Skip to main content
See All Integrations

Kubernetes

Use the official Pomerium Ingress Controller to convert selected Kubernetes Ingress resources into TLS routes with identity-aware policy.

First-party Pomerium Kubernetes integration guide

Categories
Architectures, Deployment Environments

Overview

The Pomerium Kubernetes integration is the official open-source Pomerium Ingress Controller. It watches Kubernetes Ingress resources that select the pomerium IngressClass and converts their hosts, Services, TLS Secrets, and Pomerium annotations into identity-aware routes.

Application teams can keep route configuration with their Kubernetes resources. Pomerium applies a shared identity and policy layer before traffic reaches each selected Service.

Kubernetes supplies Ingress, Service, Secret, and custom-resource state. The Pomerium controller watches that state and serves only matching TLS routes.

How it works

Verify the current requirements. Install a pinned Pomerium Ingress Controller version and complete the global Pomerium custom resource.

Create a TLS-enabled Ingress with spec.ingressClassName: pomerium, a Service backend, a host, and the required Pomerium policy annotations.

Check the controller, Pomerium custom resource, Ingress events, TLS Secret, and Service endpoints. Test an allowed request and a denied request.

Example

A Grafana Service has a TLS-enabled Ingress with spec.ingressClassName: pomerium and an ingress.pomerium.io/policy annotation. Pomerium approves or denies each request before it sends approved traffic to ready Service endpoints.

Considerations

  • The controller serves only Ingress resources with a matching class, and Pomerium requires TLS.
  • Default Backends and Resource Backends are not supported.
  • Ingress annotations are strings and must encode structured values correctly.
  • Gateway API support is experimental and partial. It does not have full Ingress parity.
  • The controller does not secure the Kubernetes API or all east-west traffic.

Sources and official resources

  • Use cert-manager to issue and renew TLS certificates for services exposed through the Pomerium Kubernetes Ingress Controller.

  • Run the Pomerium Kubernetes Ingress Controller on Amazon EKS and keep application Services private behind explicit Pomerium Ingress resources.

  • Run the Pomerium Kubernetes Ingress Controller on GKE and keep application Services private behind explicit Pomerium Ingress resources.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo