Project reference ↗

Employees may need access to internal web applications without joining an entire private network. Pomerium sits in front of those applications, uses an identity provider to establish who the visitor is and evaluates rules for the requested route. That makes it useful for applying consistent sign-in and access policies across services. Its Kubernetes controller also manages routing, so deployment choices must define both which traffic it owns and which identities are allowed to reach each application.

Current guidance

Current official Kubernetes documentation describes a controller that builds routes from Ingress resources, selects a matching ingressClassName and requires HTTPS. This is a useful current installation model, but it is not evidence that an old stable/pomerium release can be upgraded by changing only its chart repository.

Decide whether Pomerium will own the external ingress path or sit within an existing access architecture. Inventory identity-provider claims, allowed users/groups, session behavior, upstream identity headers and mutual TLS requirements. Policies attached to routes need the same review as application authorization; an authenticated user should not automatically be allowed to reach every protected service.

Translate configuration deliberately into the selected controller’s global settings and per-route annotations. Test accepted and denied identities, overlapping host/path routes, logout, expired sessions, WebSockets and upstream TLS against representative applications. Restrict namespace and ingress-class ownership so two controllers do not compete. Keep the previous endpoint available until authorization behavior, not just successful login, matches the migration plan. No access-policy migration was executed here.

Historical upstream link check · 2026-10-09

The recorded upstream address responded successfully (HTTP 200) on 2026-10-09. GitHub confirms that helm/charts is archived: this is a historical chart distribution, not evidence that the application itself is retired. Link availability does not certify the historical installation instructions or current security support.

Source for this check ↗

Website availability is separate from project, chart and image support. Use the current guidance and primary sources on this page to assess the distribution.

The original record

Historical Kubedex content

Original publication: 2019-07-30T03:51:02+00:00. Preserved for context. Commands, versions, prices and results below reflect the original research.

Pomerium is a context and identity aware access proxy.

Pomerium can be used to:

  • enable secure remote access to internal websites, without a VPN.
  • provide unified authentication (SSO) using the identity provider of your choice.
  • enforce dynamic access policy based on context, identity, and device state.
  • aggregate access logs and telemetry data.

 

The post Pomerium appeared first on kubedex.com.

Sources & further reading

  1. Official Pomerium Kubernetes ingress model
  2. Recovered historical source

Spotted something that needs another look?

Help improve this page →