# Support

**URL:** https://discuss.pomerium.com/c/support/9.md?page=1

[Latest](https://discuss.pomerium.com/latest.md) · [Categories](https://discuss.pomerium.com/categories.md) · [Tags](https://discuss.pomerium.com/tags.md)

**Page:** 2

---

## [MY application and IDP can work together, but I want to add them to the pomerium](https://discuss.pomerium.com/t/my-application-and-idp-can-work-together-but-i-want-to-add-them-to-the-pomerium/431)

<div class="topic-metadata">

**Author:** [@oznfc](https://discuss.pomerium.com/u/oznfc)\
**Replies:** 2\
**Last updated:** [November 25, 2024, 1:25pm UTC](https://discuss.pomerium.com/t/my-application-and-idp-can-work-together-but-i-want-to-add-them-to-the-pomerium/431 "2024-11-25T13:25:02Z")

</div>

I want to use my application running at localhost:3000 in pomerium with my IDP. The application and IDP can work together, but I want to add them to the pomerium.I’m using console.pomerium…app with my docker. it’s doc…

---

## [TLS Certificate verification failed](https://discuss.pomerium.com/t/tls-certificate-verification-failed/425)

<div class="topic-metadata">

**Author:** [@Sidhant](https://discuss.pomerium.com/u/Sidhant)\
**Replies:** 2\
**Last updated:** [November 13, 2024, 5:12pm UTC](https://discuss.pomerium.com/t/tls-certificate-verification-failed/425 "2024-11-13T17:12:15Z")

</div>

TLS certificate verification failed when verifying the JWT: x509: certificate is valid for \*, not pomerium How do i resolve this error

---

## [Envoy hangs with ext\_authz\_error](https://discuss.pomerium.com/t/envoy-hangs-with-ext-authz-error/421)

<div class="topic-metadata">

**Author:** [@ms1111](https://discuss.pomerium.com/u/ms1111)\
**Replies:** 6\
**Last updated:** [November 13, 2024, 4:30pm UTC](https://discuss.pomerium.com/t/envoy-hangs-with-ext-authz-error/421 "2024-11-13T16:30:47Z")

</div>

Hi, We’ve been using Pomerium for a couple of years with Azure AD as the IDP. Up until recently we were running Pomerium 0.25.2 on Ubuntu 20.04. We recently updated to 0.27.2, and then replaced the VM with Ubuntu 24.04. …

---

## [Integrating pomerium with keycloak](https://discuss.pomerium.com/t/integrating-pomerium-with-keycloak/418)

<div class="topic-metadata">

**Author:** [@Sidhant](https://discuss.pomerium.com/u/Sidhant)\
**Replies:** 2\
**Last updated:** [October 24, 2024, 10:12am UTC](https://discuss.pomerium.com/t/integrating-pomerium-with-keycloak/418 "2024-10-24T10:12:58Z")

</div>

What happened? I am getting a error 404 trying to access the service , What did you expect to happen? I am using pomerium as a reverse proxy in my minor project to demonstrate Zero Trust Architecture . i want to integra…

---

## [Request for \`--no-browser\` option for \`pomerium-cli\`](https://discuss.pomerium.com/t/request-for-no-browser-option-for-pomerium-cli/416)

<div class="topic-metadata">

**Author:** [@rajivr](https://discuss.pomerium.com/u/rajivr)\
**Replies:** 1\
**Last updated:** [October 7, 2024, 3:41pm UTC](https://discuss.pomerium.com/t/request-for-no-browser-option-for-pomerium-cli/416 "2024-10-07T15:41:45Z")

</div>

What happened? I am new to Pomerium. Firstly, thank you for making Pomerium and making Pomerium Core freely available. Currently when using pomerium-cli, it automatically launches a browser when a connection needs to be…

---

## [Serving with the wrong certificate](https://discuss.pomerium.com/t/serving-with-the-wrong-certificate/415)

<div class="topic-metadata">

**Author:** [@julianbadillo](https://discuss.pomerium.com/u/julianbadillo)\
**Replies:** 2\
**Last updated:** [October 4, 2024, 4:49pm UTC](https://discuss.pomerium.com/t/serving-with-the-wrong-certificate/415 "2024-10-04T16:49:45Z")

</div>

What happened? A handful of our routes got net::ERR\_CERT\_COMMON\_NAME\_INVALID errors from the browsers (not all of them). If I click on the security details on the browser, the wrong certificate is being presented. The c…

---

## [Adding an external URL to an existing Pomerium Configuration](https://discuss.pomerium.com/t/adding-an-external-url-to-an-existing-pomerium-configuration/402)

<div class="topic-metadata">

**Author:** [@matswillemsen](https://discuss.pomerium.com/u/matswillemsen)\
**Replies:** 1\
**Last updated:** [September 15, 2024, 10:20pm UTC](https://discuss.pomerium.com/t/adding-an-external-url-to-an-existing-pomerium-configuration/402 "2024-09-15T22:20:50Z")

</div>

We currently are exposing internal domains through an internal endpoint, with also the Pomerium Authenticate URL set to this internal endpoint (authenticate.xxx.internal.ah.nl) Now, we want to expose this authenticate e…

---

## [How to test config before restarting service?](https://discuss.pomerium.com/t/how-to-test-config-before-restarting-service/216)

<div class="topic-metadata">

**Author:** [@torch](https://discuss.pomerium.com/u/torch)\
**Replies:** 14\
**Last updated:** [September 13, 2024, 12:37pm UTC](https://discuss.pomerium.com/t/how-to-test-config-before-restarting-service/216 "2024-09-13T12:37:35Z")

</div>

What happened? I see no (apparent) way to test a changed configuration before restarting pomerium. I tried running a second instance of the service on a different port, to see if it would start without errors. Existing…

---

## [Accessing upstream services that require sso](https://discuss.pomerium.com/t/accessing-upstream-services-that-require-sso/398)

<div class="topic-metadata">

**Author:** [@Arzar](https://discuss.pomerium.com/u/Arzar)\
**Replies:** 5\
**Last updated:** [September 11, 2024, 4:09pm UTC](https://discuss.pomerium.com/t/accessing-upstream-services-that-require-sso/398 "2024-09-11T16:09:47Z")

</div>

We want to try Pomerium with our internal services, but many of our upstream applications use SAML for SSO authentication. We haven’t found a good way to get the SAML authentication working through the Pomerium proxy. Is…

---

## [How to deal with absolute path and cross orgin](https://discuss.pomerium.com/t/how-to-deal-with-absolute-path-and-cross-orgin/397)

<div class="topic-metadata">

**Author:** [@Arzar](https://discuss.pomerium.com/u/Arzar)\
**Replies:** 2\
**Last updated:** [September 5, 2024, 11:03am UTC](https://discuss.pomerium.com/t/how-to-deal-with-absolute-path-and-cross-orgin/397 "2024-09-05T11:03:11Z")

</div>

We tried to set up Pomerium to provide access to some of our internal resources. Most of these resources are legacy systems that we cannot modify. However, we encountered some issues. We are getting redirected out of Po…

---

## [Connecting OICD server](https://discuss.pomerium.com/t/connecting-oicd-server/390)

<div class="topic-metadata">

**Author:** [@misha](https://discuss.pomerium.com/u/misha)\
**Replies:** 3\
**Last updated:** [August 12, 2024, 9:26pm UTC](https://discuss.pomerium.com/t/connecting-oicd-server/390 "2024-08-12T21:26:48Z")

</div>

What happened? Pomerium v0.25.0 deployed on GKE. On the server side, the setup as described in(https://openid.net/) includes https://example.com/.well-known/openid-configuration endpoint First, I am reaching authorizat…

---

## [Cross-Origin Configuration](https://discuss.pomerium.com/t/cross-origin-configuration/384)

<div class="topic-metadata">

**Author:** [@sorin.flueras](https://discuss.pomerium.com/u/sorin.flueras)\
**Replies:** 1\
**Last updated:** [July 1, 2024, 5:17pm UTC](https://discuss.pomerium.com/t/cross-origin-configuration/384 "2024-07-01T17:17:02Z")

</div>

There are three solutions provided at Cross-Origin Configuration | Pomerium for fixing the 401 error related to cross-origin configuration. However, all three require changes to the application code. What can I do if I c…

---

## [Programatic Access JWT expires too early](https://discuss.pomerium.com/t/programatic-access-jwt-expires-too-early/198)

<div class="topic-metadata">

**Author:** [@mchaines](https://discuss.pomerium.com/u/mchaines)\
**Replies:** 8\
**Last updated:** [May 17, 2024, 8:37am UTC](https://discuss.pomerium.com/t/programatic-access-jwt-expires-too-early/198 "2024-05-17T08:37:56Z")

</div>

I’ve implemented a programmatic access workflow as described here. After receiving the session callback, I capture the JWT from the URL and add it to subsequent API requests in an auth header like Authorization: Pomerium…

---

## [Modify the token type towards argo-workflow](https://discuss.pomerium.com/t/modify-the-token-type-towards-argo-workflow/367)

<div class="topic-metadata">

**Author:** [@daniel.caldararu](https://discuss.pomerium.com/u/daniel.caldararu)\
**Replies:** 4\
**Last updated:** [May 16, 2024, 9:29am UTC](https://discuss.pomerium.com/t/modify-the-token-type-towards-argo-workflow/367 "2024-05-16T09:29:01Z")

</div>

What happened? I’m trying to use Pomerium in order to redirect the token once I authenticate through my issuer, towards to argo-workflow UI which supports Token authentication and SSO login. Unfortunately doesn’t work be…

---

## [service":"autocert","error":"no OCSP stapling for \[www.hyprpg.net\]: no OCSP server specified in certificate](https://discuss.pomerium.com/t/service-autocert-error-no-ocsp-stapling-for-www-hyprpg-net-no-ocsp-server-specified-in-certificate/375)

<div class="topic-metadata">

**Author:** [@Rajni](https://discuss.pomerium.com/u/Rajni)\
**Replies:** 1\
**Last updated:** [May 15, 2024, 3:51pm UTC](https://discuss.pomerium.com/t/service-autocert-error-no-ocsp-stapling-for-www-hyprpg-net-no-ocsp-server-specified-in-certificate/375 "2024-05-15T15:51:09Z")

</div>

What happened? service":“autocert”,“error”:“no OCSP stapling for \[www.hyprpg.net\]: no OCSP server specified in certificate” What did you expect to happen? How’d it happen? Ran x Clicked y Saw error z What’s your envir…

---

## [Pomerium OSS + LogTo in k3s (Traefik)](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372)

<div class="topic-metadata">

**Author:** [@IngwiePhoenix](https://discuss.pomerium.com/u/IngwiePhoenix)\
**Replies:** 3\
**Last updated:** [May 9, 2024, 6:34pm UTC](https://discuss.pomerium.com/t/pomerium-oss-logto-in-k3s-traefik/372 "2024-05-09T18:34:12Z")

</div>

What happened? I have recently installed LogTo into my cluster and configured a few basics. Right now, my k3s cluster is not exposed to the public - I want to figure out authentication and authorization beforehand. The …

---

## [No support for Google Cloud Serverless authentication in Kubernetes?](https://discuss.pomerium.com/t/no-support-for-google-cloud-serverless-authentication-in-kubernetes/370)

<div class="topic-metadata">

**Author:** [@0anton](https://discuss.pomerium.com/u/0anton)\
**Replies:** 1\
**Last updated:** [April 27, 2024, 8:31am UTC](https://discuss.pomerium.com/t/no-support-for-google-cloud-serverless-authentication-in-kubernetes/370 "2024-04-27T08:31:29Z")

</div>

We came to a surprising statement in the documentation reading the configuration option enable\_google\_cloud\_serverless\_authentication that Kubernetes does not support Enable Google Cloud Serverless Authentication. Why i…

---

## [ERR\_TOO\_MANY\_REDIRECTS after authenticating (Pomerium + IDP (Okta, Github or Azure AD)](https://discuss.pomerium.com/t/err-too-many-redirects-after-authenticating-pomerium-idp-okta-github-or-azure-ad/363)

<div class="topic-metadata">

**Author:** [@robmonct](https://discuss.pomerium.com/u/robmonct)\
**Replies:** 2\
**Last updated:** [April 22, 2024, 7:07pm UTC](https://discuss.pomerium.com/t/err-too-many-redirects-after-authenticating-pomerium-idp-okta-github-or-azure-ad/363 "2024-04-22T19:07:29Z")

</div>

Dear team, I’m trying to use Pomerium to work as a Identity-Aware Proxy in Azure AKS. I followed the Pomerium Kubernetes Quickstart (Kubernetes Quickstart | Pomerium) and worked fine. After that, I followed the installa…

---

## [Pomerium loops re-reading configuration from CloudRun mounted Secret](https://discuss.pomerium.com/t/pomerium-loops-re-reading-configuration-from-cloudrun-mounted-secret/361)

<div class="topic-metadata">

**Author:** [@0anton](https://discuss.pomerium.com/u/0anton)\
**Replies:** 1\
**Last updated:** [April 22, 2024, 5:07pm UTC](https://discuss.pomerium.com/t/pomerium-loops-re-reading-configuration-from-cloudrun-mounted-secret/361 "2024-04-22T17:07:20Z")

</div>

Dear team, I’m observing Pomerium (using latest image from pomerium/pomerium:latest, should be v0.25.2) is looping in the fileutil/watcher permanently rebuilding/re-reading its config.yaml: { "jsonPayload": { "le…

---

## [Self hosted authenticate service](https://discuss.pomerium.com/t/self-hosted-authenticate-service/357)

<div class="topic-metadata">

**Author:** [@pepov](https://discuss.pomerium.com/u/pepov)\
**Replies:** 6\
**Last updated:** [April 10, 2024, 3:43pm UTC](https://discuss.pomerium.com/t/self-hosted-authenticate-service/357 "2024-04-10T15:43:52Z")

</div>

What happened? We used the hosted authenticate service with success but later decided to host our own to have uptime guarantee. We currently use version v0.22.1. We now get a 401 locally by our pomerium proxy after a f…

---

## [How to install on AWS EKS](https://discuss.pomerium.com/t/how-to-install-on-aws-eks/358)

<div class="topic-metadata">

**Author:** [@horangs](https://discuss.pomerium.com/u/horangs)\
**Replies:** 1\
**Last updated:** [April 9, 2024, 6:56pm UTC](https://discuss.pomerium.com/t/how-to-install-on-aws-eks/358 "2024-04-09T18:56:19Z")

</div>

What happened? Hi, I am new to this tool. and I am reading your doc, Installation | Pomerium. I preferred using helm, but pomerium did not support helm chart anymore. when I followed your document, cert-manager is r…

---

## [Pulling user's location and adding it in claims (google workspace)](https://discuss.pomerium.com/t/pulling-users-location-and-adding-it-in-claims-google-workspace/342)

<div class="topic-metadata">

**Author:** [@dinesh.udayakumar](https://discuss.pomerium.com/u/dinesh.udayakumar)\
**Replies:** 6\
**Last updated:** [April 1, 2024, 7:46pm UTC](https://discuss.pomerium.com/t/pulling-users-location-and-adding-it-in-claims-google-workspace/342 "2024-04-01T19:46:37Z")

</div>

What happened? I am trying to pull user’s location in the claims. We have the directory sync configured between Pomerium and Google workspace and able to retrieve the groups. But we also require user’s location (country…

---

## [Docker buildx build from pomerium image with --platform linux/amd64](https://discuss.pomerium.com/t/docker-buildx-build-from-pomerium-image-with-platform-linux-amd64/353)

<div class="topic-metadata">

**Author:** [@ogreyard](https://discuss.pomerium.com/u/ogreyard)\
**Replies:** 2\
**Last updated:** [March 29, 2024, 7:59pm UTC](https://discuss.pomerium.com/t/docker-buildx-build-from-pomerium-image-with-platform-linux-amd64/353 "2024-03-29T19:59:48Z")

</div>

I try to build a customized pomerium image. In the Dockerfile, I base the image on FROM cr.pomerium.com/pomerium/pomerium:latest Build succeeds on for linux/arm64/v8. Build fails for --platform linux/amd64 on local m…

---

## [Pomerium as Identity Aware Reverse-Proxy for Cloud Run](https://discuss.pomerium.com/t/pomerium-as-identity-aware-reverse-proxy-for-cloud-run/350)

<div class="topic-metadata">

**Author:** [@ogreyard](https://discuss.pomerium.com/u/ogreyard)\
**Replies:** 5\
**Last updated:** [March 29, 2024, 11:16am UTC](https://discuss.pomerium.com/t/pomerium-as-identity-aware-reverse-proxy-for-cloud-run/350 "2024-03-29T11:16:42Z")

</div>

What happened? I want to use pomerium as an identity aware reverse proxy to one of my cloud run services. The Authenticate and Authorize flows against Google IDP both work nicely. I get OAuth callback and redirected to …

---

## [Pomerium Demo 0.25.1 via Docker refusing connection](https://discuss.pomerium.com/t/pomerium-demo-0-25-1-via-docker-refusing-connection/345)

<div class="topic-metadata">

**Author:** [@ogreyard](https://discuss.pomerium.com/u/ogreyard)\
**Replies:** 3\
**Last updated:** [March 25, 2024, 12:38pm UTC](https://discuss.pomerium.com/t/pomerium-demo-0-25-1-via-docker-refusing-connection/345 "2024-03-25T12:38:15Z")

</div>

Hi there. Simply trying the demo quickstart app. No luck so far. Hope anybody can help. What happened? tried the quickstart guide via docker-compose. Started successfully, however gives “ERR\_NAME\_NOT\_RESOLVED”. When…

---

## [Connecting outbound through Enterprise Proxy (Zscaler)](https://discuss.pomerium.com/t/connecting-outbound-through-enterprise-proxy-zscaler/349)

<div class="topic-metadata">

**Author:** [@Saltcreep](https://discuss.pomerium.com/u/Saltcreep)\
**Replies:** 4\
**Last updated:** [March 22, 2024, 4:19pm UTC](https://discuss.pomerium.com/t/connecting-outbound-through-enterprise-proxy-zscaler/349 "2024-03-22T16:19:38Z")

</div>

What happened? Hello, I am a Security Engineer, not a developer and not familiar with this app, so I am sorry if I am misunderstanding something here. We have users using Pomerium to authenticate and then connect to a P…

---

## [Is it possible to serve files using pomerium?](https://discuss.pomerium.com/t/is-it-possible-to-serve-files-using-pomerium/340)

<div class="topic-metadata">

**Author:** [@rubydotexe](https://discuss.pomerium.com/u/rubydotexe)\
**Replies:** 1\
**Last updated:** [March 11, 2024, 2:34pm UTC](https://discuss.pomerium.com/t/is-it-possible-to-serve-files-using-pomerium/340 "2024-03-11T14:34:19Z")

</div>

What happened? I want to know if its possible to serve files via pomerium like you can with Caddy or NGINX? Here are some examples: Caddy: example.com { root \* /srv file\_server } Here’s what I’m trying to replicate …

---

## [Usage of AWS Cert Manager](https://discuss.pomerium.com/t/usage-of-aws-cert-manager/337)

<div class="topic-metadata">

**Author:** [@arun.sisodiya](https://discuss.pomerium.com/u/arun.sisodiya)\
**Replies:** 1\
**Last updated:** [February 22, 2024, 3:20pm UTC](https://discuss.pomerium.com/t/usage-of-aws-cert-manager/337 "2024-02-22T15:20:35Z")

</div>

Usage of AWS Cert Manager instead of cert-manager With the new versions of Pomerium, I have identified that Pomerium is supporting cert-manager for the certificates of Ingress but I want to use the AWS Cert manager for t…

---

## [Enabling whitelisting to the Public facing Ingress](https://discuss.pomerium.com/t/enabling-whitelisting-to-the-public-facing-ingress/335)

<div class="topic-metadata">

**Author:** [@arun.sisodiya](https://discuss.pomerium.com/u/arun.sisodiya)\
**Replies:** 2\
**Last updated:** [February 15, 2024, 9:23am UTC](https://discuss.pomerium.com/t/enabling-whitelisting-to-the-public-facing-ingress/335 "2024-02-15T09:23:52Z")

</div>

Unable to configure IP whitelisting on Ingress level I want to access the public-facing ingress using Pomerium as an ingress class with IP whitelisting. Currently, It is possible with the Ingress-nginx controller using …

---

## [I need Authentik Help Please](https://discuss.pomerium.com/t/i-need-authentik-help-please/326)

<div class="topic-metadata">

**Author:** [@node815](https://discuss.pomerium.com/u/node815)\
**Replies:** 8\
**Last updated:** [November 20, 2023, 6:14pm UTC](https://discuss.pomerium.com/t/i-need-authentik-help-please/326 "2023-11-20T18:14:42Z")

</div>

What happened? I get a 500 error with the integration when I try to access verify.redacted.com . What did you expect to happen? The first step after successful install? I guess? I haven’t gotten that far! How’d it hap…

[Previous page](https://discuss.pomerium.com/c/support/9.md)

[Next page](https://discuss.pomerium.com/c/support/9.md?page=2)
