Protect a self-hosted code-server browser IDE with Pomerium authentication and route policy, with WebSocket support and the correct public host.
Put the Cockpit Linux administration interface behind Pomerium so users pass identity-aware route policy before Cockpit host login.
Put GitLab Self-Managed behind a Pomerium HTTPS route so users pass identity-aware policy before GitLab login.
Put the Argo Workflows UI and API behind Pomerium so users pass identity-aware route policy before traffic reaches Argo Server.
Protect self-hosted Grafana dashboards with Pomerium route policy and SSO, then pass a signed identity JWT for seamless Grafana login.
Protect a private Google Cloud Run service with a Pomerium route, identity-aware policy, and Google-signed serverless authentication.
Protect access to Apache Airflow workflows and administration as an upstream web application.
Protect access to Apache Superset dashboards and data exploration as an upstream web application.
Protect access to Backstage developer portals and software catalogs as an upstream web application.
Protect access to self-hosted CircleCI Server web and API services.
Protect ClickHouse HTTP endpoints and native database connections with separate Pomerium routes.
Protect access to self-managed Confluence Data Center workspaces as an upstream web application.
Protect the Elasticsearch HTTP API while keeping cluster transport traffic on the private network.
Protect the Gitea web application and Git Smart HTTP traffic, with a separate route for Git over SSH when required.
Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.
Protect access to Grafana Loki HTTP endpoints as upstream web applications.
Protect the HashiCorp Consul user interface and HTTP API, with separate DNS routes when required.
Protect access to the HashiCorp Nomad user interface and HTTP API as upstream applications.
Protect access to the HashiCorp Vault user interface and HTTP API as upstream applications.
Protect access to internal administration panels as upstream web applications.
Protect access to internal HTTP APIs with identity-aware Pomerium routes.
Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.
Protect access to self-managed Jira Data Center workspaces as an upstream web application.
Protect access to JupyterHub notebook environments as an upstream web application.
Protect access to Kibana dashboards and administration as an upstream web application.
Review the retired Kubernetes Dashboard access pattern and the project recommendation to use Headlamp.
Protect access to self-hosted Mattermost workspaces as an upstream web application.
Protect access to Metabase analytics and administration as an upstream web application.
Protect access to the current MinIO AIStor Console as an upstream web application.
Protect access to MongoDB services through Pomerium TCP routes.
Protect access to MySQL services through Pomerium TCP routes.
Protect access to self-hosted NocoDB workspaces as an upstream web application.
Protect access to OpenSearch Dashboards as an upstream web application.
Protect access to pgAdmin 4 when it runs in server mode as an upstream web application.
Protect access to Portainer container administration as an upstream web application.
Protect access to PostgreSQL services through Pomerium TCP routes.
Protect access to Prometheus metrics and administration as an upstream web application.
Protect access to the Proxmox VE management interface as an upstream web application.
Protect the RabbitMQ management interface and message protocols with separate HTTP and TCP routes.
Protect access to Redis services through Pomerium TCP routes.
Protect access to Rundeck operations and automation as an upstream web application.
Protect the interactive Self-Hosted Sentry application without blocking SDK or Relay ingestion.
Protect access to SonarQube Server while keeping scanners, webhooks, and automation on compatible noninteractive paths.
Protect access to Spinnaker deployment services as upstream web applications.
Protect access to SUSE Rancher Manager cluster administration as an upstream web application.
Protect access to Temporal Web UI as an upstream web application without claiming to proxy worker and SDK gRPC traffic.
Protect the Traefik Proxy API and dashboard internal service as an upstream web application.
Protect the VMware vCenter Server web interface and API without claiming to cover every vSphere service.