Skip to main content
See All Integrations

Google Kubernetes Engine

Run the Pomerium Kubernetes Ingress Controller on GKE and keep application Services private behind explicit Pomerium Ingress resources.

Pomerium Kubernetes integration pattern

Category
Deployment Environments

Overview

The Google Kubernetes Engine integration runs the Pomerium Kubernetes Ingress Controller in a GKE cluster. Pomerium handles Ingress resources that select spec.ingressClassName: pomerium. This controller is separate from the built-in GKE Ingress controller.

GKE workloads can stay on private Service addresses while Pomerium owns user authentication and route policy. Explicit controller selection prevents the built-in GKE controller from claiming a Pomerium application Ingress.

GKE runs the Kubernetes resources. The Pomerium controller converts matching Ingress resources into protected routes. Google Cloud networking exposes the Pomerium service through the reviewed load-balancer design.

How it works

Verify the current Pomerium requirements. Install a pinned controller version and complete the global Pomerium custom resource. Use the documented http3-gke variant only when the design needs HTTP/3.

Create the application Ingress with spec.ingressClassName: pomerium, TLS, policy annotations, and a private Service backend. Do not add the GKE gce or gce-internal class annotation to that resource.

Validate the Pomerium service, Google Cloud load balancer, health checks, firewall rules, DNS, TLS, controller events, and Service endpoints. Test an allowed request and a denied request.

Example

A private Grafana Service has a TLS Ingress with spec.ingressClassName: pomerium and no gce or gce-internal class annotation. Pomerium builds the route and policy. The platform team exposes Pomerium through the selected GKE load balancer.

Considerations

  • The built-in GKE Ingress controller still selects resources with the kubernetes.io/ingress.class annotation. It is separate from the Pomerium controller.
  • Google places GKE Ingress in maintenance mode and recommends Gateway API. Pomerium Gateway API support is still experimental and partial, so do not assume full parity.
  • Pomerium protects the application routes you configure. GKE control-plane access, Google Cloud IAM, and east-west traffic need separate controls.

Sources and official resources

  • Use the official Pomerium Ingress Controller to convert selected Kubernetes Ingress resources into TLS routes with identity-aware policy.

  • Run the Pomerium Kubernetes Ingress Controller on Amazon EKS and keep application Services private behind explicit Pomerium Ingress resources.

  • Use cert-manager to issue and renew TLS certificates for services exposed through the Pomerium Kubernetes Ingress Controller.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo