
pgAdmin 4
Protect access to pgAdmin 4 when it runs in server mode as an upstream web application.
Overview
pgAdmin 4 is a PostgreSQL administration tool. Only server mode provides an HTTP upstream for Pomerium. Desktop mode is a local client and is not a web application route.
pgAdmin 4 can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to pgAdmin 4. pgAdmin 4 remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Configure the server-mode public URL, proxy headers, cookie security, and session settings for the Pomerium origin. Keep PostgreSQL endpoints private and separately controlled.
Example
Database administrators reach a private pgAdmin 4 server-mode deployment through Pomerium. pgAdmin and PostgreSQL keep their own accounts, saved connections, database roles, and SQL permissions.
Considerations
- This pattern applies only to pgAdmin 4 server mode. Desktop pgAdmin is a client.
- Protecting pgAdmin does not itself protect the database connections that pgAdmin opens to PostgreSQL.
