Beyond the VPN: Implementing Zero-Trust Remote Access for Sysadmins with Open-Source Pomerium
The Paradigm Shift: Moving Beyond the Traditional VPN
For decades, the Virtual Private Network (VPN) has been the undisputed backbone of remote server administration. System administrators (sysadmins) have relied on it to bridge the gap between untrusted external networks and secure internal infrastructure. However, as the enterprise threat landscape evolves, the flaws inherent in the traditional perimeter-based security model have become impossible to ignore.
The fundamental issue with a traditional VPN is that it grants network-level access. Once a user or an attacker compromises VPN credentials, they gain entry to the internal network segment. From there, they can move laterally, scanning for vulnerabilities, exploiting unpatched internal services, and exfiltrating sensitive corporate data. For sysadmins managing critical infrastructure, databases, and internal dashboards, this "verify once, trust inherently" approach is a ticking time bomb.
Enter the Zero-Trust Architecture (ZTA). Guided by the core principle of "never trust, always verify," Zero-Trust eliminates the concept of a trusted internal network. Access is never granted based solely on physical or network location. Instead, every single request to an internal resource must be authenticated, authorized, and encrypted based on identity, device posture, and context. For sysadmins looking to secure their infrastructure without the overhead and risks of a legacy VPN, open-source Pomerium has emerged as a powerful, elegant alternative.
What is Pomerium?
Pomerium is an open-source, identity-aware reverse proxy that serves as a single point of ingress for your internal applications and services. Instead of putting users on the network, Pomerium sits between the external world and your private infrastructure, validating every request against your organization's Identity Provider (IdP) and defined access policies.
Whether you need to secure a web-based administration panel, an internal API, or even SSH connections, Pomerium applies context-aware authorization rules in real-time. Because it operates at the application layer (Layer 7) rather than the network layer (Layer 3/4), users only ever see the specific applications they are explicitly authorized to access. The rest of your infrastructure remains entirely invisible to the public internet.
Key Benefits for System Administrators
- Granular Authorization: Define access policies based on user identity, group membership, domain, device health, or geographic location.
- Seamless User Experience: Eliminates the need for cumbersome VPN client software. Users authenticate via a standard web browser using their existing corporate credentials.
- Centralized Logging and Auditing: Pomerium logs every single request, providing unparalleled visibility into who accessed what internal resource, and when. This simplifies compliance and incident response drastically compared to opaque VPN traffic logs.
- Open-Source Agility: The open-source core allows sysadmins to deploy, inspect, and scale the solution self-hosted on their own infrastructure without vendor lock-in.
Architectural Blueprint: VPN vs. Zero-Trust Proxy
To understand the practical superiority of Pomerium, it helps to contrast its architecture with a standard remote access setup.
In a traditional VPN setup, authentication happens at the perimeter. Once authenticated, the user's device is virtually placed inside the network, allowing potential lateral movement to any vulnerable internal server.
With Pomerium, the architecture shifts drastically. The internal servers remain isolated in a private subnet with no public IP addresses and no inbound routing from a VPN gateway. Pomerium acts as the gatekeeper, deployed within a demilitarized zone (DMZ) or an ingress controller in a Kubernetes cluster.
- The sysadmin attempts to access an internal service (e.g.,
[https://grafana.internal.company.com](https://grafana.internal.company.com)). - Pomerium intercepts the request and checks for a valid session cookie.
- If unauthenticated, Pomerium redirects the user to the configured Identity Provider (such as Okta, Azure AD, Google Workspace, or Keycloak).
- Upon successful multi-factor authentication (MFA) at the IdP, the user is redirected back to Pomerium with an identity token.
- Pomerium evaluates the token against its policy engine. If the user belongs to the 'Sysadmin' group, Pomerium proxies the traffic securely to the internal Grafana instance.
Step-by-Step Guide to Configuring Pomerium for Remote Access
Let's walk through a practical deployment scenario. In this guide, we will set up Pomerium using Docker Compose to secure an internal administration dashboard, authenticating users against an Identity Provider via OpenID Connect (OIDC).
Prerequisites
Before beginning the installation, ensure you have the following prerequisites in place:
- A Linux server with Docker and Docker Compose installed.
- A public domain name (e.g.,
company.com) with DNS records pointing to your server's public IP address. - An account with an Identity Provider (IdP) supporting OIDC (e.g., Google Cloud Console, GitHub, or Okta) where you have registered an application and obtained a Client ID and Client Secret.
Step 1: Generate Cryptographic Keys
Pomerium requires a shared secret for internal communication between its components and a cookie secret to encrypt session state. You can generate secure, random base64 strings using the following commands in your terminal:
openssl rand -base64 32
openssl rand -base64 32Keep these strings secure; you will need to paste them into your configuration file shortly.
Step 2: Create the Pomerium Configuration File
Create a directory named pomerium and inside it, create a file named config.yaml. This file dictates how Pomerium authenticates users and proxies traffic. Replace the placeholder values with your actual domain, IdP details, and generated secrets.
# config.yaml
address: ":443"
# Identity Provider Configuration (Example using Google)
idp_provider: "google"
idp_client_id: "YOUR_CLIENT_ID.apps.googleusercontent.com"
idp_client_secret: "YOUR_CLIENT_SECRET"
# Cryptographic Secrets
authenticate_service_url: [https://authenticate.company.com](https://authenticate.company.com)
cookie_secret: "YOUR_GENERATED_COOKIE_SECRET"
shared_secret: "YOUR_GENERATED_SHARED_SECRET"
# Automatically provision TLS certificates via Let's Encrypt
certificates:
- cert: /pomerium/cert.pem
key: /pomerium/privkey.pem
# Access Control Policies
policy:
- from: [https://grafana.company.com](https://grafana.company.com)
to: http://internal-grafana-server:3000
allowed_domains:
- company.com
allowed_groups:
- [email protected]
cors_allow_preflight: true
timeout: 30sStep 3: Define the Deployment with Docker Compose
Next, create a docker-compose.yml file in the same parent directory to manage the Pomerium container and ensure it can communicate seamlessly with your internal services.
version: '3.8'
services:
pomerium:
image: pomerium/pomerium:latest
container_name: pomerium
volumes:
- ./pomerium/config.yaml:/pomerium/config.yaml:ro
ports:
- "80:80"
- "443:443"
environment:
- TZ=UTC
restart: unless-stopped
internal-grafana-server:
image: grafana/grafana:latest
container_name: internal-grafana
expose:
- "3000"
restart: unless-stoppedRun docker-compose up -d to pull the images and launch the infrastructure. Pomerium will automatically handle the incoming TLS handshakes, coordinate authentication with your IdP, evaluate the domain and group policies, and route authorized sysadmins directly to the Grafana interface.
Hardening Your Zero-Trust Environment
While deploying a basic instance of Pomerium drastically improves your security posture over a legacy VPN, production enterprise environments require additional hardening layers to guarantee robust protection against sophisticated threat actors.
1. Integrate Device Posture Checking
True Zero-Trust goes beyond user identity; it validates the health and identity of the connecting endpoint. Pomerium integrates with device management frameworks to verify that a sysadmin is connecting from a corporate-managed laptop with an active firewall, disk encryption enabled, and up-to-date antivirus software. If a sysadmin tries to connect from a compromised personal device, access is instantly denied, even with valid credentials.
2. Enforce Strict Multi-Factor Authentication (MFA)
Ensure that your OIDC Identity Provider enforces hardware-based MFA, such as FIDO2/WebAuthn security keys (e.g., YubiKeys), for all accounts in the administrative group. This mitigates the risk of session hijacking, SIM-swapping, and sophisticated phishing attacks designed to steal standard authentication tokens.
3. Implement Time-Bound Access Policies
Sysadmins often require elevated privileges to perform specific maintenance tasks. Rather than granting permanent access to critical infrastructure, utilize Pomerium's dynamic policy engine to enforce time-bound permissions or integration with Just-In-Time (JIT) access approval workflows. This minimizes the attack surface during non-working hours.
Conclusion: The Future of Infrastructure Administration
Transitioning from a traditional, network-centric VPN to an identity-aware Zero-Trust Remote Access proxy like Pomerium is no longer just a trend—it is an operational necessity for modern engineering organizations. By implementing Pomerium, system administrators can isolate internal services entirely from the public internet, eliminate the hazards of lateral network movement, and establish granular, verifiable access criteria for every single administrative tool.
The open-source nature of Pomerium ensures that teams of any scale can initiate their Zero-Trust journey immediately, safeguarding critical dashboards, terminal environments, and APIs while providing an frictionless, clientless authentication experience for the engineering staff. It is time to deprecate the network perimeter and secure your infrastructure at the application layer.
