
Cloud Run
Protect a private Google Cloud Run service with a Pomerium route, identity-aware policy, and Google-signed serverless authentication.
Overview
Cloud Run is a managed Google Cloud platform for containerized services. Pomerium can protect a private Cloud Run service and use Google-signed serverless authentication for the upstream request.
Cloud Run can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Cloud Run. Cloud Run remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Remove public allUsers access. Grant the exact Pomerium service account roles/run.invoker on the selected service. Route to the run.app address and enable Google Cloud serverless authentication on the Pomerium route.
Example
A team keeps a Cloud Run service private and grants only the Pomerium service account the Cloud Run Invoker role. Pomerium route policy approves the user before Pomerium sends a signed request to the service.
Considerations
- The Pomerium Kubernetes Ingress Controller does not support the Google Cloud serverless authentication setting.
- Cloud Run sees Pomerium's service identity. It does not see each user's Google identity as the Cloud Run caller.
- Run Pomerium on a supported host or cluster that can reach the existing Cloud Run service.
