Design cloud-native access boundaries
Combine named application access, segmentation, workload identity, Kubernetes authorization, and multi-cloud trust.
Topic index
Learn the network boundaries, traffic paths, and infrastructure patterns behind private access.
Topic index
Pomerium operates at the application access path. It accepts a named user-facing route, evaluates identity-aware policy, and connects approved traffic to a reachable private upstream. The deployment still needs correct DNS, TLS, load balancing, and private network reachability.
2 learning paths
Combine named application access, segmentation, workload identity, Kubernetes authorization, and multi-cloud trust.
Build justified trust from small enforcement components, hardened runtimes, boot evidence, isolation, and controlled information flow.
22 related guides
Apply user and workload identity across APIs, gateways, meshes, sidecars, clusters, clouds, and application resources.
Trace SPIFFE IDs, SVIDs, trust domains, bundles, Workload API delivery, attestation, rotation, and federation.
Place transport and application enforcement where the required identity, destination, protocol, resource, and action are visible.
Place access enforcement across identity-aware proxies, API gateways, service meshes, load balancers, and network tunnels.
Use network segmentation to limit reachability and identity policy to decide access to named services, resources, and actions.
Compare shared kernel, virtual machine, host, node, runtime, credential, and control-plane trust boundaries.
Design a webhook, import, preview, or fetch service with strict destination, redirect, credential, egress, and resource policy.
Map user identity and policy to non-HTTP connections while controlling clients, ports, names, lifetime, and protocol limits.
Distinguish reverse, forward, transparent, and identity-aware proxies by client, destination, trust, and enforcement role.
Exchange attested platform identity for short-lived target credentials without copying long-lived cloud keys into workloads.
Place identity, transport, route, and application policy across mesh gateways, sidecars, ambient proxies, and workloads.
Design named administrative access with strong identity, narrow routes, native server controls, session limits, and evidence.
Separate stored secrets from projected, rotated credentials and reduce exposure through identity-bound delivery and use.
Trace resolution, routing, certificate names, endpoint authentication, and failover without treating DNS as identity.
Distinguish a resource-centered security architecture from a product pattern that brokers selected remote access.
Trace human and workload identity across clouds and find direct, federation, routing, control-plane, and recovery bypass paths.
Trace Kubernetes API transport, authentication, authorization, admission, persistence, and audit for human and workload requests.
Trace addresses, prefixes, routes, ports, translation, names, and firewalls without confusing reachability with identity.
Trace TLS 1.3 authentication, key establishment, record protection, termination, and early-data risk across an access path.
Use traffic direction to describe topology, then make identity and resource decisions independently.
Keep routing, segmentation, firewalls, naming, transport protection, and availability controls without using location as trust.
Validate X.509 paths, service names, key usage, constraints, time, and revocation without expanding the trust boundary.
37 related terms
A bastion host is a hardened system that provides controlled administrative access to a more protected network or resource.
Distinguish browser or native-client access from broad network tunnels and state which protocols still require a local connector.
A Cloud Access Security Broker is a policy enforcement point that mediates use of cloud services.
Cloud metadata services can deliver workload credentials, so network and identity boundaries must stop unintended callers.
Cloud network security protects data, workloads, identities, and communication paths in cloud environments. It follows a shared responsibility model.
A context-aware proxy is a policy enforcement point placed between a requester and a protected service.
Separate the systems that define and distribute access policy from the request path that enforces it on live traffic.
Model how traffic, expensive valid work, state, queues, dependencies, identity, and recovery controls can make a service unavailable.
East-west traffic is traffic between workloads, services, or systems within or across internal, cloud, or data-center environments.
Bound untrusted code with explicit memory, process, file, network, device, syscall, identity, and resource controls.
A firewall is a device or program that controls network traffic between networks or hosts according to a firewall policy.
Find every route that reaches a protected origin without the intended identity, policy, and evidence controls.
Explain HTTPS as HTTP over an authenticated, encrypted TLS channel with explicit names, endpoints, and termination boundaries.
An implicit trust zone grants authority from location, membership, or prior access without a resource-specific decision.
Place controls on traffic entering and leaving a workload boundary without treating direction or network location as identity.
IPsec is a suite of protocols that protects IP traffic under a security policy.
Gateway API models infrastructure, listeners, routes, backends, and policy attachment through role-oriented resources.
A namespace scopes names and policy objects, but tenant isolation depends on many cluster and workload controls.
Kubernetes NetworkPolicy controls selected Pod ingress and egress reachability through a supporting network plugin.
Grant Kubernetes API verbs on exact resources and namespaces without broad roles, aggregation, bind, or escalation paths.
Use bounded, short-lived Kubernetes service-account tokens for a workload and avoid static namespace-wide credentials.
A load balancer selects a backend, while a gateway terminates or mediates a protocol boundary and can apply policy.
The primary security goal of micro-segmentation is to limit which workloads can communicate and reduce lateral movement after compromise.
Network segmentation divides a network into logical or physical zones and controls traffic between them.
North-south traffic crosses an environment or trust boundary, such as traffic between a user and an application or between a private service and the internet.
The OSI model is a seven-layer reference model, not a guarantee that each protocol provides reliability.
A security perimeter is a boundary where controls inspect or restrict communication. NIST zero trust does not remove firewalls or all network boundaries.
SASE is an architecture that converges wide-area networking and security functions and delivers them as a distributed cloud service.
An SWG applies policy to user access to internet web services.
A software-defined perimeter hides protected services from unauthorized requesters and establishes identity-controlled connectivity.
Software-defined networking separates programmable control functions from the packet-forwarding plane through defined abstractions and interfaces.
SD-WAN uses a software-controlled policy layer to steer WAN traffic across one or more underlays such as broadband, cellular, and MPLS.
Infer participants, relationships, activity, protocol, content class, and events from communication timing, direction, size, frequency, and routes.
Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.
A VPN creates an encrypted tunnel over another network. Remote-access VPNs connect an endpoint to a private network. Site-to-site VPNs connect networks.
Use platform evidence to select a workload identity without treating mutable labels or network location as proof.
ZTNA is an access approach that applies zero trust principles to connections between subjects and specific private resources.