Skip to main content

Kubernetes access

Identity-aware kubectl access to Kubernetes APIs

Put Pomerium in front of the Kubernetes API server. Authenticate users through Pomerium, apply route policy, and let Kubernetes RBAC authorize cluster resources.

What this pattern controls

Consistent identity

Use the configured identity provider for cluster access.

Access gateway

Apply Pomerium route policy before the API request proceeds.

Native RBAC

Keep Kubernetes resources and verbs under Kubernetes RBAC.

API authentication

Choose the Kubernetes identity path

Pomerium supports user impersonation and Pomerium JWT authentication paths. The Kubernetes API server remains the owner of Kubernetes RBAC.

  • Use Kubernetes user impersonation when Pomerium presents an authorized service-account identity.
  • Use Pomerium JWT with Kubernetes Structured Authentication Configuration on supported Kubernetes versions.
  • Map verified users and groups to Kubernetes RBAC subjects.

Operator workflow

Keep kubectl and Kubernetes RBAC

Users keep kubectl and a kubeconfig. The Pomerium CLI supplies the credential flow for the protected API route.

  • Use pomerium-cli as a kubeconfig credential plugin.
  • Keep the API server behind the protected Pomerium route.
  • Use standard kubectl commands after the credential flow completes.

Kubernetes authentication

Choose the API-server identity method

User impersonation

Pass user identity through Kubernetes impersonation

Pomerium uses an authorized service account to impersonate the verified user and groups. Kubernetes RBAC makes the resource decision.

Pomerium JWT

Let the API server validate Pomerium identity

Kubernetes 1.30 and later can use Structured Authentication Configuration to validate a Pomerium JWT. Cloud providers might not expose the required API-server setting.

Technical sources

Pomerium CLI

Install and use pomerium-cli for the credential flow.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo