Back to articles
Technology Insight

Securing Internal Infrastructure: A Guide to Pomerium Zero-Trust Proxy with Google Workspace OAuth2

June 3, 2026

The Paradigm Shift: Moving Beyond the Secure Perimeter

For decades, corporate network security relied on the traditional perimeter model: a digital moat consisting of firewalls and Virtual Private Networks (VPNs). Once an employee authenticated through the VPN, they were granted broad lateral access to the internal network. However, in today’s decentralized business ecosystem—defined by remote work, cloud migration, and sophisticated cyber threats—this "trust but verify" approach is dangerously obsolete.

If an attacker compromises a single set of VPN credentials, they gain a foothold to traverse your entire internal infrastructure. To mitigate this systemic vulnerability, modern enterprises are pivoting toward a Zero-Trust Architecture (ZTA). Guided by the core principle of "never trust, always verify," Zero-Trust dictates that identity and context must be continuously authenticated and authorized for every single request, regardless of whether it originates inside or outside the physical office network.

Among the leading solutions enabling this transition is Pomerium, an open-source, identity-aware access proxy that integrates seamlessly with your existing Identity Provider (IdP) to secure internal endpoints without the performance bottlenecks or security liabilities of a legacy VPN.

---

What is Pomerium, and Why Pair it with Google Workspace?

Pomerium acts as a centralized gatekeeper for your internal applications, infrastructure, and APIs. Instead of exposing services directly to the public internet or burying them behind a complex network layer, Pomerium intercepts all incoming traffic, validates the user’s identity against an external IdP, evaluates contextual access policies, and only then forwards the traffic to the upstream service.

Integrating Pomerium with Google Workspace OAuth2 provides an enterprise-grade security solution leveraging infrastructure you likely already manage. By combining these two technologies, organizations achieve several critical advantages:

  • Centralized Identity Management: Leverage existing Google Workspace user directories, organizational units (OUs), and group memberships without creating redundant credential databases.
  • Enforce Multi-Factor Authentication (MFA): Inherit Google’s robust security controls, including hardware security keys, Google Authenticator, and push notifications.
  • Granular Contextual Access: Define access policies based not just on who the user is, but also their device posture, geographic location, and time of day.
  • Seamless User Experience: Employees access internal tools via standard URLs (e.g., [https://grafana.internal.company.com](https://grafana.internal.company.com)) through a simple single sign-on (SSO) browser workflow, eliminating the tedious process of connecting and reconnecting to a client-side VPN.
---

Architectural Overview: How It Works

To understand how Pomerium secures your internal ecosystem, it is helpful to look at the request lifecycle when a user attempts to access an internal dashboard, such as an internal metrics tool or CRM:

  1. Initial Request: The user navigates to an internal URL secured by Pomerium.
  2. Authentication Challenge: Pomerium detects that the user does not have a valid session cookie. It redirects the user’s browser to the Google Workspace OAuth2 login page.
  3. Identity Verification: The user authenticates with their corporate Google credentials, completing any mandated MFA steps.
  4. Token Issuance: Google issues a secure OAuth2 token back to Pomerium containing the user’s identity details and group claims.
  5. Policy Evaluation: Pomerium’s authorization engine cross-references this identity data against pre-defined policies (e.g., "Only users in the 'DevOps' Google Group can access this route").
  6. Secure Proxying: If authorized, Pomerium establishes an encrypted connection, appends identity headers to prevent spoofing, and proxies the request to the upstream internal application.
Security Note: The upstream internal application never needs to be exposed to the public internet; it only accepts incoming traffic routed directly from the isolated Pomerium proxy instance.
---

Step-by-Step Implementation Guide

Setting up Pomerium with Google Workspace requires configuring the Google Cloud Console, writing the Pomerium configuration file, and launching the proxy service. Below is a detailed walkthrough of the technical implementation.

Step 1: Configure Google Workspace OAuth2 Credentials

First, you must establish Pomerium as a trusted application within your Google Cloud ecosystem:

  1. Log in to the Google Cloud Console and select or create a project dedicated to internal security management.
  2. Navigate to APIs & Services > OAuth consent screen. Select Internal as the User Type so that only users within your Google Workspace domain can authenticate. Fill out the required application metadata.
  3. Navigate to Credentials > Create Credentials > OAuth client ID.
  4. Select Web application as the application type.
  5. Under Authorized JavaScript origins, enter your Pomerium authenticate URL (e.g., [https://authenticate.corp.yourcompany.com](https://authenticate.corp.yourcompany.com)).
  6. Under Authorized redirect URIs, add the corresponding callback path: [https://authenticate.corp.yourcompany.com/oauth2/callback](https://authenticate.corp.yourcompany.com/oauth2/callback).
  7. Click Create and securely store the generated Client ID and Client Secret.

Step 2: Generate Cryptographic Secrets

Pomerium requires secure keys to encrypt session cookies and sign state tokens. Run the following commands in your terminal to generate high-entropy, base64-encoded secrets:

# Generate Cookie Secret
openssl rand -base64 32

# Generate Shared Secret
openssl rand -base64 32

Step 3: Author the Pomerium Configuration

Create a config.yaml file to define your global settings, identity provider integrations, and granular access routes. Below is an enterprise-ready configuration template:

# Global Settings
address: ":443"
authenticate_service_url: [https://authenticate.corp.yourcompany.com](https://authenticate.corp.yourcompany.com)

# Cryptographic Keys (Replace with your generated values)
cookie_secret: "YOUR_GENERATED_COOKIE_SECRET"
shared_secret: "YOUR_GENERATED_SHARED_SECRET"

# Identity Provider Integration (Google Workspace)
idp_provider: "google"
idp_client_id: "YOUR_GOOGLE_CLIENT_ID.apps.googleusercontent.com"
idp_client_secret: "YOUR_GOOGLE_CLIENT_SECRET"

# Certificates (Ensure these paths match your SSL/TLS certificates)
authenticate_service_certificate_file: /pomerium/certs/fullchain.pem
authenticate_service_certificate_key_file: /pomerium/certs/privkey.pem

# Contextual Access Control Policies and Routing
routes:
  - from: [https://grafana.corp.yourcompany.com](https://grafana.corp.yourcompany.com)
    to: [http://grafana.internal.net:3000](http://grafana.internal.net:3000)
    policy:
      - allow:
          and:
            - domain:
                is: yourcompany.com
            - groups:
                has: [email protected]
    pass_identity_headers: true

  - from: [https://crm.corp.yourcompany.com](https://crm.corp.yourcompany.com)
    to: [http://crm-local.infrastructure:8080](http://crm-local.infrastructure:8080)
    policy:
      - allow:
          and:
            - domain:
                is: yourcompany.com
            - groups:
                has: [email protected]
    pass_identity_headers: true

Step 4: Deploying via Docker Compose

For scalable, containerized execution, deploy Pomerium using Docker Compose. Ensure your SSL certificates and configuration file are mounted correctly into the container container runtime:

version: '3.8'

services:
  pomerium:
    image: pomerium/pomerium:latest
    container_name: pomerium_proxy
    volumes:
      - ./config.yaml:/pomerium/config.yaml:ro
      - ./certs:/pomerium/certs:ro
    ports:
      - "443:443"
    restart: always

Execute docker-compose up -d to initialize the zero-trust proxy gatekeeper.

---

Best Practices for Production Environments

Deploying a Zero-Trust architecture requires adhering to rigid operational standards to maximize resilience and auditability:

  • Enable Continuous Identity Verification: Configure low session timeouts (e.g., 8 to 12 hours) to ensure that if an employee is offboarded from Google Workspace, their access to internal tools is revoked within minutes.
  • Audit Logging and SIEM Integration: Pomerium generates comprehensive, structured JSON logs detailing every authorization decision. Forward these logs to a Centralized Log Management or SIEM system (like Splunk, Datadog, or an ELK stack) to monitor anomalous access patterns.
  • Network Isolation: Implement strict internal firewall rules or security groups ensuring that your upstream applications only accept traffic originating from the Pomerium proxy’s specific internal IP address.
---

Conclusion

Transitioning from a porous VPN architecture to a strict, identity-aware Zero-Trust model is no longer an optional luxury—it is an operational necessity for modern, cloud-forward business enterprises. By deploying Pomerium in tandem with Google Workspace OAuth2, your organization effectively eliminates the risks associated with lateral network movement, simplifies employee onboarding, and significantly hardens your internal infrastructure against modern threat vectors.

Securing Internal Infrastructure: A Guide to Pomerium Zero-Trust Proxy with Google Workspace OAuth2 | DPTCloud