Skip to main content

Kubernetes security

Identity-aware ingress for selected Kubernetes Services

Install the Pomerium Kubernetes Ingress Controller, define a TLS Ingress, and attach policy to the selected HTTP or HTTPS Service.

What this pattern controls

Ingress scope

Protect selected HTTP and HTTPS Services.

Route policy

Attach Pomerium policy to the Ingress route.

Layered controls

Keep Kubernetes RBAC and application permissions.

Kubernetes ingress

Install the controller and define a protected Ingress

Use this pattern for selected HTTP and HTTPS Services. It does not secure all cluster or east-west traffic.

  • Install the official Pomerium Kubernetes Ingress Controller.
  • Define global settings in the Pomerium custom resource.
  • Set spec.ingressClassName to pomerium on the protected Ingress.

Scope

Protect the service boundary, not the whole cluster

Kubernetes still selects the backend Pod. Pomerium controls access to the selected route and does not replace Kubernetes RBAC.

  • Select the backend Kubernetes Service.
  • Attach route policy with supported Pomerium annotations.
  • Keep Kubernetes RBAC and application permissions in place.

Technical sources

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo