Skip to main content
See All Integrations

Cloud Run

Protect a private Google Cloud Run service with a Pomerium route, identity-aware policy, and Google-signed serverless authentication.

First-party Pomerium integration guide

Categories
Architectures, Deployment Environments

Overview

Cloud Run is a managed Google Cloud platform for containerized services. Pomerium can protect a private Cloud Run service and use Google-signed serverless authentication for the upstream request.

Cloud Run can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Cloud Run. Cloud Run remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.

Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.

Remove public allUsers access. Grant the exact Pomerium service account roles/run.invoker on the selected service. Route to the run.app address and enable Google Cloud serverless authentication on the Pomerium route.

Example

A team keeps a Cloud Run service private and grants only the Pomerium service account the Cloud Run Invoker role. Pomerium route policy approves the user before Pomerium sends a signed request to the service.

Considerations

  • The Pomerium Kubernetes Ingress Controller does not support the Google Cloud serverless authentication setting.
  • Cloud Run sees Pomerium's service identity. It does not see each user's Google identity as the Cloud Run caller.
  • Run Pomerium on a supported host or cluster that can reach the existing Cloud Run service.

Sources and official resources

  • Run the Pomerium Kubernetes Ingress Controller on GKE and keep application Services private behind explicit Pomerium Ingress resources.

  • Use the official Pomerium Ingress Controller to convert selected Kubernetes Ingress resources into TLS routes with identity-aware policy.

  • Use Docker Compose to connect the official Pomerium container to protected application containers on a private network without publishing each upstream port.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo