Pomerium is an identity and context-aware access proxy.
Find a file
Kenneth Jenkins d8d59ddded
pin to a debian:latest image for casource base image (#4250) (#4310)
The debian 'stable' images configure apt to install from the rolling
'stable' repository, rather than a specific Debian release. Thus even
though we pin to a specific Docker image digest, the packages installed
by 'apt-get' can change when a new Debian release is promoted to stable.

Instead, pin to an image where apt is configured to install from
repositories for a specific Debian release (in this case, bullseye).
2023-06-16 14:20:09 -07:00
.github pin to a debian:latest image for casource base image (#4250) (#4310) 2023-06-16 14:20:09 -07:00
.vscode
authenticate authenticate: add events (#4051) 2023-05-01 15:11:30 -04:00
authorize authorize: populate issuer even when policy is nil (#4213) 2023-05-31 08:59:19 -07:00
cmd/pomerium
config config: update logic for checking overlapping certificates (#4216) (#4217) 2023-06-01 10:13:40 -06:00
databroker config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
examples Update grafana.ini.yml (#4045) 2023-03-08 09:18:50 -07:00
integration config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
internal config: update logic for checking overlapping certificates (#4216) (#4217) 2023-06-01 10:13:40 -06:00
ospkg
pkg config: update logic for checking overlapping certificates (#4216) (#4217) 2023-06-01 10:13:40 -06:00
proxy config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
scripts dependencies: upgrade go and envoy (#4116) 2023-04-17 16:44:58 -06:00
ui
.codecov.yml
.dockerignore
.fossa.yml
.gitattributes
.gitignore tls: wildcard catch-all cert must be at the end of cert list (#4119) 2023-04-21 12:37:32 -04:00
.golangci.yml config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
.pre-commit-config.yaml
.tool-versions dependencies: upgrade go and envoy (#4116) 2023-04-17 16:44:58 -06:00
3RD-PARTY
DEBUG.MD
Dockerfile pin to a debian:latest image for casource base image (#4250) (#4310) 2023-06-16 14:20:09 -07:00
Dockerfile.debug chore(deps): bump debian from d4bbca2 to 1fbdbcf (#4115) 2023-04-17 13:46:33 -06:00
go.mod chore(deps): bump github.com/google/go-jsonnet from 0.19.1 to 0.20.0 (#4140) 2023-05-01 14:50:20 -04:00
go.sum chore(deps): bump github.com/google/go-jsonnet from 0.19.1 to 0.20.0 (#4140) 2023-05-01 14:50:20 -04:00
LICENSE
Makefile config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00
pomerium.go
README.md
RELEASING.md
SECURITY.md Update SECURITY.md (#4145) 2023-05-01 19:19:15 +00:00
tools.go config: remove source, remove deadcode, fix linting issues (#4118) 2023-04-21 17:25:11 -06:00

pomerium logo

pomerium chat GitHub Actions Go Report Card GoDoc LICENSE Docker Pulls

Pomerium is an identity and context-aware reverse proxy that brokers secure access to apps and services at scale. Pomerium provides a standardized interface to add access control to applications regardless of whether the application itself has authorization or authentication baked-in.

Pomerium can be used in situations where you'd typically reach for a VPN, but, unlike a VPN, does not require a client and uses identity and context, not network locality to determine access.

Pomerium can be used to:

  • provide a single-sign-on gateway to internal applications.
  • enforce dynamic access policy based on context, identity, and device identity.
  • aggregate access logs and telemetry data.
  • a VPN alternative.

Docs

For comprehensive docs, and tutorials see our documentation.

Integration Tests

To run the integration tests locally, first build a local development image:

./scripts/build-dev-docker.bash

Next go to the integration/clusters folder and pick a cluster, for example google-single, then use docker-compose to start the cluster. We use an environment variable to specify the dev docker image we built earlier:

cd integration/clusters/google-single
env POMERIUM_TAG=dev docker-compose up -V

Once that's up and running you can run the integration tests from another terminal:

go test -count=1 -v ./integration/...

If you need to make a change to the clusters themselves, there's a tpl folder that contains jsonnet files. Make a change and then rebuild the clusters by running:

go run ./integration/cmd/pomerium-integration-tests/ generate-configuration