Named workload
Give each workload a unique service identity.
Secure service access
Authenticate a workload with a Pomerium service account JWT, then apply the policy on the requested route before Pomerium forwards the request.
Give each workload a unique service identity.
Permit only the required Pomerium route.
Keep detailed permissions in the service.
Machine identity
A Pomerium service account JWT is a machine credential for Pomerium Zero or Enterprise. Do not share one workload identity across unrelated services.
Route boundary
Pomerium applies route policy on each request before it forwards traffic. Route access does not replace the service's detailed authorization.
Create and use Pomerium service account JWTs.
Apply allow and deny policy to a route.
Select authorization log fields.