Skip to main content
See All Integrations

HashiCorp Nomad

Protect access to the HashiCorp Nomad user interface and HTTP API as upstream applications.

Standard protected service pattern

Categories
Cloud Native Tools, Upstream Applications

Overview

HashiCorp Nomad is a workload orchestrator. Its user interface and client-facing HTTP API normally use port 4646. Internal RPC on 4647 and Serf traffic on 4648 are cluster protocols, not user endpoints.

HashiCorp Nomad can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to HashiCorp Nomad. HashiCorp Nomad remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.

Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.

Configure the public interface origin and route only the selected port 4646 endpoint. Keep the Nomad control plane and cluster network private.

Example

Platform operators use a Pomerium HTTPS route for the private Nomad user interface. Nomad keeps ACLs for jobs, namespaces, variables, nodes, and administrative operations.

Considerations

  • Expose only the client-facing interface and API. Do not send Nomad RPC or Serf traffic through the user route.
  • Preserve Nomad ACLs and TLS. CLI and automation need compatible noninteractive credentials.

Sources and official resources

  • Protect the HashiCorp Consul user interface and HTTP API, with separate DNS routes when required.

  • Protect access to the HashiCorp Vault user interface and HTTP API as upstream applications.

  • Protect access to Portainer container administration as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo