Skip to main content

tags

Access Control

Browse Pomerium articles tagged Access Control.

Topic archive

Resources Tagged: Access Control

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included
blog posts

Google Built an Agent Runtime on Kubernetes. Here's How to Build a Cloud-Agnostic One with Identity Included

Google spent the last year quietly admitting what we already knew: Kubernetes was never designed to run AI agents. As Janakiram MSV writes in The New Stack , Google's GKE Agent Sandbox and the new Agent Substrate project amount to an indirect admission "that the platform that won the container decade is not the right control plane for AI agents."

Replacing Ingress-NGINX: A Modern Approach to Secure Kubernetes Access
blog posts

Replacing Ingress-NGINX: A Modern Approach to Secure Kubernetes Access

For years, NGINX Ingress has been the default answer to a simple question: How do I get traffic into my Kubernetes cluster? It excels at Layer-7 routing, TLS termination, and traffic shaping, and for many workloads it remains a solid choice. But as Kubernetes has moved beyond hosting public-facing services and into powering internal platforms , the limitations of traditional ingress have become increasingly apparent.

The OWASP Top 10 for LLMs and How to Defend Against Them
blog posts

The OWASP Top 10 for LLMs and How to Defend Against Them

TL;DR — The OWASP Top 10 for Large Language Model (LLM) applications highlights prompt injection, insecure output handling, and data exposure as critical risks. This guide walks through the Top 10 and shows where Zero Trust access controls, starting free with Pomerium Zero , are most effective: LLM01 Prompt Injection and LLM02 Sensitive Information Disclosure.

Why Traditional Access Controls Fail in LLM Deployments
blog posts

Why Traditional Access Controls Fail in LLM Deployments

TL;DR: Prompt-driven apps quickly outgrow static API keys and coarse Identity Access Management (IAM) roles. OWASP’s LLM risk list shows why that model breaks. The answer is continuous, identity-aware policy applied before prompts ever reach the model. Pomerium provides that control so teams can ship GenAI features with confidence.

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes
blog posts

Why the Managed Context Protocol (MCP) Spec Still Leaves Gaping Security Holes

TL;DR — MCP gives AI agents a shared way to invoke tools and complete tasks. But the spec lacks core security features. There is no built-in authorization, no identity enforcement, and no way to apply context-aware policy. Teams relying on reference servers are exposing internal APIs without guardrails. Pomerium applies Zero Trust controls to every request, adding identity, context, and policy enforcement at Layer 7.

Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)
blog posts

Your Employees Are Already Dumping Company Data to LLMs (Here’s What To Do About It)

It's happening right now, in your organization. That senior developer just pasted your global auth tokens into ChatGPT to debug a tricky race condition. Your data analyst uploaded last quarter's customer churn data to Claude to help write their board presentation. Your product manager is feeding competitive analysis docs to Gemini to brainstorm feature ideas.

12 Crucial Mobile Device Management (MDM) Features - 2025
blog posts

12 Crucial Mobile Device Management (MDM) Features - 2025

When choosing the right Mobile Device Management (MDM) solution for your organization, focusing on essential features is key to meeting both security and operational needs. Here’s a breakdown of the top 12 essential MDM features to help you compare and select the right tool for your business. We have also included a ready-to-use questionnaire that you can utilize to evaluate the features of your shortlisted MDM solutions.

40 Unique IAM Interview Questions and Answers | 2025 Edition
blog posts

40 Unique IAM Interview Questions and Answers | 2025 Edition

Are you a founder, manager, or part of an HR team looking to hire for a position in an identity and access management (IAM) company? A fundamental understanding of IAM is crucial for success, especially if the role is technical, such as an analyst, engineer, or tech support. In this article, we've compiled 40 Identity and Access Management interview questions—ranging from basic to advanced—along with ideal answers to help you evaluate candidates effectively. Additionally, we’ve included operational and behavioral IAM interview questions to assess the candidate's overall personality and fit for the role.

8 Best Open Source Zero Trust Software Solutions
blog posts

8 Best Open Source Zero Trust Software Solutions

Unlike traditional security, which often grants implicit trust to users solely because they are inside the network, the Zero Trust model grants no implicit trust, and therefore continuously verifies all activity, ensuring that only the right people with the right level of access are authorized to reach the resources within the network. There are many open-source zero-trust software that facilitate this approach by ensuring that no entity, whether inside or outside the network, is trusted by default. Here are eight notable open-source Zero Trust software solutions.

Heimdall Reverse Proxy: Features, Alternatives, Pros-Cons
blog posts

Heimdall Reverse Proxy: Features, Alternatives, Pros-Cons

Heimdall is a reverse proxy tool, primarily used for managing and securing web traffic to internal services, often implemented in home labs, self-hosted services, or small-scale cloud environments. Heimdall reverse proxy is typically used to route traffic based on domain or path rules to the appropriate backend service. In this article, we have included Heimdall reverse proxy’s features, pros and cons, and best alternative.

The Best OAuth2 Proxy Alternative: Pomerium
blog posts

The Best OAuth2 Proxy Alternative: Pomerium

An OAuth2 proxy is a reverse proxy server that sits in front of a web application or service to protect access using OAuth2 or OpenID Connect (OIDC) authentication protocols. It acts as an intermediary between the users and the backend services, ensuring that only authenticated users can access protected resources.

10 Best Open Source Mobile Device Management (MDM) Solutions
blog posts

10 Best Open Source Mobile Device Management (MDM) Solutions

Managing mobile devices efficiently is crucial for organizations of all sizes. Mobile Device Management (MDM) is a system that enables organizations to securely manage, monitor, and control devices within their network. Despite the term "mobile" in its name, MDM isn’t limited to just cell phones—it covers a wide range of devices including smartphones, tablets, laptops, and even IoT devices. Choosing the right MDM solution involves considering various factors, so to help with this decision, we’ve shortlisted the 10 best open-source mobile device management solutions.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo