Resource before network
Named resource access grants a principal a path to an identified application, API, administrative endpoint, or service. It does not make the principal a member of the private network. The resource name, protocol, action boundary, and policy are explicit.
Build the path
Publish only the required hostname, route, port, or service identity through an enforcement point. Keep the origin private from untrusted clients. Authenticate the requester, authorize the named resource, forward only approved traffic, and let the upstream authorize its internal objects and actions.
Distinguish reachability
Network reachability answers whether packets can travel to an address or subnet. Resource access answers whether an identified principal can use a specific protected service. Segmentation can reduce paths but cannot replace application identity, route policy, or business authorization.
Failure and residual risk
Wildcard routes, shared hostnames, open origin paths, DNS confusion, and protocol upgrades can expose more than the named resource. A permitted application can still reach sensitive neighbors. Access to one route can reveal every object behind it if the application lacks local authorization.
Pomerium boundary
Pomerium creates identity-aware routes to named upstream services. It can avoid broad client network membership for supported traffic. It does not segment the upstream network by itself or authorize the application's internal objects and actions.
Evaluation checklist
- Does the grant name one service, hostname, protocol, and intended action boundary?
- Can the client reach any private address that the grant did not name?
- Can traffic reach the origin without the intended enforcement point?
- Are wildcard hosts, alternate ports, upgrades, and redirects bounded?
- Does the upstream still authorize its records and business actions?
