Skip to main content

Reference Architecture: Using AWS EKS with Pomerium

Pomerium integrates well with AWS EKS, giving you fine grained access to any application you’re hosting in AWS, regardless of how Authentication and Authorization are managed. Pomerium also supports any IdP you may be using, including AWS Cognito.

Architectural Notes

  • Pomerium prefers a Network Load Balancer over an ELB/ALB, due to performing best when TLS is terminated at its proxy.
  • Pomerium can be used to offload Authentication that supports JWKS, as well as can be used to add AuthN/AuthZ to applications that don’t have it (in this case shown as Redpanda’s console, which defaults to HTTP without Auth)
  • Pomerium can be used to provide secure authentication to your Kubernetes API, anywhere in the world, without the need for a client.
  • Pomerium can also be used to provide SSH to your internal hosts and databases via our TCP over HTTPS support

AWS EKS

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo