Skip to main content

Native SSH access

Identity-aware SSH without a custom tunnel client

Users connect with a standard SSH client. Pomerium authenticates them through OAuth, applies SSH route policy, and presents an ephemeral certificate to the upstream server.

What this pattern controls

Native client

Use the standard SSH client already in the operator workflow.

Ephemeral credential

Issue a short-lived user certificate after authentication.

Identity policy

Apply route and SSH-specific policy before access.

SSH trust path

Use short-lived certificates instead of shared SSH keys

Pomerium terminates the downstream SSH connection, authenticates the user, evaluates policy, and connects to the upstream with a signed user certificate.

  • Configure Pomerium host keys and a user certificate-authority key.
  • Trust the Pomerium user CA on each upstream SSH server.
  • Define each upstream SSH server as an ssh route.

Protocol boundary

Keep the native SSH workflow explicit

Native SSH requires server-side CA trust and Pomerium SSH configuration. It is different from the pomerium-cli TCP tunnel path.

  • Use a standard SSH client without a Pomerium tunnel.
  • Apply supported general and SSH-specific policy criteria.
  • Use Zero or Enterprise session recording only when that licensed feature is configured.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo