Pomerium is an identity and context-aware access proxy, written in Go and released under the Apache-2.0 licence, that builds secure, clientless connections to internal web applications and other services without a corporate VPN.
What it is
Pomerium is an identity and context-aware reverse proxy. It sits in front of internal web applications and other services and brokers access to them, combining identity and access management with proxying so that requests are authenticated and evaluated before they reach anything behind it. The project is written in Go, ships under the Apache-2.0 licence, and is listed in this registry under Infrastructure & Operations / Networking & Connectivity with 5,020 stars and 357 forks. Its topics place it in the identity-aware proxy, reverse proxy, gateway and zero-trust space, alongside IAM, BeyondCorp and AI gateway concerns.
The concrete problem it solves is remote access to internal services without a corporate VPN. Rather than tunnelling users onto the network and trusting them once they arrive, Pomerium is deployed where the applications and services are, requires no client software on the user's device, and verifies every single action before allowing it to execute. Access decisions are context-aware, integrating organizational data so that policy reflects more than a login event. That combination of clientless, tunnel-free and continuously verified access is the specific thing the project replaces.
Key capabilities
- Identity-aware reverse proxying for internal web apps and other services, with authentication handled by the proxy rather than by each application.
- Clientless access, so users reach protected services from a browser without an agent or VPN client.
- Tunnel-free architecture deployed where the applications and services already run, rather than routing traffic through a central concentrator.
- Continuous verification and auditing, verifying every action before it is allowed to execute.
- Context-aware access policies derived from integrated organizational data.
- Zero-trust and BeyondCorp access patterns, positioned as a replacement for VPN-based remote access.
- AI gateway functionality, reflected in the aigateway topic alongside its gateway, IAM and identity roles.
Who uses it and how
- Security and platform teams replacing a corporate VPN for internal web applications, so unmanaged or third-party devices need no client software.
- Organizations adopting zero-trust or BeyondCorp-style access, using Pomerium as the enforcement point in front of internal services.
- Teams that need per-action verification and an audit trail, since every action is verified before execution.
- Operators who would rather not run the control plane themselves can use Pomerium Zero, the hosted control plane with a management GUI.
- Deployments where the proxy runs alongside the applications and services it protects.
Getting started
Pomerium is distributed as the Docker image pomerium/pomerium, for which the repository carries a Docker Pulls badge, with comprehensive documentation and tutorials at the project documentation site. A hosted control plane and management GUI is available through Pomerium Zero at console.pomerium.app.
How it compares
No list of paid products that Pomerium replaces is provided in these facts, and no comparable tool is named in the material given. On the facts available, it stands alone in this registry.
When to use it — and when not to
A self-hoster takes on running and updating the proxy and its identity integrations, and the README excerpt supplied here is brief, deferring installation and configuration to the external documentation rather than describing them in the repository. Teams that want a managed control plane and a graphical interface are pointed to Pomerium Zero instead of self-hosting, and an organization with no internal web applications or services to protect has nothing for an access proxy to guard. The repository also carries 159 open issues, which is worth weighing before adopting it.