Consistent identity
Use the configured identity provider for cluster access.
Kubernetes access
Put Pomerium in front of the Kubernetes API server. Authenticate users through Pomerium, apply route policy, and let Kubernetes RBAC authorize cluster resources.
Use the configured identity provider for cluster access.
Apply Pomerium route policy before the API request proceeds.
Keep Kubernetes resources and verbs under Kubernetes RBAC.
API authentication
Pomerium supports user impersonation and Pomerium JWT authentication paths. The Kubernetes API server remains the owner of Kubernetes RBAC.
Operator workflow
Users keep kubectl and a kubeconfig. The Pomerium CLI supplies the credential flow for the protected API route.
Kubernetes authentication
Pomerium uses an authorized service account to impersonate the verified user and groups. Kubernetes RBAC makes the resource decision.
Kubernetes 1.30 and later can use Structured Authentication Configuration to validate a Pomerium JWT. Cloud providers might not expose the required API-server setting.
User impersonation, Pomerium JWT, kubeconfig, and RBAC setup.
Install and use pomerium-cli for the credential flow.
Route-level identity and context policy.