What is Route?
In Pomerium, a route defines how a requester reaches a service behind Pomerium. It maps an external from URL to one or more upstream to destinations and can apply policy, header handling, rewrites, and load balancing. This application route is different from IP routing, which selects a network path for packets.
Why it matters
A Pomerium route is both an application entry point and a policy boundary. A clear route definition helps operators send requests to the correct service and apply the intended access rules.
How it works
- Define the public from URL and one or more upstream to destinations.
- Attach policy that Pomerium evaluates when a requester uses the route.
- After an allow decision, Pomerium proxies the request and applies configured header, rewrite, and load-balancing rules.
Example
An operator maps https://grafana.example.com to http://grafana:3000 and permits only members of the operations group.
Pomerium boundary
Routes are the main Pomerium configuration unit for protected services. Pomerium uses each route to connect a public URL to an upstream service and to apply authentication, authorization, and proxy settings.
Limits and non-claims
- A Pomerium route is not an IP route and does not select packet paths between networks.
- A route does not stop direct upstream access unless the deployment also restricts bypass paths.
- A valid route does not repair application defects or replace service-level security controls.
Evaluation checklist
- Do authority, host, path, protocol, and upstream selection identify one intended resource?
- Which route decision ends at the gateway, and which object action remains for the application?
- Can wildcard overlap, shadow routes, alternate names, redirects, or a direct upstream bypass policy?
