keep learning

Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo