categories
Infrastructure
Browse Pomerium articles in the Infrastructure category.
Topic archive
Resources Categorized: Infrastructure

It’s always DNS part ∞: tracking down a use-after-free bug in Envoy’s DNS Resolver
We found a use-after-free bug in Envoy’s DNS resolver, c-ares (CVE-2025-62408, CVE-2025-67514).
Introducing Pomerium Ingress Controller for Kubernetes
UPDATED Dec 2025: Looking for options to replace NGINX? We've written a short tutorial on how to migrate from NGINX to Pomerium's ingress control by adding a few lines to you config. Check it out here .
How Pomerium Brings Zero Trust to Legacy, Hybrid, and Cloud-Native Environments
Enterprise infrastructure doesn't live in just one place. It spans data centers, Kubernetes clusters, cloud workloads, and SaaS tools. Some of it's old. Some of it's modern. All of it needs to be secure.

Security is Usability — Examining Cybersecurity Erosion
We examine cybersecurity erosion, the concept that security systems are only as good as their least compliant user. To avoid it, security should always be designed to be usable.

Decisionmaker's Guide to Cloud Workstations
This guide will examine three common cloud workspace solutions, their trade-offs, and points of concerns that decisionmakers should keep in mind.
Network-centric vs Application-centric Approach
The traditional network model results in the Perimeter Problem. Here's why companies should be using the application-centric approach for better usability and security.

CrowdStrike is a Harsh Reminder of the Danger of Third-Party Clients
The true lesson from the CrowdStrike BSOD debacle: avoid third-party clients
Elevating Remote Access: Understanding NextGen VPN Flaws
Virtual Private Networks (VPNs) have been around for decades, providing secure connections between remote locations and enabling remote workers to access company resources. NextGen VPNs, such as StrongDM , Tailscale , and Twingate offer streamlined experiences and advanced features that organizations not only use but also adore.
Applying Zero Trust to Multi-Cloud Environments
We read the National Institute of Standards and Technology (NIST)’s SP 800-207A: A Zero Trust Architecture Model for Access Control in Cloud-Native Applications in Multi-Cloud Environments to summarize it so you don’t have to.

The Three Pillars of Observability
Observability is key to understanding your system’s performance and health. Learn how metrics, traces, and logs provide essential insights for monitoring, troubleshooting, and optimizing your infrastructure.

What is Zero Trust Architecture and Security?
The term "Zero Trust" has been co-opted by many marketing branches of products, but it has a defined meaning with real industry impact.

IAM Trends and Future Outlook
Earlier this year, CISA (Cybersecurity and Infrastructure Security Agency) released their Enduring Security Framework Guidance on IAM (Identity Access Management). While we highly recommend practitioners read the document itself for its best practices and list of immediate actions, we want to discuss some of CISA’s best practices as well as their current and future trends.

What Is SASE? — A Buyer’s Guide
Update: Gartner is now supporting the service chained products they once warned about.

The Perimeter Problem: Why Traditional Network Security Fails
Traditional network perimeter defenses are failing, called the Perimeter Problem. We discuss the pitfalls of tunneling tools, and why going perimeter-less is the best option.

A Case Against Layer 4 Security Tools
We often talk about how Layer 4 tooling such as VPNs are bad for security , so this post is going to dig into why. If you just want the conclusion, it's simple: Layer 4 tooling is fundamentally blind to its own traffic and Layer 7 tooling is not, which leads to different results for auditing, logging, and continuous verification.

VPNs Are Killing Productivity
VPNs have long been the standard for secure remote access, but they come with significant drawbacks like poor security, performance issues, and increased IT workloads. As remote work continues to evolve, organizations must rethink their approach to access control.

A Close Read at NIST’s Definition of Zero Trust Architecture
This is written based on the second draft of SP 1800-35.

Remote Work Infrastructure
The discussion for or against remote work is mostly settled — and remote work has won despite the wishes of the tech giants . The studies prove that remote workers are more productive , are less likely to churn , and expect remote work to be normalized going forward . When it comes to the critical metrics of workforce productivity and employee retention, remote work is a clear winner. Embracing remote work also means saving money in the long run for both employees and employers.

Log4J and the Fragility of Modern Infrastructure
It’s like watching a slow-motion train crash come to fruition. XKCD drew a comic in August 2020 effectively predicting an issue just like the Log4j RCE exploit , but we predict it to be the first of many headline-worthy exploitable dependencies.
