What is the distinction?
Relative to a proxy, downstream is the client-facing side and upstream is the service-facing side. Relative to another intermediary, the same component can change labels. Always state the reference point and traffic direction.
Why it matters
TLS, identity, headers, timeouts, retries, health, and policy can differ on each hop. An instruction to "trust the upstream header" is unsafe unless it names which component created it and which downstream path is trusted.
How it works
A client opens a downstream connection to Pomerium. Pomerium authenticates and authorizes the request, then opens or reuses an upstream connection to the configured service. Each hop has separate endpoint identity, transport, protocol, and failure behavior.
Example
The browser is downstream of Pomerium. Grafana is upstream of Pomerium. From Grafana's view, Pomerium is its downstream client.
Failure and residual risk
Ambiguous direction causes certificate, timeout, header, and logging errors. Retries can duplicate upstream actions. An upstream service can be reachable through another downstream path that bypasses the proxy.
Pomerium boundary
Pomerium terminates the client-facing path and connects to configured upstreams. Operators own both transport boundaries, upstream identity verification, direct-path isolation, and application behavior.
Evaluation checklist
- Relative to which intermediary are upstream and downstream defined?
- Which endpoint identity and TLS policy apply on each hop?
- Who creates, removes, and validates identity headers?
- How do timeouts, retries, and failures cross the boundary?
- Can another downstream path reach the upstream directly?
