Skip to main content

Pomerium Integrations

Connect Pomerium to identity, context, services, and deployment tools.

Identity sources

  • Use Auth0 as Pomerium's OpenID Connect identity provider, then apply authenticated identity and selected claims to private application policy.

  • Azure Active Directory is now Microsoft Entra ID. Use the current Pomerium integration guide while keeping azure as the provider configuration key.

  • Use GitHub as an OAuth 2.0 identity provider for Pomerium-protected applications with a registered callback, client ID, and client secret.

  • Use GitLab.com or GitLab Self-Managed as the identity provider for Pomerium-protected applications through OAuth and OpenID Connect.

  • Use Google Workspace accounts as the Google identity provider for Pomerium-protected applications, with optional Enterprise directory sync for groups.

  • Use Okta as Pomerium's OpenID Connect identity provider, apply user and group claims to route policy, and add Enterprise directory sync when needed.

  • Use OneLogin as Pomerium's OpenID Connect identity provider to authenticate users and apply their identity to route policy.

  • Connect a compatible OpenID Connect provider to Pomerium with discovery, authorization-code sign-in, identity claims, and route policy.

  • Use PingOne for Workforce as Pomerium's OpenID Connect identity provider and apply Ping identity or group data to access policy.

  • Use an Amazon Cognito User Pool as the identity provider for Pomerium through OpenID Connect.

  • Use authentik as the identity provider for Pomerium through OpenID Connect.

  • Use Dex as the identity provider for Pomerium through OpenID Connect.

  • Use Duo Single Sign-On as the identity provider for Pomerium through OpenID Connect.

  • Use IBM Verify as the identity provider for Pomerium through OpenID Connect.

  • Use Idira IAM, formerly CyberArk Workforce Identity, as the identity provider for Pomerium through OpenID Connect.

  • Use JumpCloud as the identity provider for Pomerium through OpenID Connect.

  • Use Keycloak as the identity provider for Pomerium through OpenID Connect.

  • Use Microsoft Entra ID as the identity provider for Pomerium through OpenID Connect.

  • Use Ory Hydra as the identity provider for Pomerium through OpenID Connect.

  • Use PingAM, formerly ForgeRock Access Management, as the identity provider for Pomerium through OpenID Connect.

  • Use ZITADEL as the identity provider for Pomerium through OpenID Connect.

Context sources

  • Use the Pomerium Enterprise FleetDM plugin to evaluate Fleet device policy and vulnerability data during access decisions.

  • Use TriNet HR Platform workforce records in Pomerium Enterprise policy to check employment status and worker type before access.

  • Use Tor exit relay IP data in Pomerium Enterprise policy to identify or restrict requests from known Tor exits.

  • Import selected BambooHR workforce fields into Pomerium Enterprise policy with the example external data source and user email matching.

  • Use selected CrowdStrike Falcon data in Pomerium policy through a custom external data source.

  • Use selected IP geolocation records in Pomerium policy with the documented GeoIP data-source pattern.

  • Use selected Iru Endpoint Management device data in Pomerium policy through a custom external data source.

  • Use selected Jamf Pro device data in Pomerium policy through a custom external data source.

  • Use selected Kolide inventory records in Pomerium policy through a customer-owned external data source.

  • Use selected Microsoft Intune device data in Pomerium policy through a custom external data source.

  • Use selected Rippling workforce data in Pomerium policy through a custom external data source.

  • Use selected ServiceNow CMDB records in Pomerium policy through a custom external data source.

  • Use selected SentinelOne Singularity Endpoint records in Pomerium policy through a customer-owned external data source.

  • Use selected Snipe-IT asset data in Pomerium policy through a custom external data source.

  • Use selected Tanium Platform records in Pomerium policy through a customer-owned external data source.

  • Use selected Workday HCM workforce records in Pomerium policy through a customer-owned external data source.

Protected services

  • Protect a self-hosted code-server browser IDE with Pomerium authentication and route policy, with WebSocket support and the correct public host.

  • Put the Cockpit Linux administration interface behind Pomerium so users pass identity-aware route policy before Cockpit host login.

  • Put GitLab Self-Managed behind a Pomerium HTTPS route so users pass identity-aware policy before GitLab login.

  • Put the Argo Workflows UI and API behind Pomerium so users pass identity-aware route policy before traffic reaches Argo Server.

  • Protect self-hosted Grafana dashboards with Pomerium route policy and SSO, then pass a signed identity JWT for seamless Grafana login.

  • Protect a private Google Cloud Run service with a Pomerium route, identity-aware policy, and Google-signed serverless authentication.

  • Protect access to Apache Airflow workflows and administration as an upstream web application.

  • Protect access to Apache Superset dashboards and data exploration as an upstream web application.

  • Protect access to Backstage developer portals and software catalogs as an upstream web application.

  • Protect access to self-hosted CircleCI Server web and API services.

  • Protect ClickHouse HTTP endpoints and native database connections with separate Pomerium routes.

  • Protect access to self-managed Confluence Data Center workspaces as an upstream web application.

  • Protect the Elasticsearch HTTP API while keeping cluster transport traffic on the private network.

  • Protect the Gitea web application and Git Smart HTTP traffic, with a separate route for Git over SSH when required.

  • Protect GitHub Enterprise Server web and API access, with a separate route for Git over SSH when required.

  • Protect access to Grafana Loki HTTP endpoints as upstream web applications.

  • Protect the HashiCorp Consul user interface and HTTP API, with separate DNS routes when required.

  • Protect access to the HashiCorp Nomad user interface and HTTP API as upstream applications.

  • Protect access to the HashiCorp Vault user interface and HTTP API as upstream applications.

  • Protect access to internal administration panels as upstream web applications.

  • Protect access to internal HTTP APIs with identity-aware Pomerium routes.

  • Protect the Jenkins web application and API, with separate WebSocket or TCP access for build agents when required.

  • Protect access to self-managed Jira Data Center workspaces as an upstream web application.

  • Protect access to JupyterHub notebook environments as an upstream web application.

  • Protect access to Kibana dashboards and administration as an upstream web application.

  • Review the retired Kubernetes Dashboard access pattern and the project recommendation to use Headlamp.

  • Protect access to self-hosted Mattermost workspaces as an upstream web application.

  • Protect access to Metabase analytics and administration as an upstream web application.

  • Protect access to the current MinIO AIStor Console as an upstream web application.

  • Protect access to MongoDB services through Pomerium TCP routes.

  • Protect access to MySQL services through Pomerium TCP routes.

  • Protect access to self-hosted NocoDB workspaces as an upstream web application.

  • Protect access to OpenSearch Dashboards as an upstream web application.

  • Protect access to pgAdmin 4 when it runs in server mode as an upstream web application.

  • Protect access to Portainer container administration as an upstream web application.

  • Protect access to PostgreSQL services through Pomerium TCP routes.

  • Protect access to Prometheus metrics and administration as an upstream web application.

  • Protect access to the Proxmox VE management interface as an upstream web application.

  • Protect the RabbitMQ management interface and message protocols with separate HTTP and TCP routes.

  • Protect access to Redis services through Pomerium TCP routes.

  • Protect access to Rundeck operations and automation as an upstream web application.

  • Protect the interactive Self-Hosted Sentry application without blocking SDK or Relay ingestion.

  • Protect access to SonarQube Server while keeping scanners, webhooks, and automation on compatible noninteractive paths.

  • Protect access to Spinnaker deployment services as upstream web applications.

  • Protect access to SUSE Rancher Manager cluster administration as an upstream web application.

  • Protect access to Temporal Web UI as an upstream web application without claiming to proxy worker and SDK gRPC traffic.

  • Protect the Traefik Proxy API and dashboard internal service as an upstream web application.

  • Protect the VMware vCenter Server web interface and API without claiming to cover every vSphere service.

Access patterns

  • Connect DBeaver to protected database services through Pomerium TCP routes.

  • Protect access to private DNS services through separate Pomerium UDP and TCP routes.

  • Protect Remote Desktop access through separate Pomerium TCP and UDP routes when both transports are required.

  • Protect SSH access with Pomerium native SSH or TCP routes.

  • Protect access to private TCP services through Pomerium routes.

  • Protect access to private UDP services through Pomerium CONNECT-UDP routes.

Deployment integrations

  • Use cert-manager to issue and renew TLS certificates for services exposed through the Pomerium Kubernetes Ingress Controller.

  • Run the Pomerium Kubernetes Ingress Controller on Amazon EKS and keep application Services private behind explicit Pomerium Ingress resources.

  • Use Docker Compose to connect the official Pomerium container to protected application containers on a private network without publishing each upstream port.

  • Run the Pomerium Kubernetes Ingress Controller on GKE and keep application Services private behind explicit Pomerium Ingress resources.

  • Use the official Pomerium Ingress Controller to convert selected Kubernetes Ingress resources into TLS routes with identity-aware policy.

Need another integration guide?

Tell us which integration, service, or deployment path you need. We will use the request to prioritize the next researched guide.

Suggest a guide

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo