
GitLab
Use GitLab.com or GitLab Self-Managed as the identity provider for Pomerium-protected applications through OAuth and OpenID Connect.
Overview
GitLab is a software delivery platform. Pomerium can use GitLab.com through its built-in provider or a GitLab Self-Managed instance through OpenID Connect as an identity source for protected routes.
GitLab identity can give development teams one sign-in path for private applications. The applications keep their own detailed permissions after Pomerium approves the route.
GitLab sends authenticated identity data toward Pomerium. Pomerium applies route policy and sends only approved traffic toward the protected application.
How it works
Register a GitLab application with the exact Pomerium callback URL and the openid, profile, and email scopes.
Use the gitlab provider for GitLab.com. Use the generic oidc provider and the instance base URL for GitLab Self-Managed.
Test the exact claims that the selected GitLab instance issues. Keep client credentials outside source control.
Example
A team registers Pomerium as a GitLab application with the openid, profile, and email scopes. Users sign in through GitLab. Pomerium applies route policy before it sends approved traffic to a private service.
Considerations
- This route supplies identity. It does not protect GitLab repositories or Git traffic.
- Do not assume that Pomerium receives every GitLab group claim.
- GitLab editions and hosting models have different identity configuration details.
