Skip to main content
See All Integrations

NocoDB

Protect access to self-hosted NocoDB workspaces as an upstream web application.

Standard protected service pattern

Categories
AI and Data, Upstream Applications

Overview

NocoDB is an open-source web application for working with database data through spreadsheet-style interfaces and APIs. Its browser application and API use HTTP.

NocoDB can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to NocoDB. NocoDB remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.

Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.

Configure the NocoDB public site URL and trusted proxy behavior. Test browser, API, attachment, import, export, and webhook flows.

Example

Employees reach a private NocoDB workspace through Pomerium. NocoDB keeps workspace, base, table, field, and record permissions. API clients use a reviewed noninteractive path.

Considerations

  • Set NC_SITE_URL to the public Pomerium origin for current releases.
  • API clients and integrations need noninteractive authentication.

Sources and official resources

  • Protect access to Metabase analytics and administration as an upstream web application.

  • Protect access to Apache Superset dashboards and data exploration as an upstream web application.

  • Protect access to the current MinIO AIStor Console as an upstream web application.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo