Secure Shell
Protect SSH access with Pomerium native SSH or TCP routes.
Overview
Secure Shell is a protocol for secure remote login, command execution, file transfer, and tunneling. Pomerium includes a native SSH access capability. A generic Pomerium TCP tunnel is a separate access model.
Secure Shell can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can start the selected SSH route. The SSH server remains responsible for host keys, user mapping, command and file permissions, and forwarding controls.
How it works
Use the documented Pomerium native SSH route when that model fits the deployment. A generic TCP tunnel is a separate option.
Keep SSH host-key verification and the server authorization controls active. Test the edition-specific authorization criteria before deployment.
Choose the native SSH model or the generic TCP tunnel model. Do not mix their client commands or policy assumptions. Test host keys, user mapping, file transfer, forwarding, and session behavior.
Example
An engineer connects to a private SSH host through the documented Pomerium native SSH route. Pomerium evaluates the route policy. The SSH server keeps its host keys and applicable server permissions.
Considerations
- Some native SSH authorization criteria are edition-specific. Confirm the current product requirements.
- Keep SSH host-key verification and server-side controls active.
