Ingress scope
Protect selected HTTP and HTTPS Services.
Kubernetes security
Install the Pomerium Kubernetes Ingress Controller, define a TLS Ingress, and attach policy to the selected HTTP or HTTPS Service.
Protect selected HTTP and HTTPS Services.
Attach Pomerium policy to the Ingress route.
Keep Kubernetes RBAC and application permissions.
Kubernetes ingress
Use this pattern for selected HTTP and HTTPS Services. It does not secure all cluster or east-west traffic.
Scope
Kubernetes still selects the backend Pod. Pomerium controls access to the selected route and does not replace Kubernetes RBAC.
Install the controller and required resources.
Configure the protected Ingress and annotations.
Separate kubectl and API server access flow.