Skip to main content

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

What is Route?

In Pomerium, a route defines how a requester reaches a service behind Pomerium. It maps an external from URL to one or more upstream to destinations and can apply policy, header handling, rewrites, and load balancing. This application route is different from IP routing, which selects a network path for packets.

Why it matters

A Pomerium route is both an application entry point and a policy boundary. A clear route definition helps operators send requests to the correct service and apply the intended access rules.

How it works

  1. Define the public from URL and one or more upstream to destinations.
  2. Attach policy that Pomerium evaluates when a requester uses the route.
  3. After an allow decision, Pomerium proxies the request and applies configured header, rewrite, and load-balancing rules.

Example

An operator maps https://grafana.example.com to http://grafana:3000 and permits only members of the operations group.

Pomerium boundary

Routes are the main Pomerium configuration unit for protected services. Pomerium uses each route to connect a public URL to an upstream service and to apply authentication, authorization, and proxy settings.

Limits and non-claims

  • A Pomerium route is not an IP route and does not select packet paths between networks.
  • A route does not stop direct upstream access unless the deployment also restricts bypass paths.
  • A valid route does not repair application defects or replace service-level security controls.

Evaluation checklist

  • Do authority, host, path, protocol, and upstream selection identify one intended resource?
  • Which route decision ends at the gateway, and which object action remains for the application?
  • Can wildcard overlap, shadow routes, alternate names, redirects, or a direct upstream bypass policy?

Sources and further reading

Keep learning

Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Application and Service Access

Layer-7 Enforcement

Layer 7 enforcement uses protocol facts, such as host, route, method, tool name, and verified identity, to make access decisions.

Learn this term
Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo