
Cockpit
Put the Cockpit Linux administration interface behind Pomerium so users pass identity-aware route policy before Cockpit host login.
Overview
Cockpit is a web administration interface for Linux servers. Pomerium can control access to the Cockpit route before Cockpit asks for the host login.
Cockpit can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Cockpit. Cockpit remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Enable WebSockets, preserve the public host, set the exact HTTPS and WSS origins, and set ProtocolHeader to X-Forwarded-Proto. Run Cockpit without upstream TLS only on the private path behind Pomerium, and restrict port 9090 to Pomerium.
Example
A server team exposes Cockpit only through Pomerium. Pomerium policy limits route access to administrators. Cockpit then uses its normal PAM or SSH host authentication.
Considerations
- Pomerium gates the route. It does not sign the user into Cockpit.
- Cockpit still uses its normal PAM or SSH host authentication and host authorization.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- CockpitOfficial website
- Cockpit web service guideOfficial documentation
- Cockpit configurationPrimary source
- Cockpit repositoryOfficial repository
- Secure Cockpit with PomeriumPomerium documentation
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
