Skip to main content

Upstream and Downstream

Upstream and downstream describe direction relative to one intermediary, so the reference point must be explicit.

What is the distinction?

Relative to a proxy, downstream is the client-facing side and upstream is the service-facing side. Relative to another intermediary, the same component can change labels. Always state the reference point and traffic direction.

Why it matters

TLS, identity, headers, timeouts, retries, health, and policy can differ on each hop. An instruction to "trust the upstream header" is unsafe unless it names which component created it and which downstream path is trusted.

How it works

A client opens a downstream connection to Pomerium. Pomerium authenticates and authorizes the request, then opens or reuses an upstream connection to the configured service. Each hop has separate endpoint identity, transport, protocol, and failure behavior.

Example

The browser is downstream of Pomerium. Grafana is upstream of Pomerium. From Grafana's view, Pomerium is its downstream client.

Failure and residual risk

Ambiguous direction causes certificate, timeout, header, and logging errors. Retries can duplicate upstream actions. An upstream service can be reachable through another downstream path that bypasses the proxy.

Pomerium boundary

Pomerium terminates the client-facing path and connects to configured upstreams. Operators own both transport boundaries, upstream identity verification, direct-path isolation, and application behavior.

Evaluation checklist

  • Relative to which intermediary are upstream and downstream defined?
  • Which endpoint identity and TLS policy apply on each hop?
  • Who creates, removes, and validates identity headers?
  • How do timeouts, retries, and failures cross the boundary?
  • Can another downstream path reach the upstream directly?

Sources and further reading

Keep learning

Application and Service Access

Route

In Pomerium, a route defines how a requester reaches a service behind Pomerium.

Learn this term
Application and Service AccessNetwork and Infrastructure

Context-Aware Proxy

A context-aware proxy is a policy enforcement point placed between a requester and a protected service.

Learn this term
Agentic AccessIdentity and Authentication

Identity Propagation

Identity propagation carries verified information about the originating principal and, when needed, the acting service across request boundaries.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo