docs: add architecture diagram for cloudrun (#1444)

This commit is contained in:
Travis Groth 2020-09-22 17:40:48 -04:00 committed by GitHub
parent 0c60a9404e
commit fdec45fe04
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
2 changed files with 502 additions and 0 deletions

View file

@ -21,6 +21,8 @@ These bearer tokens are not easily set in a browser session and must be refreshe
## How it works
![cloudrun architecture](./img/cloud-run/architecture.svg)
- Add an IAM policy delegating `roles/run.invoker` permissions to a service account
- Run Pomerium with access to a key for the corresponding service account
- Publish DNS records for each protected application pointing to Pomerium