Skip to main content

Protect application and service access

Design browser, API, service, SSH, TCP, and UDP access without losing identity or creating a direct bypass.

Learning outcomes

  • Select an enforcement layer and client path for each application protocol.
  • Trace browser, API, service, and non-HTTP identity through the complete request path.
  • Protect upstream identity assertions and separate route permission from object permission.
  • Close direct paths and validate failure, retry, and recovery behavior.

Scenario

One engineering service has a browser interface, an API used by automation, and an SSH administration path. The design needs separate routes, suitable client authentication, and the same narrow access intent across all three protocols.

Ordered learning units

  1. Concept

    Named Resource Access

    Grant access to one named application or service without extending general reachability to its network or neighboring systems.

  2. Concept

    Upstream and Downstream

    Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.

  3. Concept

    Secure Route Selection

    Select a route from trusted authority and path data so an attacker cannot redirect policy or credentials to the wrong upstream.

  4. Concept

    Gateway Bypass Path

    Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.

  5. Guide

    Design identity-aware API access

    Protect API inventory, clients, routes, versions, objects, actions, credentials, quotas, and evidence with explicit owners.

  6. Concept

    WebSocket Access

    WebSocket access starts with an HTTP upgrade and then carries long-lived bidirectional messages on one connection.

  7. Guide

    Design service-to-service access

    Authenticate workloads, preserve human actor context, authorize target actions, and manage machine credentials through their lifecycle.

  8. Concept

    Credential Injection

    Credential injection supplies a bounded upstream credential after access policy allows a request.

  9. Concept

    Identity-Aware Rate Limiting

    Identity-aware rate limiting bounds request volume by accountable subject, client, resource, action, and cost.

Evaluation questions

  • Which browser, API, service, SSH, TCP, and UDP endpoints does the service require?
  • Can each human or automation client complete the selected authentication path?
  • Does the upstream validate trusted identity data and keep its own object permissions?

Completion conditions

  • Draw and test every client-to-target path for one multi-protocol service.
  • Prove unauthorized clients, forged identity, wrong object actions, and direct-origin requests fail.

Sources and further reading

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo