Skip to main content

Secure service access

Named machine identities for private service routes

Authenticate a workload with a Pomerium service account JWT, then apply the policy on the requested route before Pomerium forwards the request.

What this pattern controls

Named workload

Give each workload a unique service identity.

Narrow route

Permit only the required Pomerium route.

Clear boundary

Keep detailed permissions in the service.

Machine identity

Give each workload its own service account

A Pomerium service account JWT is a machine credential for Pomerium Zero or Enterprise. Do not share one workload identity across unrelated services.

  • Create a separate service account user ID for each workload.
  • Store its JWT as a secret.
  • Set an expiration date when the workload has a known lifetime.

Route boundary

Authorize the exact private service route

Pomerium applies route policy on each request before it forwards traffic. Route access does not replace the service's detailed authorization.

  • Add the service account user ID to the required route policy.
  • Use separate routes when human and machine trust requirements differ.
  • Keep operation, resource, and data authorization in the upstream service.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo